INTERNAL ONLY • NBCB POD TALK

Very Secure Storage™ Metrics Panel

Super Confidential. Reminder to self: Must whitelist to our company IP address...
EC2 CPU
17%
Load low, vibes high
EC2 Memory
42%
No swap, no stress
Root Disk
68%
/var/log a bit thicc
Network (in/out)
2.6 / 0.9 MBps
Last 60s average
HTTP 5xx
0.9%
Mostly fine, mostly
Active Sessions
128
pod-talk-web + storage-panel
CloudFront Hits
92%
Cache doing overtime
Origin Pulls (S3)
8%
Assets mostly cached
S3 Storage Used
14.2 GB
nbcb-static-files
public-read: yes
IAM Risk Score
MEDIUM
Least privilege pending
Instance Info RUNNING
InstanceId: i-0nbcb12345f00dbabe InstanceType: t3.small Region: ap-southeast-1 AZ: ap-southeast-1a PrivateIP: 10.0.2.41 Uptime: 4d 07h 12m AMI: ubuntu-22.04-lts IMDS: v1 enabled (legacy)
Note: values may be delayed due to “migration mode”.
Service Health GREEN
ServiceStatusNotes
pod-talk-webOKresponding normally
trend-scraperDEGRADEDrate limiting by “someone”
very-secure-storageOKvault locked (probably)
cdn-originOKstatic assets served fast
metrics-panelOKdefinitely not leaking anything
Heads up: we’re still moving old on-prem stuff into cloud storage. If you see folders like /backup/ or /static-archive/, pretend you didn’t.
Traffic SnapshotLast 5 mins
Requests/min380
Error rate0.9%
p95 latency210ms
Top endpoint/api/fetch?url=
Totally harmless URL fetcher
Recent Logs (sanitized)tail -n 14
[INFO] 2025-12-02 08:01:12 healthcheck OK [INFO] 2025-12-02 08:02:09 /static/style.css served via CDN [WARN] 2025-12-02 08:03:44 backup sync retrying: s3://nbcb-static-files/backup/ [INFO] 2025-12-02 08:04:01 migration job: onprem-export.xml copied [WARN] 2025-12-02 08:04:55 IMDS v1 still enabled for legacy app [INFO] 2025-12-02 08:05:13 user "chan-ma-li" tested least privilege [INFO] 2025-12-02 08:05:57 /secrets/flag1 access denied (as expected) [WARN] 2025-12-02 08:06:30 cloudfront dir listing blocked in browser
Sanitized means “we removed the scary parts”. Mostly.
Security Group Snapshotsg-0nbcb00badbeef
PortSourceReason
22/tcp0.0.0.0/0temporary admin access (will close later)
80/tcp0.0.0.0/0pod-talk web
443/tcp0.0.0.0/0cdn + storage panel
9100/tcp10.0.0.0/16node exporter
“Temporary” since 2023-eh.
IAM Findingslast scan: 6h ago
FindingSeverityNotes
iam:AddUserToGroup detectedHIGHneeded for migration scripts (??? maybe idk)
Access keys older than 90 daysMEDrotate after launch
MFA missing on 1 userLOWuser said “later lah”
S3 Hot Foldersnbcb-static-files
PrefixObjectsNotes
/static/1,204public CDN assets
/backup/12old exports + “final_final.zip”
/admin/4requires authenticated access
/secrets/1do not touch pls
Scheduled Jobssystemd timers
02:00 backup-sync.service s3://nbcb-static-files/backup/ 03:30 log-rotate.service /var/log/nginx/* 04:15 metrics-push.service pushgateway:9091 05:00 migration-retry.service /opt/migrate_secrets.ps1
Some jobs run with “elevated” roles for convenience.
Search Resultstype anything above