krisgrzepka.com / infrastructure

How this page
reached you.

Every service below is on the real path between your browser and this file. The timings are not illustrations — they were measured in your browser as the page loaded, and they change every time you open it.

Region eu-west-2 London Origin private S3 + OAC Provisioned with Terraform Running cost ~$0/mo
Client

Your browser

Where this request started

0 ms
Edge · 400+ locations worldwide

Route 53

Resolves krisgrzepka.com to the nearest CloudFront edge

Alias record — no extra hop, no charge for the lookup

ACM certificate

TLS handshake terminates at the edge, not at the origin

Issued in us-east-1, DNS-validated, renews itself

CloudFront

Serves this file from the edge closest to you

Time to first byte — cache decision made here

Origin · eu-west-2 London

S3

Reached only when the edge does not already hold the file

Public access blocked — only CloudFront can read it, via OAC

on cache miss
Measured in your browser
ms to first byte

Reading your connection…

Decisions worth defending

The bucket is not a website
S3 static hosting is off and public access is blocked. CloudFront reaches it with Origin Access Control, so the only route to the file is through the CDN.
TLS ends at the edge
ACM issues and renews the certificate on its own. Nothing expires quietly at 3am, because no human is in the renewal path.
One route, one permission
The API exposes a single POST route, and the Lambda's role allows sending mail — not reading the bucket, not touching DNS.
Rebuildable from source
Every resource on this page is declared in Terraform. Deleting the account and running apply reproduces it.