Blog

All posts
John Damask · 2026-03-03
devlogdeploymenttestingverification

The deploy script split was merged, and the test environment got its first real deployment. Running deploy-test.sh from main provisioned the entire stack from scratch in the test account -- a clean-slate validation of the script's idempotent resource creation logic.

The deployment created everything the script promises: Secrets Manager entry for the Anthropic API key, two new S3 buckets (one for Lambda artifacts, one for PDF uploads with public-read policy and CORS), an ACM certificate with automated DNS validation via the Route 53 hosted zone, the ECR repository with a freshly-built Playwright/Chromium screenshot image, and the full CloudFormation stack (8 Lambda functions, API Gateway, DynamoDB, CloudFront distribution, Route 53 records). The whole deploy completed without errors.

A manual end-to-end test confirmed the pipeline works: uploaded a neuroscience paper (Goldstein & Volkow, "Dysfunction of the prefrontal cortex in addiction"), Claude processed it, and the generated interactive page appeared on the test domain with a working thumbnail. The automated smoke test hit every API endpoint -- frontend pages (200), upload presigned URL generation (200), status polling (complete with cost breakdown), library (1 article), gallery with thumbnail (200), and stats endpoints. All green.

The account guard worked as designed -- the script's first action is verifying aws sts get-caller-identity returns the expected account ID, so there's no risk of accidentally deploying to prod. The test environment is now a fully independent replica: separate S3 buckets, separate DynamoDB table, separate CloudFront distribution, separate domain, all in a separate AWS account. Changes can be validated end-to-end before touching production.