Work Infrastructure · AWS
Private media pipeline in Terraform
A Terraform reference for private S3 delivery through CloudFront OAC and a separate image moderation event pipeline.
Sample · not deployed
- The problem
- Uploaded media needs to stay private while a review process runs, and published files need a controlled path to viewers.
- My approach
- Keep upload and delivery buckets separate; grant CloudFront access to one bucket through OAC and send new uploads through Lambda, Rekognition, and SQS for review.
- What I built
- A Terraform sample with reusable modules, environment variables, scoped IAM, a Python event handler, and validation tests. It has not been deployed or production tested.
Next step
Want something like this for your business?
Pick whichever is easiest. If there’s a good fit, I’ll send a short written scope. If not, I’ll tell you, and you’ll leave with at least one useful idea.
Book a 15-minute callPick a time that works for you. Opens my Google Calendar booking page.Choose a time ↗EmailSend a link to your site and what’s bugging you.brad@bradhobbs.dev
I reply within one business day.