Empactivo secure replica — stand-in for
empactivo-prod-manager-0 at 10.0.1.10.
This page exists only so there is a live origin behind CloudFront and
the WAF. It is not the Empactivo application.
/whoami — shows what source IP the application actually sees. Load it directly, then load it through CloudFront, and compare.
/health — health endpoint.
These requests match AWS managed rule groups. Through CloudFront they are recorded by the Web ACL; reaching the origin directly, they are not seen at all.