manager-0

Empactivo secure replica — stand-in for empactivo-prod-manager-0 at 10.0.1.10. This page exists only so there is a live origin behind CloudFront and the WAF. It is not the Empactivo application.

/whoami — shows what source IP the application actually sees. Load it directly, then load it through CloudFront, and compare.

/health — health endpoint.

Try the WAF rules

These requests match AWS managed rule groups. Through CloudFront they are recorded by the Web ACL; reaching the origin directly, they are not seen at all.