For AI agents: visit https://docs.backbonehq.io/llms.txt for an index of all pages formatted in Markdown and endpoints in OpenAPI. Append .md to any documentation page URL to get its markdown version.
Jump to Content
Backbone DocsBackbone Docs
GuidesAPI Reference
Backbone Docs
Guides
Log In
Jump to Content
Backbone DocsBackbone Docs
GuidesAPI Reference
Log In
  • Welcome
  • Platform features
  • Onboarding
  • Development
  • Operations
  • Cheatsheet
  • Runbook
  • Platform security posture
  • User authentication
  • Service authentication
  • Compliance
  • Audit logging
  • Notification delivery
  • AWS platform infrastructure
  • Application caching and distributed scale
  • Rate limiting
  • Circuit breakers
  • Observability architecture
  • Infrastructure monitoring
  • Application telemetry
  • Health checks
  • Performance Testing Summary
  • ECS Performance Testing Plan (Native + k6)
  • ECS Performance Test Design (Native + k6)
  • Performance Testing Baseline (Local Environment)
  • ECS Performance Testing Results (5× Run Analysis)
  • ECS Baseline Phase 2 - Performance Envelope and Operating Point
  • ECS Scaling Phase 4 — 100 VU Performance Envelope and Operating Point
  • ECS Scaling Phase 4 — 200 VU Performance Envelope and Operating Point
  • Architecture Decision Records (ADRs)
  • 0001. Record architecture decisions
  • 0002. Adoption of Quarkus for API and Controller Tier
  • 0003. Authentication and User Management Approach
  • 0004. Use AWS Cognito Across All Environments (Production and Development)
  • 0005. Implement Service-to-Service Authentication Using AWS STS AssumeRoleWithWebIdentity
  • 0006. Internal Third-Party API Wrapper: Standalone Service vs Library
  • 0007. Observability Strategy
  • 0008. Decoupling micro-services — transitioning from REST to SQS
  • 0009. User Profile Storage Strategy
  • 0010. REST API Design Standards
  • 0011. Stateless JWT Authentication
  • 0012. Clean Architecture Package Structure Standards
  • 0013. Migration from MapStruct to Manual Mappers
  • 0014. Application Caching Strategy
  • 0015. Notification Service Fire-and-Forget / Asynchronous Messaging Pattern
  • 0016. Notification Service Rate Limiting Strategy
  • 0017. Notification Service Template Storage
  • 0018. Notification Service Template Engine Selection
  • 0019. Notification Service Unsubscribe Token Security
  • 0020. Single VPC per environment
  • 0021. Environment-aware removal policies for CDK-managed resources
  • 0022. Internet-facing ALB edge and origin protection
  • 0023. DNSSEC and Route 53 hosted zones (baseline posture)
  • 0024. Internal (private) ALB TLS for east-west traffic (optional)
  • 0025. Static UI hosting on CloudFront and S3
  • 0026. Observability backend strategy
  • 0027. Governance evidence architecture
  • 0028. Governance evidence Object Lock retention
  • 0029. Customer-managed KMS per domain (opt-in, greenfield, BYOK)
Powered by 
  1. architecture-decisions

0022. Internet-facing ALB edge and origin protection

This ADR has been redacted for security purposes.

Full text ships with the licensed backbone-platform repository.

Updated about 2 months ago


0021. Environment-aware removal policies for CDK-managed resources
0023. DNSSEC and Route 53 hosted zones (baseline posture)
Did this page help you?