Skip to content

Decision: Approve the cost-aware sandbox network topology #25

Description

@alexeygrigorev

Normative decision: Open decision 14

Decision needed

Approve dedicated two-AZ VPC, public ALB, tightly restricted public-IP ECS tasks, isolated private RDS, and no NAT gateway for sandbox; keep production inputs capable of private tasks plus NAT/endpoints.

Non-goals

Do not reuse the default VPC implicitly or weaken task/database security-group boundaries.

Acceptance criteria

  • Cost/security tradeoff is approved with expected recurring cost.
  • Task ingress is ALB-only and database ingress task-only.
  • Production portability inputs are identified.
  • Terraform policy tests encode the approved topology.

Validation scenarios

Review plan/network reachability: internet cannot reach task ports or RDS; tasks can reach locked dependencies; origin bypass is controlled.

Dependencies

Blocks sandbox Terraform implementation under #9.

Metadata

Metadata

Assignees

No one assigned

    Labels

    P0Must-have or release-blockingdecisionOwner decision requiredinfraArea: infrasecurityArea: security

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions