Normative decision: Open decision 14
Decision needed
Approve dedicated two-AZ VPC, public ALB, tightly restricted public-IP ECS tasks, isolated private RDS, and no NAT gateway for sandbox; keep production inputs capable of private tasks plus NAT/endpoints.
Non-goals
Do not reuse the default VPC implicitly or weaken task/database security-group boundaries.
Acceptance criteria
Validation scenarios
Review plan/network reachability: internet cannot reach task ports or RDS; tasks can reach locked dependencies; origin bypass is controlled.
Dependencies
Blocks sandbox Terraform implementation under #9.
Normative decision: Open decision 14
Decision needed
Approve dedicated two-AZ VPC, public ALB, tightly restricted public-IP ECS tasks, isolated private RDS, and no NAT gateway for sandbox; keep production inputs capable of private tasks plus NAT/endpoints.
Non-goals
Do not reuse the default VPC implicitly or weaken task/database security-group boundaries.
Acceptance criteria
Validation scenarios
Review plan/network reachability: internet cannot reach task ports or RDS; tasks can reach locked dependencies; origin bypass is controlled.
Dependencies
Blocks sandbox Terraform implementation under #9.