syslog-server/terraform/ec2.tf
Adam Moussa e17b284370
feat(infra): migrate syslog-server to HCP Terraform (PLAT-78) (#38)
* feat(infra): migrate syslog-server to HCP Terraform

Replace the mgmt CDK stack with a seahaven-prod HCP workspace so the
collector is owned by Terraform before UniFi cutover.

* fix(infra): keep no-logs alarm quiet until UniFi cutover

The new prod unifi-syslog group is empty until devices are re-pointed, so treat_missing_data=breaching would page site-alerts on first apply.

* fix(infra): allow scoped apply to modify SG rules in place

Authorize/Revoke plus description updates are not enough for aws_vpc_security_group_*_rule in-place changes after the bootstrap window.
2026-09-16 21:29:43 +00:00

39 lines
883 B
HCL

resource "aws_instance" "this" {
ami = var.ami_id
instance_type = "t4g.nano"
subnet_id = aws_subnet.public.id
vpc_security_group_ids = [aws_security_group.this.id]
iam_instance_profile = aws_iam_instance_profile.this.name
user_data = file("${path.module}/user_data.sh")
user_data_replace_on_change = true
root_block_device {
volume_size = 30
volume_type = "gp3"
encrypted = true
}
metadata_options {
http_endpoint = "enabled"
http_tokens = "required"
}
tags = {
Name = "syslog-server"
}
}
resource "aws_eip" "this" {
domain = "vpc"
tags = {
Name = "syslog-server"
}
depends_on = [aws_internet_gateway.this]
}
resource "aws_eip_association" "this" {
instance_id = aws_instance.this.id
allocation_id = aws_eip.this.id
}