Skip to content

chore: DB EC2 의 private IP 를 현재 주소로 고정 - #86

Merged
Hexeong merged 2 commits into
mainfrom
chore/fix-db-ec2-private-ip
Oct 10, 2026
Merged

Hexeong merged 2 commits into
mainfrom
chore/fix-db-ec2-private-ip

Conversation

@Hexeong

@Hexeong Hexeong commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

관련 이슈

작업 내용

  • prod DB EC2(aws_instance.db_server)의 private IP를 현재 주소로 명시적으로 고정했습니다.
  • 값은 db_ec2_private_ip 변수로 받으며, default 없이 secrets의 prod_db.tfvars에서 읽습니다.
  • app_stack 모듈 변수 db_private_ip는 DB EC2를 쓰지 않는 stage를 위해 null 기본값을 둡니다.

배경

복구 워크플로우(#68)는 인스턴스를 교체하는 방식으로 진행합니다. 지금은 교체할 때마다 private IP가 바뀌어 다음 작업이 함께 필요합니다.

  1. Parameter Store /solid-connection/prod/spring.datasource.url 갱신 (현재 private IP를 직접 가리킴)
  2. Spring은 이 값을 기동할 때 읽으므로 API 서버 재배포

DB EC2는 private subnet에 있어 EIP로 주소를 유지할 수 없습니다. 그래서 private IP를 고정해 두 단계를 복구 절차에서 없앱니다.

특이 사항

  • secrets submodule 갱신이 필요합니다. prod_db.tfvars에 db_ec2_private_ip를 추가하고 이 PR의 submodule 포인터를 올리기 전까지는 CI plan이 변수 누락으로 실패합니다.
  • 로컬에서 DB EC2 리소스만 -target으로 지정해 plan을 확인했습니다.
    • 현재 IP와 같은 값: No changes
    • 다른 IP(.117): private_ip ... # forces replacement, Plan: 2 to add, 0 to change, 2 to destroy
    • 값이 실제로 비교되고 있으며, 현재 값으로는 운영 인스턴스가 교체되지 않습니다.
  • terraform validate를 통과했습니다.

리뷰 요구사항 (선택)

  • CI plan에서 module.prod_stack.aws_instance.db_server에 변경이 없는지 확인 부탁드립니다.
  • 교체할 때 -replace는 destroy 후 create 순서로 진행됩니다. 기존 인스턴스가 종료되면서 반환된 IP를 새 인스턴스가 바로 받는지는 복구 리허설에서 확인할 예정입니다.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • 새 기능
    • 프로덕션 환경에서 DB 서버의 사설 IP 주소를 지정할 수 있습니다. 지정한 주소는 DB 서브넷의 IP 범위에 속해야 합니다.

인스턴스를 교체하면 private IP 가 바뀌어 Parameter Store 의
spring.datasource.url 갱신과 API 서버 재배포가 함께 필요했다.
DB EC2 는 private subnet 에 있어 EIP 로 주소를 유지할 수도 없다.

복구 워크플로우(#68)에서 인스턴스를 교체해도 datasource 설정을
그대로 쓸 수 있도록 현재 주소를 명시적으로 고정한다.

- prod 의 db_ec2_private_ip 는 default 없이 secrets tfvars 에서 읽는다
- 모듈 변수는 DB EC2 를 쓰지 않는 stage 를 위해 null 기본값을 둔다
- 현재 주소와 같은 값이면 plan 이 No changes 임을 확인했다

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Repository: solid-connection/solid-connection-infra/.coderabbit.yaml
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ee6264fb-80e3-49a0-8e32-f81eaf493bf3
📥 Commits

Reviewing files that changed from the base of the PR and between 2fb03f2 and 6b040fe.

📒 Files selected for processing (5)
  • config/secrets
  • environment/prod/main.tf
  • environment/prod/variables.tf
  • modules/app_stack/db_ec2.tf
  • modules/app_stack/variables.tf

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

prod 환경에서 DB EC2의 고정 사설 IP를 입력하고 app_stack 모듈을 통해 인스턴스에 전달하도록 변경했습니다. 또한 config/secrets의 서브모듈 커밋 참조를 갱신했습니다.

Changes

DB EC2 사설 IP 설정

Layer / File(s) Summary
사설 IP 입력값 전달 및 인스턴스 설정
environment/prod/variables.tf, modules/app_stack/variables.tf, environment/prod/main.tf, modules/app_stack/db_ec2.tf
prod 환경에 db_ec2_private_ip 변수를 추가하고 app_stack 모듈에 전달합니다. aws_instance.db_server는 전달받은 값을 private_ip로 사용합니다. prod 변수 설명에는 IP가 db_ec2_subnet_id의 CIDR 범위 안에 있어야 한다고 명시합니다.

secrets 서브모듈 참조 갱신

Layer / File(s) Summary
서브모듈 커밋 참조 변경
config/secrets
서브모듈 커밋 참조를 cbceeaaba7de5fa1c944732d2223759fe4a44d2a에서 86d5235eec346b56210117b54ffa79590383d579로 변경합니다.

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~8 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 6b040

No confirmed issue prevents merging. Confirm the production secrets value and CI Terraform plan before applying the change to production.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 6b040

The visible changes are narrowly scoped and retain existing network and storage protections. However, the updated secret values and address continuity during database replacement have not been verified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The visible new control affects the production DB endpoint and applications using that endpoint. It operates through deployment configuration rather than a newly exposed request entrypoint. Exposure beyond this scope cannot be excluded for the unreadable secrets revision.

Trust Boundaries and Controls

  • observed — The new address input reaches the EC2 provisioning boundary without adding an IAM principal or changing the visible instance-profile reference. Subnet, ingress-rule, and credential inputs already existed. Actual IAM permissions, secret-backed ingress values, and the new address value were not verified, so unchanged references are not proof of unchanged effective exposure.

Hardening Proposals

  • proposed — Before relying on fixed-address recovery, verify the full production plan against the pinned secrets revision and rehearse replacement through address reassignment, persistent-volume reattachment, interrupted execution, retry, and rollback. Confirm that the unchanged datasource endpoint reaches the intended restored database throughout recovery.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed 제목은 prod DB EC2의 private IP를 고정하는 주요 변경 내용을 정확하고 간결하게 설명합니다.
Description check ✅ Passed PR 설명은 관련 이슈, 작업 내용, 배경, 특이 사항, 리뷰 요구사항을 포함합니다. secrets submodule 갱신과 Terraform 검증 결과도 설명합니다. 템플릿의 이슈 연결 표현은 resolves가 아니라 Refs이지만, 설명의 핵심 정보는 대부분 충족합니다.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-08T08:43:44.794210Z 6b040fe New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@Hexeong Hexeong self-assigned this Oct 8, 2026
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Terraform Plan: stage

No changes. Your infrastructure matches the configuration.

전체 plan 결과는 보안을 위해 댓글에 포함되지 않습니다. 워크플로우 실행 아티팩트를 확인하세요.

@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Terraform Plan: prod

No changes. Your infrastructure matches the configuration.

전체 plan 결과는 보안을 위해 댓글에 포함되지 않습니다. 워크플로우 실행 아티팩트를 확인하세요.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c8426f9180

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +36 to +39
variable "db_ec2_private_ip" {
description = "DB EC2에 고정할 Private IP (db_ec2_subnet_id 의 CIDR 안에 있어야 합니다)"
type = string
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Update the secrets submodule for the required IP input

The prod plan/apply workflows check out config/secrets recursively and load prod_db.tfvars, but this commit leaves the submodule pinned at the previous cbceeaaba7de5fa1c944732d2223759fe4a44d2a revision. Because this new variable has no default, Terraform requires the pinned file to define it (HashiCorp variable reference); otherwise the prod CI run triggered by these changes cannot generate a plan or apply. Update the submodule pointer to the revision containing db_ec2_private_ip in the same change.

Useful? React with 👍 / 👎.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Terraform Plan: global

No changes. Your infrastructure matches the configuration.

전체 plan 결과는 보안을 위해 댓글에 포함되지 않습니다. 워크플로우 실행 아티팩트를 확인하세요.

@github-actions

github-actions Bot commented Oct 8, 2026

Copy link
Copy Markdown

Terraform Plan: monitoring

No changes. Your infrastructure matches the configuration.

전체 plan 결과는 보안을 위해 댓글에 포함되지 않습니다. 워크플로우 실행 아티팩트를 확인하세요.

@lsy1307 lsy1307 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

클린합니다

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants