# Tokyo Resource Inventory 最后更新:`2026-05-21` 这个文件记录当前东京迁移的真实实施状态,不是示例。 ## Region - AWS account: `hifastvpn (200810848252)` - Region: `ap-northeast-1` ## Current Status - 东京迁移方案已在仓库内落地为执行资产 - 东京 VPC 已创建 - 东京子网、IGW、路由表已在 AWS 控制台创建并复核 - 东京三层安全组已在 AWS 控制台创建并复核 - 东京 VPC DNS 开关已开启,可支持公网可访问 RDS - 东京 S3 备份桶已在 AWS 控制台创建并复核 - 东京 ACM 证书请求已创建,等待 DNS 验证 - 东京 RDS MySQL 已创建完成并可用 - 东京业务 EC2 已创建完成并绑定固定 EIP - 因当前本机没有可用 AWS CLI 凭据,云上资源状态仍需在 AWS 控制台或已登录环境中复查 ## Networking - VPC - Name: `ppanel-jp-prod` - VPC ID: `vpc-0846b23b4a7d64eac` - CIDR: `10.20.0.0/16` - Status: `created` - Public subnet A - Name: `ppanel-jp-public-a` - AZ: `ap-northeast-1a` - CIDR: `10.20.0.0/24` - Subnet ID: `subnet-091232bdb53e71490` - Status: `created` - Public subnet C - Name: `ppanel-jp-public-c` - AZ: `ap-northeast-1c` - CIDR: `10.20.1.0/24` - Subnet ID: `subnet-01ba0975c525ce8cf` - Status: `created` - Private subnet A - Name: `ppanel-jp-private-a` - AZ: `ap-northeast-1a` - CIDR: `10.20.10.0/24` - Subnet ID: `subnet-0bd13111c02f0edbe` - Status: `created` - Private subnet C - Name: `ppanel-jp-private-c` - AZ: `ap-northeast-1c` - CIDR: `10.20.11.0/24` - Subnet ID: `subnet-0d86c5c756dbc84b2` - Status: `created` - Internet Gateway - Name: `ppanel-jp-igw` - IGW ID: `igw-028041bcbf63b672c` - Status: `created` - Public route table - Name: `ppanel-jp-public-rt` - Route Table ID: `rtb-061b101080e4800e5` - Default route: `0.0.0.0/0 -> igw-028041bcbf63b672c` - Status: `created` - Private route table - Name: `ppanel-jp-private-rt` - Route Table ID: `rtb-0d7a191a515031c45` - Status: `created` ## Security - `sg-alb` - Name: `ppanel-jp-sg-alb` - Security Group ID: `sg-0b3a23c31041a5a5a` - Inbound: - `80/tcp <- 0.0.0.0/0` - `443/tcp <- 0.0.0.0/0` - Status: `created` - `sg-ec2` - Name: `ppanel-jp-sg-ec2` - Security Group ID: `sg-01f2a5a81e7505c91` - Inbound: - `80/tcp <- sg-0b3a23c31041a5a5a` - `22/tcp <- 64.118.144.142/32` - `6379/tcp <- 104.238.220.230/32` - Status: `created` - `sg-rds` - Name: `ppanel-jp-sg-rds` - Security Group ID: `sg-0b71db1e2c18b57c0` - Inbound: - `3306/tcp <- sg-01f2a5a81e7505c91` - `3306/tcp <- 104.238.220.230/32` - Status: `created` ## Compute / Database / Edge - EC2 `ppanel-app-jp-01`: - Instance ID: `i-07839130074cd7ed9` - Type: `c7i.xlarge` - Platform: `Ubuntu 26.04 / Linux` - AZ: `ap-northeast-1c` - VPC: `ppanel-jp-prod (vpc-0846b23b4a7d64eac)` - Subnet: `ppanel-jp-public-c (subnet-01ba0975c525ce8cf)` - Private IP: `10.20.1.168` - Public IP / Elastic IP: `3.114.29.208` - Public DNS: `ec2-3-114-29-208.ap-northeast-1.compute.amazonaws.com` - Security group: `ppanel-jp-sg-ec2 (sg-01f2a5a81e7505c91)` - Key pair: `ppanel-jp-key-20260521` - Root volume: `gp3 100GiB` - ENI: `eni-08accb427a470c9f7` - EIP allocation ID: `eipalloc-038b32d5c0119accf` - EIP association ID: `eipassoc-09184aa9161b6a4d9` - Status: `running` - SSH recovery private key: `deploy/aws/ap-northeast-1/keys/ppanel-jp-recovery` - SSH recovery public key: `deploy/aws/ap-northeast-1/keys/ppanel-jp-recovery.pub` - RDS subnet group: - Name: `ppanel-jp-rds-subnet-group` - VPC: `vpc-0846b23b4a7d64eac` - Subnets: - `subnet-0bd13111c02f0edbe` / `ppanel-jp-private-a` - `subnet-0d86c5c756dbc84b2` / `ppanel-jp-private-c` - Status: `created` - RDS public subnet group: - Name: `ppanel-jp-rds-public-subnet-group` - VPC: `vpc-0846b23b4a7d64eac` - Subnets: - `subnet-091232bdb53e71490` / `ppanel-jp-public-a` - `subnet-01ba0975c525ce8cf` / `ppanel-jp-public-c` - Status: `created` - RDS `ppanel-mysql-jp`: - Engine: `MySQL Community 8.4.8` - Class: `db.r7g.xlarge` - Storage: `gp3 100GiB` - Deployment: `Single instance (current actual state)` - VPC: `ppanel-jp-prod (vpc-0846b23b4a7d64eac)` - Subnet group: `ppanel-jp-rds-public-subnet-group` - Security group: `ppanel-jp-sg-rds (sg-0b71db1e2c18b57c0)` - Master username: `admin` - Credential management: `self-managed` - Secrets Manager managed password: `disabled` - Current master password visibility: `not retrievable from AWS console; reset only` - Public access: `enabled (set at creation time for external replication)` - Status: `available` - Endpoint: `ppanel-mysql-jp.cpo0keikgh80.ap-northeast-1.rds.amazonaws.com` - Public IP (resolved via public DNS): `52.196.204.186` - Connection test from Tokyo EC2: - `mysql -h ppanel-mysql-jp.cpo0keikgh80.ap-northeast-1.rds.amazonaws.com -u admin -e "select 1"` - Result: `ERROR 1045 (28000): Access denied for user 'admin'@'ip-10-20-1-168.ap-northeast-1.compute.internal' (using password: NO)` - Meaning: `network path and security group are working; only the password is missing` - Current admin password: `TkyRds20260521!N9mQ8sKe2vLp7Xa` - External replica prep for `104.238.220.230`: - binlog retention hours: `24` - replication user: `repl@104.238.220.230` - replication password: `XwWrQGVWtxmXJ3etHmkFvnRSD54MKYer` - current binlog file: `mysql-bin-changelog.000189` - current binlog position: `185053` - ALB `ppanel-alb-jp`: `not created` - WAF `ppanel-waf-jp`: `not created` - ACM certificate in `ap-northeast-1`: - Certificate ID: `29d0b9b6-ab37-44d9-ad9e-18fa7e9aae3a` - Domains: - `api-jp.hifast.biz` - `logs-jp.hifast.biz` - Status: `pending_validation` - Route 53 hosted zone in current AWS account: `not found` - S3 backup bucket `hifast-prod-backups-200810848252-ap-northeast-1`: `created` ## Domains - Parallel API domain: `api-jp.hifast.biz` - Parallel logs domain: `logs-jp.hifast.biz` - Production API domain: `pending user final confirmation` - ACM DNS validation records pending external DNS add: - `api-jp.hifast.biz` - Name: `_0de5970dfbadaf46759447b2ea627a10.api-jp.hifast.biz.` - Type: `CNAME` - Value: `_6a632a5b85c5b3f304cc492090b741b3.jkddzztszm.acm-validations.aws.` - `logs-jp.hifast.biz` - Name: `_349a2b2bc4678d76c3ab341ccf73db61.logs-jp.hifast.biz.` - Type: `CNAME` - Value: `_74ced20dc96aa39070188605cf0ced18.jkddzztszm.acm-validations.aws.` ## DR - DR host: `104.238.220.230` - Planned MySQL upstream after cutover: `Tokyo RDS` - Planned Redis upstream after cutover: `Tokyo EC2 public IP`