M4 · BOUN-11466Tonyno repo mapped
F4.2 — Dashboard hosting, CDN & access control
Not startedMedium confidence
Serve the dashboard and the snapshot JSON from one place, and decide + implement who can see it. This resolves the M3 plan's open question (“public-read vs CloudFront vs signed access to the snapshot bucket”) and step-functions.md open question 4 (cache policy/CDN between the private snapshot bucket and the HTML page).
No PRs and the sole story is still todo; the hosting/CDN/access-control decisions (bucket and distribution ownership, signed cookies vs basic-auth vs Cognito) haven't started, 17 days since the ticket was last touched.
0%
Unchanged since last snapshot
- Since last activity
- 17d
- Oldest staged work
- —
- Acceptance criteria covered
- 0/5
- PRs open
- 0
Stories
- No branch or PR yet
1 tracked · 1 to do
Acceptance criteria
- Dashboard assets and the snapshot JSON are served from one CloudFront distribution over two private, origin-access-only S3 bucketsno signal
- Long-lived caching for hashed assets; short TTL/revalidation on latest.json so a fresh snapshot is visible within ~1 minuteno signal
- Access control is decided and implemented, with the decision recorded on the ticket and in Confluenceno signal
- Terraform owns buckets/distribution/certificates; nothing stateful in SAMno signal
- A runbook entry covers invalidation and end-to-end snapshot-freshness verificationno signal
Gaps
- Dashboard assets and the snapshot JSON are served from one CloudFront distribution over two private, origin-access-only S3 buckets — no ticket or code
- Long-lived caching for hashed assets; short TTL/revalidation on latest.json so a fresh snapshot is visible within ~1 minute — no ticket or code
- Access control is decided and implemented, with the decision recorded on the ticket and in Confluence — no ticket or code
- Terraform owns buckets/distribution/certificates; nothing stateful in SAM — no ticket or code
- A runbook entry covers invalidation and end-to-end snapshot-freshness verification — no ticket or code
Criteria are read from the ticket description on every run. A gap closes on its own once a story or PR matching it appears — nothing here is closed by hand.