Notes
Notes and explorations on various topics.
- AWS GovCloud Architecture: SPA + Small Backend, Cognito-Gated
· aws, govcloud, cognito, ecs, alb, architecture
Single-partition GovCloud design for an SPA + ECS backend gated by a Cognito user pool owned by another team.
- Frontend + Router Integration Architecture Options
· aws, architecture, frontend, api-gateway, bff
Compares AWS-native frontend, BFF, and router integration patterns for protected SPA and partner API access.
- AWS GovCloud Authenticated SPA and API Router
· aws, govcloud, fedramp, architecture, authentication, spa, api
Reference architecture for a FedRAMP High GovCloud React SPA, authenticated asset delivery, API router, partner SDKs, and machine-to-machine access.
- GovCloud SaaS Platform Architecture
· aws, govcloud, architecture, cognito, avp, alb, smithy, rbac
AWS-native architecture for a GovCloud-deployable SaaS with React SPA, pluggable OIDC IdP, AVP-based RBAC, unified ALB front door, and Smithy-generated SDK.
- Centralized API Router
· aws, api-gateway, alb, avp, smithy, architecture
Why and how to put API Gateway behind the ALB to centralize auth, AVP, error shaping, and cross-cutting API concerns instead of duplicating them in every service.
- Frontend Story
· react, vite, nginx, fargate, frontend, spa, accessibility, otel
React SPA design: stack, build, deploy as nginx on Fargate, SDK consumption, telemetry, security headers, dev workflow, accessibility for gov.
- Partner API
· aws, api-gateway, oauth, sdk, avp, partner, architecture
Public partner-facing API surface: dedicated domain, REST API Gateway, OAuth client-credentials, scopes, versioning, SDK distribution, and operational surface.
- Session Management
· auth, session, cognito, alb, oidc, fedramp, frontend
How session lifetime, silent refresh, idle timeout, and expiry handling work in the SPA — the standard pattern for gov/regulated SaaS.
- GovCloud-Compatible React SPA Architecture
· aws, govcloud, cognito, alb, spa, architecture
ALB-fronted architecture for a Cognito-authenticated React SPA with companion APIs in AWS GovCloud.
- React SPA + Keycloak on GovCloud — Serverless Variant
· aws, govcloud, keycloak, oidc, react, spa, fedramp, serverless, lambda, architecture
ALB + Lambda target groups variant of the GovCloud Keycloak SPA design — eliminates Fargate while keeping the OIDC enforcement layer on the ALB.
- Hierarchical Multi-Org API Patterns
· multi-tenant, api-design, authorization, rbac
How established platforms model hierarchical org trees, scope APIs, place resources at create time, and move them between orgs.
- React SPA + Keycloak Auth on AWS GovCloud
· aws, govcloud, keycloak, oidc, react, spa, fedramp, architecture
High-level architecture and sequence diagrams for a Keycloak-protected React SPA hosted on AWS GovCloud, with auth required before any frontend asset is served.
- GovCloud SPA Hosting: ECS/nginx vs Internal ALB + S3
· govcloud, spa, s3, alb, keycloak, oidc, cdk
Whether to keep building a Docker image per frontend release or migrate React SPA assets to S3 behind the existing OIDC-gated ALB in GovCloud.
- Detecting Flaky Playwright Tests in CI with an Allowlist
· playwright, ci, github-actions, flaky-tests
GitHub Actions workflow that repeat-runs tests to catch new flakes, with a tag-based allowlist for incremental adoption.
- SPA + BFF Architectures on AWS
· aws, bff, spa, cloudfront, lambda, fargate, api-gateway, app-runner, appsync, amplify
Comparison of AWS-native topologies for a single-page app fronted by a Backend-for-Frontend service.
- SPA + BFF with Keycloak AuthN and AVP AuthZ
· aws, bff, spa, keycloak, oidc, avp, cedar, fedramp, govcloud
Frontend architecture options when a separate team owns Keycloak for identity and authorization uses Amazon Verified Permissions driven by JWT claims.
- GovCloud-Compatible React SPA on ECS Fargate
· aws, govcloud, cdk, ecs-fargate, alb, spa
Serve a Vite SPA from nginx on Fargate behind an internal ALB, with no CloudFront, no NAT, no public endpoints. GovCloud-ready.
- Keycloakify Pipeline: Build, Test, Deploy
· keycloak, keycloakify, ci-cd, auth, aws
Owning a Keycloakify project end-to-end — dev loop, testing, CI/CD, and deploying themes to a running Keycloak.
- AWS-Native Frontend Operational Excellence
· aws, cloudfront, observability, opex, orr, lambda-edge, rum, synthetics, waf, x-ray
Complete observability, release, on-call, and ORR strategy for a CloudFront + Lambda@Edge + S3 frontend application.
- Upstream Fork Strategy
· git, workflow, ci
How to maintain a customized fork of another team's codebase with automated upstream syncing.
- Context
- Design
- 0001 Agent Is A Ui Not A Trust Boundary
- 01 Hello World Chat Panel And Echo Backend
- 02 Bedrock Text Conversation Streaming
- 03 Observability Baseline
- 04 Navigation Intents End To End
- 05 First End To End Tool Call
- 06 Smithy To Manifest Generator
- 07 Runbook Kb And Lookup Tool
- 08 Risk Classes And Approval Card Hardening
- 09 Out Of Scope Handoff
- 10 Production Polish Errors Truncation Projection
- Prd
- ai-chat
- docs
- issues
- •Prd
Loading graph…
Nodes are notes; edges connect notes that share at least one tag.