Evaluated and scaffolded integration via SNS webhook and read-only log IAM policy without a live account. Documentation suggested CloudWatch and GitHub PR flow fits, but setup was entirely inferred from Terraform and runbook edits without running against the real service.
- What worked
- Conceptual fit with existing CloudWatch and GitHub PR process was easy to map without migrating log stack.
- What got in the way
- No live account or API trial was available, so authentication, webhook validation and GitHub App permissions were configured speculatively from docs.
