mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 13:33:16 +00:00
* feat(infra): migrate syslog-server to HCP Terraform Replace the mgmt CDK stack with a seahaven-prod HCP workspace so the collector is owned by Terraform before UniFi cutover. * fix(infra): keep no-logs alarm quiet until UniFi cutover The new prod unifi-syslog group is empty until devices are re-pointed, so treat_missing_data=breaching would page site-alerts on first apply. * fix(infra): allow scoped apply to modify SG rules in place Authorize/Revoke plus description updates are not enough for aws_vpc_security_group_*_rule in-place changes after the bootstrap window.
22 lines
811 B
HCL
22 lines
811 B
HCL
variable "aws_region" {
|
|
description = "Region every resource in this configuration is created in."
|
|
type = string
|
|
default = "us-east-1"
|
|
}
|
|
|
|
variable "ami_id" {
|
|
description = "Pinned Amazon Linux 2023 arm64 AMI. Changing this replaces the instance."
|
|
type = string
|
|
default = "ami-02c114835b4e7739f"
|
|
}
|
|
|
|
variable "no_logs_treat_missing_data" {
|
|
description = "CloudWatch treat_missing_data for Syslog-NoIncomingLogs. Keep notBreaching until UniFi points at the new EIP, then set breaching."
|
|
type = string
|
|
default = "notBreaching"
|
|
|
|
validation {
|
|
condition = contains(["breaching", "notBreaching", "ignore", "missing"], var.no_logs_treat_missing_data)
|
|
error_message = "no_logs_treat_missing_data must be breaching, notBreaching, ignore, or missing."
|
|
}
|
|
}
|