Files
boc/terraform/aamos-ledger/README.md
T
Bernt 05ed037fe8 pilot.landvex.com: HTTPS + Full Stack Verified
- DNS: pilot.landvex.com -> 16.170.83.169
- TLS: Let's Encrypt certificate (expires 2026-09-30)
- Nginx: reverse proxy with SSL termination
- API: https://pilot.landvex.com/api/v1/missions
- UI: https://pilot.landvex.com/
- Upload: POST /api/v1/missions/import (multipart/form-data)

Verified:
 https://pilot.landvex.com/health
 https://pilot.landvex.com/version
 https://pilot.landvex.com/api/v1/missions (list)
 https://pilot.landvex.com/api/v1/missions/:id (get)
 POST /api/v1/missions/import (video upload)
 UI loads with title 'LandveX Intelligence Lab'

Next: Pilot 001 — Break the system!
2026-07-02 17:34:19 +00:00

1.1 KiB

Terraform: aamos-ledger

Status: Pågående — ej deployad Mål: Reproducerbar infrastruktur för bokföringsmotorn Blockerad av: STOP-005-CRIT (hemlighetsrotation)


Vad som finns

  • Terraform-konfiguration för EC2
  • AWS Secrets Manager integration
  • IAM med minimala rättigheter
  • Security Group
  • Variabler för staging/production

Vad som saknas

  • Remote state (S3 + DynamoDB)
  • EBS-kryptering
  • CloudWatch övervakning
  • ALB/NLB istället för direkt EC2-access
  • Auto Scaling Group
  • RDS-konfiguration (just nu pekar den på befintlig RDS)
  • Redis-konfiguration (just nu pekar den på befintlig Redis)
  • user-data.sh skript
  • terraform plan har körts
  • terraform apply har körts

Nästa steg

  1. Konfigurera remote state
  2. Skapa user-data.sh
  3. Kör terraform plan
  4. Kör terraform apply i staging
  5. Verifiera att hemligheter läses från Secrets Manager
  6. Uppdatera systemd-service att använda Secrets Manager
  7. Rotera hemligheter
  8. Deploya till production

Skapad: 2026-07-01T13:25Z Blockerad av: STOP-005-CRIT