No description
Find a file
dependabot[bot] dea67a6792
chore(deps): bump the minor-and-patch group with 4 updates
Bumps the minor-and-patch group with 4 updates: [constructs](https://github.com/aws/constructs), [@types/node](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/node), [aws-cdk](https://github.com/aws/aws-cdk-cli/tree/HEAD/packages/aws-cdk) and [tsx](https://github.com/privatenumber/tsx).


Updates `constructs` from 10.7.2 to 10.8.1
- [Release notes](https://github.com/aws/constructs/releases)
- [Commits](https://github.com/aws/constructs/compare/v10.7.2...v10.8.1)

Updates `@types/node` from 26.1.2 to 26.2.0
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/node)

Updates `aws-cdk` from 2.1134.0 to 2.1135.1
- [Release notes](https://github.com/aws/aws-cdk-cli/releases)
- [Commits](https://github.com/aws/aws-cdk-cli/commits/aws-cdk@v2.1135.1/packages/aws-cdk)

Updates `tsx` from 4.23.4 to 4.23.11
- [Release notes](https://github.com/privatenumber/tsx/releases)
- [Changelog](https://github.com/privatenumber/tsx/blob/master/release.config.cjs)
- [Commits](https://github.com/privatenumber/tsx/compare/v4.23.4...v4.23.11)

---
updated-dependencies:
- dependency-name: constructs
  dependency-version: 10.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: "@types/node"
  dependency-version: 26.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aws-cdk
  dependency-version: 2.1135.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: tsx
  dependency-version: 4.23.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-11 06:09:09 +00:00
.github chore(deps): bump aws-cdk and allowlist brace-expansion GHSA-rgw5 (PLAT-83) (#23) 2026-08-05 23:05:49 +00:00
.security-review chore(deps): bump aws-cdk and allowlist brace-expansion GHSA-rgw5 (PLAT-83) (#23) 2026-08-05 23:05:49 +00:00
bin feat: syslog-server under IaC (INFRA-12) 2026-06-09 13:51:17 -04:00
lib feat(syslog-server): IaC-managed EC2 StatusCheckFailed alarm + auto-recovery (INFRA-58) (#4) 2026-06-17 15:02:04 -04:00
.gitignore feat: syslog-server under IaC (INFRA-12) 2026-06-09 13:51:17 -04:00
AGENTS.md ci: add org PR policy caller 2026-08-04 11:32:26 -04:00
cdk.context.json feat: syslog-server under IaC (INFRA-12) 2026-06-09 13:51:17 -04:00
cdk.json build(deps): migrate CDK app ts-node->tsx, adopt typescript 7 (INFRA-183) (#11) 2026-07-08 17:48:22 -04:00
package-lock.json chore(deps): bump the minor-and-patch group with 4 updates 2026-08-11 06:09:09 +00:00
package.json chore(deps): bump the minor-and-patch group with 4 updates 2026-08-11 06:09:09 +00:00
README.md Document CDK app layout in README (#12) 2026-07-10 16:07:36 -04:00
tsconfig.json feat: syslog-server under IaC (INFRA-12) 2026-06-09 13:51:17 -04:00

syslog-server

TypeScript AWS CDK CI

CDK stack for the syslog-server EC2 collector: receives remote syslog (UDP/TCP 514) from the office UniFi fleet over its Elastic IP and ships it to the unifi-syslog CloudWatch Logs group via the CloudWatch agent.

Brought under IaC for INFRA-12 (AWS audit L-6). Previously a console/CLI instance with no drift detection.

Architecture

office UniFi devices ──syslog/514──▶ EIP 184.72.154.32 ──▶ EC2 (rsyslog)
                                                              │
                                              /var/log/remote/<host>/*.log
                                                              │
                                              CloudWatch agent ──▶ unifi-syslog (90d)
                                                                        │
                                                       Syslog-NoIncomingLogs alarm ──▶ site-alerts
Resource Value
Instance syslog-server, t4g.nano, Amazon Linux 2023 (arm64), 30 GiB encrypted gp3
Subnet subnet-0eea820effe1b3ae5 (public, us-east-1a, vpc-0d3d4b67bd0cf8a68)
Elastic IP 184.72.154.32 (eipalloc-006bdefc9802f3285) — unmanaged, re-associated by ID
Security group syslog-server — 514 tcp/udp + 22 from office IPs + VPC/VPN CIDRs; 2055/2056 udp reserved (netflow/sflow)
IAM role syslog-server-role — AmazonSSMManagedInstanceCore + CloudWatchAgentServerPolicy
Log group unifi-syslog (90-day retention) — created/retained by the CW agent, not a CFN resource (holds history; see stack comment)
Alarm Syslog-NoIncomingLogs — IncomingLogEvents Sum < 1 over 2×1-day, ALARM-only → site-alerts

CDK app

Infrastructure is a single-stack AWS CDK app written in TypeScript. cdk.json is the app manifest the CDK CLI reads on every command: its app entry (npx tsx bin/app.ts) runs the TypeScript entry point directly through tsx, so synth/deploy need no separate tsc compile step. The file also carries the watch globs (for cdk watch) and the CDK feature-flag context.

Path Role
cdk.json CDK app manifest — app entry command, watch globs, feature-flag context
bin/app.ts App entry point; instantiates SyslogServerStack with explicit stackName: "syslog-server" and env pinned to account 328440206208 / us-east-1
lib/syslog-server-stack.ts The syslog-server stack — every resource in the table above (EC2 instance + rsyslog/CloudWatch/NetFlow user-data, security group, IAM role, EIP association, alarms)
cdk.context.json Cached provider lookups — the VPC (vpc-0d3d4b67bd0cf8a68) and the pinned AL2023 AMI (cachedInContext); committed so synth is deterministic

aws-cdk-lib is pinned to an exact version (2.261.0). The npm scripts wrap the CDK CLI — npm run synth, npm run diff, npm run deploy — plus npm run build (tsc type-check).

Documentation

The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's syslog-server stack is represented there as a Mermaid subgraph.

Access

SSM Session Manager (no key pair). SSH 22 is open from office/VPC for break-glass only.

Deploy

CI/CD via the org reusable workflows (ci-typescript-cdk.yaml, cd-cdk.yaml); merges to main deploy through the githubdeploy-syslog-server OIDC role. No Docker assets, so a local cdk deploy is also safe.

npm ci
npm run diff
npm run deploy

Notes

  • EIP is unmanaged. CloudFormation associates it but never releases it, so the public forwarding target survives any instance replacement.
  • AMI is pinned in cdk.context.json (cachedInContext). An AL2023 AMI change forces instance replacement — refresh deliberately with cdk context --reset <ami key> && cdk synth.
  • To widen device coverage of the forwarded syslog feed, see INFRA-11 (UniFi controller remote-logging config).