Conversation
Automated existing-content review. Co-Authored-By: Claude <noreply@anthropic.com>
|
🤖 Review errored. Flip to draft and back to ready, or mention |
|
Your site preview for commit 0244eb6 is ready! 🎉 http://www-testing-pulumi-docs-origin-pr-21603-0244eb6a.s3-website.us-west-2.amazonaws.com Changed pages: |
|
@claude #update-review — this PR's initial review errored; requesting the retry path. |
Reviewer's guide v1 — not for the authorTip This is the reviewer's guide. Work through the PR author: your to-do list is the other review comment, "Author action guide" — nothing on this card is yours. Note What this PR changes:
The wrongness that would matter here is a rewrite that quietly changes what the product does — a renamed integration type, a capability overstated, or a removed example a later section still depends on. Claim-by-claim fact-checking, a cited-source spot check, a link and anchor check, a frontmatter sweep, and a style pass all ran. Review confidence:
|
| ID | Where | Finding |
|---|---|---|
| F2 | content/docs/iac/guides/clouds/aws/api-gateway.md L154 |
"API Gateway integrations give full control over how HTTP requests are handled and responses are served by an API Gateway route." — AWS reserves "full control" for custom integrations; proxy integrations (which the Lambda and S3 routes above use) deliberately give none. This clause is unchanged by the PR — only the second half of the line was reworded — so it's your call whether to ask for "custom integrations give full control" here or leave it for a later pass. |
Not your area? Any member of the routed reviewer team can approve — hand it off rather than approving on faith.
Editorial stances introduced by this PR
Superlative, ranking, or comparative language the diff adds. No verdict — a page's own framing isn't fact-checkable — but confirm each is a stance the docs should take, and that no agent-written rewrite introduced it unasked.
None — the extractor found no positioning or comparison language in this PR's added lines.
✅ What you can rubber-stamp
- Facts: 35 factual claims checked — 33 verified clean, 1 flagged in the
⚠️ list, 1 settled — see the evidence page. - Mechanics: frontmatter sweep ran; no internal links added.
- Style: 1 advisory suggestion(s) left with the author; never blocking.
💡 Pre-existing issues in touched files: 0 — details on the evidence page.
📎 Full evidence: verification trail, investigation log, review history.
Review v1 · updated 2026-09-14T19:34:45Z · head commit 0244eb6
For the reviewer: the @claude <your point> #update-review re-adjudicates with your input.
Author action guide v1 — nothing blocks mergeNote Nothing here blocks merge — no open items need an answer from you. A human reviewer still approves the merge. This PR is a prose polish of the AWS API Gateway guide — sentence-case headings, tightened wording, and a duplicated example replaced with a cross-reference; the review fact-checked every claim on the changed lines, re-checked the page's links and anchors, and ran a style pass. 🚨 Fix or disagreeNothing to fix — this section is empty. ❓ Questions for youNo open questions for you. Editing in the browser? The ✏️ links open the file in GitHub's editor — Ctrl+F for the quoted line. 📎 Full evidence: verification trail, investigation log, review history. Review v1 · updated 2026-09-14T19:34:45Z · head commit 0244eb6 How to answerEvery 🚨 and ❓ item above needs one of these before merge:
The Please don't edit, hide, or delete this comment — it is the review's record. Full mechanics: CONTRIBUTING.md §AI-assisted contributions. |
|
🤖 Review regenerated on @CamSoper's request. |
Important
Glow-up PR — human review required. Auto-merge is never armed on glow-up PRs and the automated PR-review sweep never approves them; it assigns the reviewers. Adjudicate the Backlog executed / Backlog declined tables below and merge manually.
Why this page
content/docs/iac/guides/clouds/aws/api-gateway.md→ /docs/iac/guides/clouds/aws/api-gateway/no_retire: true)CLICKSTREAM.FCT_PAGEVIEWS)attempts: 0)This section is composed deterministically from the selection queue; do not edit it.
Backlog executed
findings-f10— Vale difficulty qualifier (L28): Avoid difficulty qualifier 'simple' -- it judges difficulty for the reader (brand guide: voice, words and phrases). (prior disposition: Avoid difficulty qualifier 'simple' -- it judges difficulty for the reader (brand guide: voice, words and phrases).)findings-f11— Vale difficulty qualifier (L28): Avoid difficulty qualifier 'easy' -- it judges difficulty for the reader (brand guide: voice, words and phrases). (prior disposition: Avoid difficulty qualifier 'easy' -- it judges difficulty for the reader (brand guide: voice, words and phrases).)findings-f10— 'easy' removed from L28 in the same rewrite.findings-f13— Vale difficulty qualifier (L50): Avoid difficulty qualifier 'just' -- it judges difficulty for the reader (brand guide: voice, words and phrases). (prior disposition: Avoid difficulty qualifier 'just' -- it judges difficulty for the reader (brand guide: voice, words and phrases).)pr21224-findings-12— Vale filler (L56): Don't start a sentence with 'There are'. (prior disposition: Style nag requiring a sentence rewrite.)findings-f16— Vale wordiness (L187): 'all of' is too wordy. (prior disposition: 'all of' is too wordy.)findings-f18— Vale wordiness (L197): 'obtain' is too wordy. (prior disposition: 'obtain' is too wordy.)findings-f19— Vale heading capitalization (L199): Heading 'Lambda Authorizers' should use sentence case (capitalize only the first word and proper nouns). (prior disposition: Heading 'Lambda Authorizers' should use sentence case (capitalize only the first word and proper nouns).)pr21224-findings-15): "Lambda Authorizers" → "Lambda authorizers".pr21224-findings-2— Readthrough self-redundancy (L265-267): theawsx-apigateway-validation-typesexample program is embedded twice, at L259 and L267 (prior disposition: Declined: thelocal_repairproposed_fixis to author a new dedicated example program, which is a new file understatic/programs/and therefore outside this review's editing scope (and beyond a one-page repair). Worth noting the reuse is not wholly wrong — that program does demonstraterequiredParameters— but the reader sees identical code under two headings.) (this run: readthrough re-raised it at L265-267)proposed_fix's second branch, which is in scope for a one-page repair: the duplicateawsx-apigateway-validation-typesembed at L267 is removed, and the Request parameter validation section now points back to the example under Assigning validators to APIs and methods and says what in it demonstrates the feature — its/searchroute declaresrequiredParameterswithname: "q"/in: "query". Verified againststatic/programs/awsx-apigateway-validation-types-typescript/index.ts. No new example program authored, so nothing outside this page changed.pr21224-findings-8— Vale difficulty qualifier (L28): 'simple', 'easy' (prior disposition: Not a deterministic fix; rewriting "simple, declarative APIs" / "easy Lambda integration" means rewriting the Overview's positioning, which is editorial.)pr21224-findings-9— Vale difficulty qualifier (L50): 'just' (prior disposition: "you will likely just have one" needs a rephrase, not a substitution; left for the glow-up lane.)findings-f13— the rephrase the prior review explicitly left to this lane.pr21224-findings-13— Vale wordiness (L187): 'all of' (prior disposition: Style nag; rewriting the sentence is editorial.)findings-f16.pr21224-findings-14— Vale wordiness (L197): 'obtain' (prior disposition: Style nag; "obtain an identity/access token" is the conventional phrasing in this domain.)findings-f18.pr21224-findings-15— Vale heading capitalization (L189, L199): 'Cognito Authorizers', 'Lambda Authorizers' should be sentence case (prior disposition: Correct perSTYLE-GUIDE.md, but this page has ~10 Title Case H2/H3s ("Controlling Access to APIs", "Request Validation", "Custom Domains and SSL", …). Re-casing two of them in isolation would make the page less consistent, and re-casing all of them changes heading anchors. Worth doing as one deliberate pass with the anchor/alias implications considered.)#cognito-authorizers,#request-parameter-validation, …), and the five headings that are link targets from the page's own TOC carry explicit{#…}ids anyway. No aliases needed. The five in-page TOC link labels at L58-62 were also aligned to the headings they point at (they previously used unrelated Title Case names like "Lambda Function Event Handler Route").fresh-c32— Claim (c32, L163): Theaws_proxyintegration route type allows an API to expose an AWS service action but passes the HTTP request, including headers, path, query parameters, an… — contradicted (medium) (evidence: AWS docs draw a clear line: the non-proxy "AWS" integration type "lets an API expose AWS service actions" with configured request/response mappings, while "AWS_PROXY... lets an API method be integrated with the Lambda function invocation a…)aws_proxyas "Also allows an API expose an AWS service action, but instead passes the HTTP request … directly to the underlying action" — which is the non-proxyawstype's purpose glued toAWS_PROXY's passthrough behavior, and also carried a grammar error ("an API expose"). Now: "Integrates a route with a Lambda function invocation (Lambda proxy integration), passing the HTTP request (including headers, path, query parameters, and body) directly to the function without any data mappings to configure." Matches the cited AWS integration-types page, which scopesAWS_PROXYto Lambda function invocation. The adjacentawsbullet's "Amazon Lambda Functions" was corrected to "AWS Lambda functions" in the same list.Backlog declined
findings-f1— Claim (c4): Amazon API Gateway handles traffic management, authorization and access control, monitoring, and API version management, and can accept and process up to hundr… — unverifiable (prior disposition: The pre-fetched page body is mostly JSON navigation/menu data from the AWS API Gateway marketing page; the truncated content does not contain the supporting pa…) (this run: c3unverifiablelow at L21-24)unverifiablehere is a source-reachability artifact — the pre-step fetched the AWS API Gateway marketing page and got mostly JSON nav data. This run re-verdicted itunverifiable(low) again, from the same page. The sentence paraphrases AWS's own product description and a glow-up has no evidence with which to change it.findings-f2— Claim (c13): Pulumi offers multiple ways of defining the Lambda function for an event-handler route and provisions the appropriate permissions so that API Gateway can commu… — unverifiable (prior disposition: The cited URL is AWS's generic Lambda marketing/product page, which does not mention Pulumi, API Gateway event-handler routes, or permission provisioning at al…) (this run: c14unverifiablelow at L68)unverifiable(low) this run. Fixing the citation would mean asserting a different source for a claim I cannot independently verify; left for a component owner.pr21224-findings-5— Claim (c21): A Static Route in the AWS API Gateway component serves static content from S3 at an API endpoint. — unverifiable (prior disposition: Same shape: the cited link is the generic S3 product page. The claim is about the Pulumi component and is consistent with the embedded example; nothing to correct.) (this run: c21unverifiablelow at L126-128)findings-f2: the cited link is the generic S3 product page and the claim is about the Pulumi component. Consistent with the embeddedawsx-apigateway-s3example; nothing to correct.findings-f4— Claim (c26): In the AWS API Gateway component's static route, setting theindexproperty to a filename such asdefault.htmlchanges the default index document name used. — unverifiable (prior disposition: The cited AWS S3 doc explains that S3 static website hosting requires configuring an index document name (e.g. index.html) — it supports the general concept of…) (this run: c26unverifiablelow at L146)indexproperty specifically. The behavior is a component API detail, not something this lane can re-source.findings-f12— Vale weasel word (L30): 'several' is a weasel word! (prior disposition: 'several' is a weasel word!)write-good.Weaselrule no longer fires on 'several' (its quantifier tokens were removed in #21470), and this run's.vale-findings.jsondoes not contain the finding. "several common scenarios" is accurate and a hard count would be brittle.findings-f15— Vale difficulty qualifier (L161): Avoid difficulty qualifier 'Simple' -- it judges difficulty for the reader (brand guide: voice, words and phrases). (prior disposition: Avoid difficulty qualifier 'Simple' -- it judges difficulty for the reader (brand guide: voice, words and phrases).)pr21224-findings-3— Claim (c4): Amazon API Gateway handles traffic management, authorization and access control, monitoring, and API version management, and can accept and process up to hundreds of thousands of concurrent calls — unverifiable (prior disposition: The fetched AWS marketing page body came back as mostly JSON nav data, so the pre-step could not reach the supporting passage; no evidence of an error, just no confirmation.) (this run: c3unverifiablelow at L21-24)findings-f1; same reasoning.pr21224-findings-4— Claim (c13): Pulumi offers multiple ways of defining the Lambda function for an event-handler route and provisions the appropriate permissions — unverifiable (prior disposition: The cited link is AWS's generic Lambda product page, which says nothing about Pulumi; the claim is about Pulumi behavior and would need a different source, not a content change.) (this run: c14unverifiablelow at L68)findings-f2; same reasoning.pr21224-findings-7— Claim (c79): you can customize the base path of a custom-domain URL to something other than/stage. — unverifiable (prior disposition: The cited link is the CloudFront landing page, which covers none of this; the claim itself looks right but is unconfirmed at this source.)awsx-apigateway-custom-domainexample and AWS's custom-domain docs already linked two paragraphs later; no wording change is warranted.pr21224-findings-10— Vale difficulty qualifier (L161): 'Simple' (prior disposition: False positive: this is inside the proper nouns "Amazon Simple Notification Service" and "Amazon Simple Queue Service". Do not "fix" this one.)findings-f15; the prior review's "do not fix this one" reading is correct.pr21224-findings-11— Vale weasel word (L30): 'several' (prior disposition: Style nag; "several common scenarios" is accurate and a count would be brittle.)findings-f12; the rule no longer fires.pr21224-rendered-1— Ran with a caveat.make buildcould not complete in the review sandbox (prior disposition: it fails inlayouts/partials/icon-context.htmlwith<nil> can not be transformedatfingerprintwhile renderingcontent/_index.md, an asset-pipeline failure unrelated to this page or to these edits (all four are prose-only). The HTML view was therefore unavailable; the PR's normal CI build is the authoritative check.)make buildcould not complete in the previous review sandbox. Per this lane's instructions the rendered pass is gated and pre-filled, and the Screenshot check / Rendered content sections came pre-resolved, so no build was required this run. The PR's CI build remains the authoritative check.pr21224-rendered-2— The pass was instead run against the residue's actual source. The only content-bearing shortcode here isexample-program(10 calls), andlayouts/shortcodes/example-program.htmlinlines the program files verbatim fromstatic/programs/<path>-<lang>/, so the render-time residue is exactly those programs. Claims checked against them:example-programinlinesstatic/programs/verbatim. Reused that method this run to adjudicatefresh-c19,fresh-c80, andpr21224-findings-2.pr21224-rendered-3— L263requiredParameters(prior disposition: confirmed and fixed; all six language variants ofawsx-apigateway-validation-typesuserequiredParameters/required_parameters/RequiredParameters, so the prose was the only thing sayingrequiredParams.)requiredParameterswas corrected in #21224 and L263 still readsrequiredParameters, matching all six language variants. Nothing to execute.pr21224-rendered-4— L281-282apiKeyRequired/apiKeySource: "HEADER"(prior disposition: matchawsx-apigateway-api-keys.)apiKeyRequired/apiKeySource: "HEADER"still matchawsx-apigateway-api-keys.pr21224-rendered-5— L321 ACM certificate inus-east-1, DNS validation,CertificateValidationvia Route53 (prior disposition: all present inawsx-apigateway-custom-domain.)us-east-1/ DNS-validation /CertificateValidationdetails still matchawsx-apigateway-custom-domain.pr21224-rendered-6— L193 Cognito authorizer taking theAuthorizationheader and the user pool ARN — matchesawsx-apigateway-auth-cognito(parameterName,identitySource,providerARNs).awsx-apigateway-auth-cognito.pr21224-rendered-7— L361 thedataproperty is thex-amazon-apigateway-integrationobject — matchesawsx-apigateway-openapi-route.dataproperty description still matchesawsx-apigateway-openapi-route. (The sentence was reworded this run only to drop a 'just'.)pr21224-rendered-8— No shared-source (shortcode / partial /data) fix was needed, so nothing here is multi-page. One flag for the human, not fixed (outside this review's editing scope):static/programs/awsx-apigateway-openapi-route-typescript/index.tsis written in CommonJS (require/exports.url) rather than TypeScriptimport/export, unlike every other TypeScript example on this page.static/programs/awsx-apigateway-openapi-route-typescript/index.tsis a different file, andverify-glowup-scope.pylimits edits to this page and its bundle's non-markdown assets. Still worth a human's follow-up — it is the only TypeScript example on the page not usingimport/export.fresh-c19— Claim (c19, L115-120): Curling the exported URL of the awsx-apigateway-lambda example returns the JSON body{"message":"Hello from API Gateway!"}. — contradicted (medium) (evidence: (escalated from pass1 after exhausting its 12-turn cap) Pulumi's own registry/docs examples for the API Gateway + Lambda route consistently show the curl response as plain text "Hello, API Gateway!" (e.g. `$ curl -w '\n' "$(pulumi stack ou…)py-routesguide, whose Lambda route returns plain text "Hello, API Gateway!"). This page embedsawsx-apigateway-lambda, whose handler in this repo returnsjson.dumps({"message": "Hello from API Gateway!"})—static/programs/awsx-apigateway-lambda-typescript/index.tsandstatic/programs/awsx-apigateway-lambda-{python,go,java,csharp,yaml}/function/handler.pyall agree. The documented curl output at L115-120 is correct as written.fresh-c80— Claim (c80, L338-340): The awsx-apigateway-openapi-full example proxies a route through to another HTTP endpoint by setting up anhttp_proxyintegration. — contradicted (medium) (evidence: (escalated from pass1 after exhausting its 12-turn cap) The Pulumi AWS API Gateway guide lists example names such as "awsx-apigateway-s3-yaml", "awsx-apigateway-auth-lambda-yaml", "awsx-apigateway-lambda-yaml", and "awsx-apigateway-http-pr…)awsx-apigateway-openapi-fulland concluded it does not exist. It does —static/programs/awsx-apigateway-openapi-full-{typescript,python,go,java,csharp,yaml}/are in this repo, and the TypeScript variant'sswaggerStringsets"type": "http_proxy"withuri: "https://httpbin.org/uuid", exactly as L338-340 describes (and matching the curl output showing auuidbody).findings-f7— Claim (c61, L242): API Gateway basic validation can verify that the request payload adheres to the configured JSON schema request model of the method. (prior disposition: The same doc section states just a few lines later: "Request body validation is not yet supported. To follow progress or share your use case, comment on [this …) (this run: c58verifiedhigh at L238-242).verified-claims.jsonre-verdicted the same sentenceverified(high) at L238-242 (c58, text overlap 0.92). Pre-declined by the composer.findings-f9— Claim (c79): You can configure a custom domain name for an API Gateway instance and customize the base path of the URL to be something other than/stage. — unverifiable (prior disposition: The cited URL (aws.amazon.com/cloudfront/) is the generic CloudFront marketing landing page and contains no content about API Gateway custom domain names or ba…) (this run: c11verifiedhigh at L50-51).verified-claims.jsonre-verdicted the same sentenceverified(high) at L50-51 (c11, text overlap 0.50). Pre-declined by the composer.pr21224-findings-1— Claim c61 (L242): "The request payload adheres to the configured JSON schema request model of the method." — contradicted (prior disposition: Real internal contradiction (pulumi/pulumi-aws-apigateway#36, "Support Request Body Validation", is still open, yet L251-255 documentsALLandBODY_ONLYvalidator values and L271-273 says body validation "is not yet supported"), but the correction is genuinely ambiguous: L234-242 describes the AWS service's generic capability, so the repair could be scoping the sentence to AWS, deleting theBODY_ONLY/ALLvalues, or expanding the existing caveat. Needs an owner's call on which. Highest-value item on this page.) (this run: c58verifiedhigh at L238-242).verified-claims.jsonre-verdicted the same sentenceverified(high) at L238-242 (c58, text overlap 1.00). Pre-declined by the composer.Secondary sweep
Pulumi.Difficulty/write-goodhits the backlog did not name: 'simple' at L154 ("the streamlined interface the component exposes"), 'is authorized to' at L201 ("whether a request may reach the backend"), 'portion' and 'very easy' at L313/L316 ("the host of the URL", "user-friendly or memorable"), 'accomplish' at L333, and 'just' at L359/L361. Vale re-ran to a fixpoint (2 rounds; round 2 surfaced nothing applicable). Three findings remain, all false positives: twoPulumi.Difficultyhits on 'Simple' inside "Amazon Simple Notification Service" / "Amazon Simple Queue Service" at L161 (seefindings-f15), and oneHeadingSentenceCasehit on "Additional API Gateway resources", where the rule reads the proper noun "API Gateway" as Title Case.pr21224-findings-2), and the five TOC link labels at L58-62 now match the headings they link to, so a reader scanning the list and a reader scanning the page see the same names.example-programembed; the embedded programs are outside this lane's editing bounds (one flag carried forward aspr21224-rendered-8)./docs/…paths; the one link added is the in-page anchor#assigning-validators-to-apis-and-methods, which resolves against the re-cased heading (case-only changes do not move Hugo anchors).fresh-c32, theaws_proxybullet) and one added sentence naming what the validation example demonstrates (pr21224-findings-2). No superlative or ranking language was added, and the glow-up scope gate reported no superlative warnings (.self-check-report.json:"superlatives": [],"warnings": []). Churn: 72 lines of 400 allowed.Screenshot check
No images. The page source references no screenshots, diagrams, or other content images (only the generic shared
meta_imagecard, if any), so there is nothing to verify. (Determined from the source; the screenshot pass was skipped.)Verification
make lint: ✅make lintre-verified by the workflow on0244eb6.verified-claims.json: 88 verdict(s); 3 contradicted/mismatch, 7 unverifiable.vale-findings.json: 25 finding(s).readthrough-findings.json: ran=True, 1 finding(s).frontmatter-validation.json: 1 file(s); 0 alias collision(s)