mirror of
https://github.com/Sea-Haven-Industries/syslog-server.git
synced 2026-09-30 06:33:15 +00:00
* feat(infra): migrate syslog-server to HCP Terraform Replace the mgmt CDK stack with a seahaven-prod HCP workspace so the collector is owned by Terraform before UniFi cutover. * fix(infra): keep no-logs alarm quiet until UniFi cutover The new prod unifi-syslog group is empty until devices are re-pointed, so treat_missing_data=breaching would page site-alerts on first apply. * fix(infra): allow scoped apply to modify SG rules in place Authorize/Revoke plus description updates are not enough for aws_vpc_security_group_*_rule in-place changes after the bootstrap window.
39 lines
883 B
HCL
39 lines
883 B
HCL
resource "aws_instance" "this" {
|
|
ami = var.ami_id
|
|
instance_type = "t4g.nano"
|
|
subnet_id = aws_subnet.public.id
|
|
vpc_security_group_ids = [aws_security_group.this.id]
|
|
iam_instance_profile = aws_iam_instance_profile.this.name
|
|
user_data = file("${path.module}/user_data.sh")
|
|
user_data_replace_on_change = true
|
|
|
|
root_block_device {
|
|
volume_size = 30
|
|
volume_type = "gp3"
|
|
encrypted = true
|
|
}
|
|
|
|
metadata_options {
|
|
http_endpoint = "enabled"
|
|
http_tokens = "required"
|
|
}
|
|
|
|
tags = {
|
|
Name = "syslog-server"
|
|
}
|
|
}
|
|
|
|
resource "aws_eip" "this" {
|
|
domain = "vpc"
|
|
|
|
tags = {
|
|
Name = "syslog-server"
|
|
}
|
|
|
|
depends_on = [aws_internet_gateway.this]
|
|
}
|
|
|
|
resource "aws_eip_association" "this" {
|
|
instance_id = aws_instance.this.id
|
|
allocation_id = aws_eip.this.id
|
|
}
|