fix(lambdas): write main data file under data/ prefix (fixes stale content root cause) - #3

Merged
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix
Jun 7, 2026
Merged

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause)#3
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix

Conversation

@datj9

@datj9datj9 commented Jun 7, 2026

Copy link
Copy Markdown
Owner

Root cause of the stale content

While verifying #1 end-to-end (invoking the deployed `gh_trending` Lambda), CloudWatch revealed the actual reason trending/HN/release content was outdated:

```
ERROR Failed to upload to S3
AccessDenied ... s3:PutObject on .../gh-trending.json
because no identity-based policy allows the s3:PutObject action
```

All three Lambdas upload their main file to a bucket-root key (`gh-trending.json`, `hn-digest.json`, `release-radar.json`), but the IAM policy grants `s3:PutObject` on the `data/*` prefix only (`tech-bytes-stack.ts:180`). So every main-file write has always failed with AccessDenied. Only the archive copies (already under `data/archive/`) persisted.

Consequences that all trace back to this:

  • The site reads `data/gh-trending.json` → never written → fell back to the committed May-12 seed file → stale page.
  • `email_digest` reads `data/{release-radar,hn-digest,gh-trending}.json` → never written → empty digest sections.
  • `release_radar` appeared to "produce no output" → it did, the write just 403'd.
  • `deploy.yml` only syncs `s3://BUCKET/data/` → root-level files were invisible to the build anyway.

Change

One-line fix per handler — prefix `S3_KEY` with `data/`:

  • `gh_trending`: `gh-trending.json` → `data/gh-trending.json`
  • `hn_digest`: `hn-digest.json` → `data/hn-digest.json`
  • `release_radar`: `release-radar.json` → `data/release-radar.json`

This aligns the write path with the IAM grant, the `email_digest` read keys, the site read path, and the deploy sync. No infra change — `data/*` is already granted.

Test plan

  • Parser unit tests still pass
  • Confirmed IAM grant is `data/*` (tech-bytes-stack.ts:180)
  • Post-merge: re-invoke each Lambda; confirm `data/*.json` now writes (no AccessDenied) and the live site shows fresh trending data

The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
@datj9
datj9 merged commit 6a71cd1 into masterJun 7, 2026
2 checks passed
datj9 added a commit that referenced this pull request Jul 11, 2026
The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
Co-authored-by: Dat <dat.nguyen@ringkas.co.id>
@datj9
datj9 deleted the fix/lambda-s3-key-prefix branch July 11, 2026 05:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@datj9@datnguyen-ringkas
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause) - #3

Merged
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix
Jun 7, 2026
Merged

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause)#3
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix

Conversation

@datj9

@datj9datj9 commented Jun 7, 2026

Copy link
Copy Markdown
Owner

Root cause of the stale content

While verifying #1 end-to-end (invoking the deployed `gh_trending` Lambda), CloudWatch revealed the actual reason trending/HN/release content was outdated:

```
ERROR Failed to upload to S3
AccessDenied ... s3:PutObject on .../gh-trending.json
because no identity-based policy allows the s3:PutObject action
```

All three Lambdas upload their main file to a bucket-root key (`gh-trending.json`, `hn-digest.json`, `release-radar.json`), but the IAM policy grants `s3:PutObject` on the `data/*` prefix only (`tech-bytes-stack.ts:180`). So every main-file write has always failed with AccessDenied. Only the archive copies (already under `data/archive/`) persisted.

Consequences that all trace back to this:

  • The site reads `data/gh-trending.json` → never written → fell back to the committed May-12 seed file → stale page.
  • `email_digest` reads `data/{release-radar,hn-digest,gh-trending}.json` → never written → empty digest sections.
  • `release_radar` appeared to "produce no output" → it did, the write just 403'd.
  • `deploy.yml` only syncs `s3://BUCKET/data/` → root-level files were invisible to the build anyway.

Change

One-line fix per handler — prefix `S3_KEY` with `data/`:

  • `gh_trending`: `gh-trending.json` → `data/gh-trending.json`
  • `hn_digest`: `hn-digest.json` → `data/hn-digest.json`
  • `release_radar`: `release-radar.json` → `data/release-radar.json`

This aligns the write path with the IAM grant, the `email_digest` read keys, the site read path, and the deploy sync. No infra change — `data/*` is already granted.

Test plan

  • Parser unit tests still pass
  • Confirmed IAM grant is `data/*` (tech-bytes-stack.ts:180)
  • Post-merge: re-invoke each Lambda; confirm `data/*.json` now writes (no AccessDenied) and the live site shows fresh trending data

The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
@datj9
datj9 merged commit 6a71cd1 into masterJun 7, 2026
2 checks passed
datj9 added a commit that referenced this pull request Jul 11, 2026
The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
Co-authored-by: Dat <dat.nguyen@ringkas.co.id>
@datj9
datj9 deleted the fix/lambda-s3-key-prefix branch July 11, 2026 05:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@datj9@datnguyen-ringkas
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause) - #3

Merged
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix
Jun 7, 2026
Merged

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause)#3
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix

Conversation

@datj9

@datj9datj9 commented Jun 7, 2026

Copy link
Copy Markdown
Owner

Root cause of the stale content

While verifying #1 end-to-end (invoking the deployed `gh_trending` Lambda), CloudWatch revealed the actual reason trending/HN/release content was outdated:

```
ERROR Failed to upload to S3
AccessDenied ... s3:PutObject on .../gh-trending.json
because no identity-based policy allows the s3:PutObject action
```

All three Lambdas upload their main file to a bucket-root key (`gh-trending.json`, `hn-digest.json`, `release-radar.json`), but the IAM policy grants `s3:PutObject` on the `data/*` prefix only (`tech-bytes-stack.ts:180`). So every main-file write has always failed with AccessDenied. Only the archive copies (already under `data/archive/`) persisted.

Consequences that all trace back to this:

  • The site reads `data/gh-trending.json` → never written → fell back to the committed May-12 seed file → stale page.
  • `email_digest` reads `data/{release-radar,hn-digest,gh-trending}.json` → never written → empty digest sections.
  • `release_radar` appeared to "produce no output" → it did, the write just 403'd.
  • `deploy.yml` only syncs `s3://BUCKET/data/` → root-level files were invisible to the build anyway.

Change

One-line fix per handler — prefix `S3_KEY` with `data/`:

  • `gh_trending`: `gh-trending.json` → `data/gh-trending.json`
  • `hn_digest`: `hn-digest.json` → `data/hn-digest.json`
  • `release_radar`: `release-radar.json` → `data/release-radar.json`

This aligns the write path with the IAM grant, the `email_digest` read keys, the site read path, and the deploy sync. No infra change — `data/*` is already granted.

Test plan

  • Parser unit tests still pass
  • Confirmed IAM grant is `data/*` (tech-bytes-stack.ts:180)
  • Post-merge: re-invoke each Lambda; confirm `data/*.json` now writes (no AccessDenied) and the live site shows fresh trending data

The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
@datj9
datj9 merged commit 6a71cd1 into masterJun 7, 2026
2 checks passed
datj9 added a commit that referenced this pull request Jul 11, 2026
The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
Co-authored-by: Dat <dat.nguyen@ringkas.co.id>
@datj9
datj9 deleted the fix/lambda-s3-key-prefix branch July 11, 2026 05:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@datj9@datnguyen-ringkas
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause) - #3

Merged
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix
Jun 7, 2026
Merged

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause)#3
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix

Conversation

@datj9

@datj9datj9 commented Jun 7, 2026

Copy link
Copy Markdown
Owner

Root cause of the stale content

While verifying #1 end-to-end (invoking the deployed `gh_trending` Lambda), CloudWatch revealed the actual reason trending/HN/release content was outdated:

```
ERROR Failed to upload to S3
AccessDenied ... s3:PutObject on .../gh-trending.json
because no identity-based policy allows the s3:PutObject action
```

All three Lambdas upload their main file to a bucket-root key (`gh-trending.json`, `hn-digest.json`, `release-radar.json`), but the IAM policy grants `s3:PutObject` on the `data/*` prefix only (`tech-bytes-stack.ts:180`). So every main-file write has always failed with AccessDenied. Only the archive copies (already under `data/archive/`) persisted.

Consequences that all trace back to this:

  • The site reads `data/gh-trending.json` → never written → fell back to the committed May-12 seed file → stale page.
  • `email_digest` reads `data/{release-radar,hn-digest,gh-trending}.json` → never written → empty digest sections.
  • `release_radar` appeared to "produce no output" → it did, the write just 403'd.
  • `deploy.yml` only syncs `s3://BUCKET/data/` → root-level files were invisible to the build anyway.

Change

One-line fix per handler — prefix `S3_KEY` with `data/`:

  • `gh_trending`: `gh-trending.json` → `data/gh-trending.json`
  • `hn_digest`: `hn-digest.json` → `data/hn-digest.json`
  • `release_radar`: `release-radar.json` → `data/release-radar.json`

This aligns the write path with the IAM grant, the `email_digest` read keys, the site read path, and the deploy sync. No infra change — `data/*` is already granted.

Test plan

  • Parser unit tests still pass
  • Confirmed IAM grant is `data/*` (tech-bytes-stack.ts:180)
  • Post-merge: re-invoke each Lambda; confirm `data/*.json` now writes (no AccessDenied) and the live site shows fresh trending data

The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
@datj9
datj9 merged commit 6a71cd1 into masterJun 7, 2026
2 checks passed
datj9 added a commit that referenced this pull request Jul 11, 2026
The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
Co-authored-by: Dat <dat.nguyen@ringkas.co.id>
@datj9
datj9 deleted the fix/lambda-s3-key-prefix branch July 11, 2026 05:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@datj9@datnguyen-ringkas
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause) - #3

Merged
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix
Jun 7, 2026
Merged

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause)#3
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix

Conversation

@datj9

@datj9datj9 commented Jun 7, 2026

Copy link
Copy Markdown
Owner

Root cause of the stale content

While verifying #1 end-to-end (invoking the deployed `gh_trending` Lambda), CloudWatch revealed the actual reason trending/HN/release content was outdated:

```
ERROR Failed to upload to S3
AccessDenied ... s3:PutObject on .../gh-trending.json
because no identity-based policy allows the s3:PutObject action
```

All three Lambdas upload their main file to a bucket-root key (`gh-trending.json`, `hn-digest.json`, `release-radar.json`), but the IAM policy grants `s3:PutObject` on the `data/*` prefix only (`tech-bytes-stack.ts:180`). So every main-file write has always failed with AccessDenied. Only the archive copies (already under `data/archive/`) persisted.

Consequences that all trace back to this:

  • The site reads `data/gh-trending.json` → never written → fell back to the committed May-12 seed file → stale page.
  • `email_digest` reads `data/{release-radar,hn-digest,gh-trending}.json` → never written → empty digest sections.
  • `release_radar` appeared to "produce no output" → it did, the write just 403'd.
  • `deploy.yml` only syncs `s3://BUCKET/data/` → root-level files were invisible to the build anyway.

Change

One-line fix per handler — prefix `S3_KEY` with `data/`:

  • `gh_trending`: `gh-trending.json` → `data/gh-trending.json`
  • `hn_digest`: `hn-digest.json` → `data/hn-digest.json`
  • `release_radar`: `release-radar.json` → `data/release-radar.json`

This aligns the write path with the IAM grant, the `email_digest` read keys, the site read path, and the deploy sync. No infra change — `data/*` is already granted.

Test plan

  • Parser unit tests still pass
  • Confirmed IAM grant is `data/*` (tech-bytes-stack.ts:180)
  • Post-merge: re-invoke each Lambda; confirm `data/*.json` now writes (no AccessDenied) and the live site shows fresh trending data

The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
@datj9
datj9 merged commit 6a71cd1 into masterJun 7, 2026
2 checks passed
datj9 added a commit that referenced this pull request Jul 11, 2026
The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
Co-authored-by: Dat <dat.nguyen@ringkas.co.id>
@datj9
datj9 deleted the fix/lambda-s3-key-prefix branch July 11, 2026 05:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@datj9@datnguyen-ringkas
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause) - #3

Merged
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix
Jun 7, 2026
Merged

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause)#3
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix

Conversation

@datj9

@datj9datj9 commented Jun 7, 2026

Copy link
Copy Markdown
Owner

Root cause of the stale content

While verifying #1 end-to-end (invoking the deployed `gh_trending` Lambda), CloudWatch revealed the actual reason trending/HN/release content was outdated:

```
ERROR Failed to upload to S3
AccessDenied ... s3:PutObject on .../gh-trending.json
because no identity-based policy allows the s3:PutObject action
```

All three Lambdas upload their main file to a bucket-root key (`gh-trending.json`, `hn-digest.json`, `release-radar.json`), but the IAM policy grants `s3:PutObject` on the `data/*` prefix only (`tech-bytes-stack.ts:180`). So every main-file write has always failed with AccessDenied. Only the archive copies (already under `data/archive/`) persisted.

Consequences that all trace back to this:

  • The site reads `data/gh-trending.json` → never written → fell back to the committed May-12 seed file → stale page.
  • `email_digest` reads `data/{release-radar,hn-digest,gh-trending}.json` → never written → empty digest sections.
  • `release_radar` appeared to "produce no output" → it did, the write just 403'd.
  • `deploy.yml` only syncs `s3://BUCKET/data/` → root-level files were invisible to the build anyway.

Change

One-line fix per handler — prefix `S3_KEY` with `data/`:

  • `gh_trending`: `gh-trending.json` → `data/gh-trending.json`
  • `hn_digest`: `hn-digest.json` → `data/hn-digest.json`
  • `release_radar`: `release-radar.json` → `data/release-radar.json`

This aligns the write path with the IAM grant, the `email_digest` read keys, the site read path, and the deploy sync. No infra change — `data/*` is already granted.

Test plan

  • Parser unit tests still pass
  • Confirmed IAM grant is `data/*` (tech-bytes-stack.ts:180)
  • Post-merge: re-invoke each Lambda; confirm `data/*.json` now writes (no AccessDenied) and the live site shows fresh trending data

The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
@datj9
datj9 merged commit 6a71cd1 into masterJun 7, 2026
2 checks passed
datj9 added a commit that referenced this pull request Jul 11, 2026
The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
Co-authored-by: Dat <dat.nguyen@ringkas.co.id>
@datj9
datj9 deleted the fix/lambda-s3-key-prefix branch July 11, 2026 05:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@datj9@datnguyen-ringkas
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause) - #3

Merged
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix
Jun 7, 2026
Merged

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause)#3
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix

Conversation

@datj9

@datj9datj9 commented Jun 7, 2026

Copy link
Copy Markdown
Owner

Root cause of the stale content

While verifying #1 end-to-end (invoking the deployed `gh_trending` Lambda), CloudWatch revealed the actual reason trending/HN/release content was outdated:

```
ERROR Failed to upload to S3
AccessDenied ... s3:PutObject on .../gh-trending.json
because no identity-based policy allows the s3:PutObject action
```

All three Lambdas upload their main file to a bucket-root key (`gh-trending.json`, `hn-digest.json`, `release-radar.json`), but the IAM policy grants `s3:PutObject` on the `data/*` prefix only (`tech-bytes-stack.ts:180`). So every main-file write has always failed with AccessDenied. Only the archive copies (already under `data/archive/`) persisted.

Consequences that all trace back to this:

  • The site reads `data/gh-trending.json` → never written → fell back to the committed May-12 seed file → stale page.
  • `email_digest` reads `data/{release-radar,hn-digest,gh-trending}.json` → never written → empty digest sections.
  • `release_radar` appeared to "produce no output" → it did, the write just 403'd.
  • `deploy.yml` only syncs `s3://BUCKET/data/` → root-level files were invisible to the build anyway.

Change

One-line fix per handler — prefix `S3_KEY` with `data/`:

  • `gh_trending`: `gh-trending.json` → `data/gh-trending.json`
  • `hn_digest`: `hn-digest.json` → `data/hn-digest.json`
  • `release_radar`: `release-radar.json` → `data/release-radar.json`

This aligns the write path with the IAM grant, the `email_digest` read keys, the site read path, and the deploy sync. No infra change — `data/*` is already granted.

Test plan

  • Parser unit tests still pass
  • Confirmed IAM grant is `data/*` (tech-bytes-stack.ts:180)
  • Post-merge: re-invoke each Lambda; confirm `data/*.json` now writes (no AccessDenied) and the live site shows fresh trending data

The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
@datj9
datj9 merged commit 6a71cd1 into masterJun 7, 2026
2 checks passed
datj9 added a commit that referenced this pull request Jul 11, 2026
The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
Co-authored-by: Dat <dat.nguyen@ringkas.co.id>
@datj9
datj9 deleted the fix/lambda-s3-key-prefix branch July 11, 2026 05:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@datj9@datnguyen-ringkas
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause) - #3

Merged
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix
Jun 7, 2026
Merged

fix(lambdas): write main data file under data/ prefix (fixes stale content root cause)#3
datj9 merged 1 commit into
masterfrom
fix/lambda-s3-key-prefix

Conversation

@datj9

@datj9datj9 commented Jun 7, 2026

Copy link
Copy Markdown
Owner

Root cause of the stale content

While verifying #1 end-to-end (invoking the deployed `gh_trending` Lambda), CloudWatch revealed the actual reason trending/HN/release content was outdated:

```
ERROR Failed to upload to S3
AccessDenied ... s3:PutObject on .../gh-trending.json
because no identity-based policy allows the s3:PutObject action
```

All three Lambdas upload their main file to a bucket-root key (`gh-trending.json`, `hn-digest.json`, `release-radar.json`), but the IAM policy grants `s3:PutObject` on the `data/*` prefix only (`tech-bytes-stack.ts:180`). So every main-file write has always failed with AccessDenied. Only the archive copies (already under `data/archive/`) persisted.

Consequences that all trace back to this:

  • The site reads `data/gh-trending.json` → never written → fell back to the committed May-12 seed file → stale page.
  • `email_digest` reads `data/{release-radar,hn-digest,gh-trending}.json` → never written → empty digest sections.
  • `release_radar` appeared to "produce no output" → it did, the write just 403'd.
  • `deploy.yml` only syncs `s3://BUCKET/data/` → root-level files were invisible to the build anyway.

Change

One-line fix per handler — prefix `S3_KEY` with `data/`:

  • `gh_trending`: `gh-trending.json` → `data/gh-trending.json`
  • `hn_digest`: `hn-digest.json` → `data/hn-digest.json`
  • `release_radar`: `release-radar.json` → `data/release-radar.json`

This aligns the write path with the IAM grant, the `email_digest` read keys, the site read path, and the deploy sync. No infra change — `data/*` is already granted.

Test plan

  • Parser unit tests still pass
  • Confirmed IAM grant is `data/*` (tech-bytes-stack.ts:180)
  • Post-merge: re-invoke each Lambda; confirm `data/*.json` now writes (no AccessDenied) and the live site shows fresh trending data

The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
@datj9
datj9 merged commit 6a71cd1 into masterJun 7, 2026
2 checks passed
datj9 added a commit that referenced this pull request Jul 11, 2026
The Lambdas upload their main output to S3_KEY at the bucket root
("gh-trending.json", "hn-digest.json", "release-radar.json"), but the
IAM policy only grants s3:PutObject on the `data/*` prefix
(tech-bytes-stack.ts:180). Every main-file write therefore failed with
AccessDenied — confirmed in CloudWatch logs:
AccessDenied ... s3:PutObject on .../gh-trending.json because no
identity-based policy allows the s3:PutObject action
Only the archive copies (already under data/archive/) ever persisted.
This is the actual reason the site content was stale: the files the
site reads (data/*.json) and email_digest reads (data/*.json) were
never successfully written — the site fell back to the committed
seed files. The deploy.yml sync (s3://BUCKET/data/) also never saw the
root-level files.
Prefix S3_KEY with `data/` in all three handlers so the write path
matches the IAM grant, the email_digest read keys, the site read path,
and the deploy sync. No infra change needed — data/* is already granted.
Co-authored-by: Dat <dat.nguyen@ringkas.co.id>
@datj9
datj9 deleted the fix/lambda-s3-key-prefix branch July 11, 2026 05:38
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@datj9@datnguyen-ringkas