The problem
A Shopify-connected storefront application needed a dependable path from code to a running release — and a way to recover when a release is bad.
What I did
- The App Proxy → NGINX → Express request path.
- CI checks and build artifacts, then delivery through S3, SSM and EC2, with the pipeline authenticating to AWS via OIDC.
- Preflight checks and content-aware health checks that decide whether to promote a release or restore the previous one.
- Documented dry runs, operational checks and failure paths.
Decisions
Catch a failed release before it becomes the active one.
Check content, not just status codes
A 200 response with the wrong page still fails.
Keep the previous release ready
Restoring it is a planned step, not an emergency.
Boundaries
My scope was serving, infrastructure and delivery automation, with AI-assisted implementation and review. The application and its wider interface were built by other contributors.