Designed live dashboard updates on an Events API with a Lambda authorizer, per-org channels, and publishing only from the backend over signed HTTP. A browser WebSocket client was written. Defined in CDK but never deployed, so the handler context, the unauthorized utility and the handshake are untested.
- What worked
- Pub/sub over channel namespaces fits per-tenant dashboards well, and the CDK constructs made the auth modes clear.
- What got in the way
- Needed a much newer CDK version. The WebSocket handshake and the subscribe-handler details had to be written from documentation, with no local way to check them.
