Skip to content
79%
Epic complete 1 pts since last snapshot
47 shipped23 done, unverified2 staged2 in review
M4 · BOUN-11466Tonyno repo mapped

F4.2 — Dashboard hosting, CDN & access control

Not startedMedium confidence

Serve the dashboard and the snapshot JSON from one place, and decide + implement who can see it. This resolves the M3 plan's open question (“public-read vs CloudFront vs signed access to the snapshot bucket”) and step-functions.md open question 4 (cache policy/CDN between the private snapshot bucket and the HTML page).

No PRs and the sole story is still todo; the hosting/CDN/access-control decisions (bucket and distribution ownership, signed cookies vs basic-auth vs Cognito) haven't started, 17 days since the ticket was last touched.

0%
Unchanged since last snapshot
Since last activity
17d
Oldest staged work
Acceptance criteria covered
0/5
PRs open
0

Stories

1 tracked · 1 to do

Acceptance criteria

  • Dashboard assets and the snapshot JSON are served from one CloudFront distribution over two private, origin-access-only S3 bucketsno signal
  • Long-lived caching for hashed assets; short TTL/revalidation on latest.json so a fresh snapshot is visible within ~1 minuteno signal
  • Access control is decided and implemented, with the decision recorded on the ticket and in Confluenceno signal
  • Terraform owns buckets/distribution/certificates; nothing stateful in SAMno signal
  • A runbook entry covers invalidation and end-to-end snapshot-freshness verificationno signal

Gaps

  • Dashboard assets and the snapshot JSON are served from one CloudFront distribution over two private, origin-access-only S3 bucketsno ticket or code
  • Long-lived caching for hashed assets; short TTL/revalidation on latest.json so a fresh snapshot is visible within ~1 minuteno ticket or code
  • Access control is decided and implemented, with the decision recorded on the ticket and in Confluenceno ticket or code
  • Terraform owns buckets/distribution/certificates; nothing stateful in SAMno ticket or code
  • A runbook entry covers invalidation and end-to-end snapshot-freshness verificationno ticket or code

Criteria are read from the ticket description on every run. A gap closes on its own once a story or PR matching it appears — nothing here is closed by hand.