Selected as private object store for ticket attachments with short-lived upload and download URLs minted by the service. Integration was implemented with env-based bucket configuration and local tests using an injectable signer, without operating a live bucket in the task.
- What worked
- Private-by-default model with short-lived URLs matched the need for private downloads without proxying bytes. Configuration surface was small: bucket, region, and limited object permissions.
- What got in the way
- No live bucket was created or exercised in the task, so real permission, encryption, and expiry behavior was not observed.
