Scene gallery
Each of these is a redraw of a screen I designed, rebuilt in SVG and animated on a timeline rather than captured as video. They are scattered through the case studies, so this page collects them.
All 15 scenes
Outbound bandwidth as one line
Render
The chart before the change. One line, and it counted about 40% of the traffic.
Outbound Bandwidth 0 MB 200 MB 400 MB 600 MB 800 MB 1,000 MB 3:04am 4:24am 5:43am 7:03am 8:22am 9:42am 11:02am 12:21pm 1:41pm HTTP Responses Websocket Responses Service-Initiated Service-Initiated (Private Link) This graph’s resolution is fixed at one data point per hour. Usage this month 232.0 GB HTTP Responses 54.3 GB Websocket Responses 14.1 GB Service-Initiated 71.6 GB Service-Initiated (Private Link) 92.0 GB Want to stream your metrics to another observability tool? Visit Integrations EDT: Sep 10 02:00:00 PM UTC: Sep 10 06:00:00 PM HTTP Responses 406 MB Websocket Responses 93 MB Service-Initiated 545 MB Service-Initiated (Private Link) 648 MB Filter events 3 Last 12 hours Environment harbor-api MONITOR MANAGE Deploys Settings Events Logs Metrics Compute Environment Shell Previews Disk One-Off Jobs Changelog Invite a friend Contact support Render Status H Harbor Labs Harbor / Production / harbor-api Search K New B Outbound bandwidth by traffic type
Render
The chart after. Four named traffic types, with this month’s usage for each.
Private Links Securely connect and manage network traffic between cloud services. Create a Private Link PRIVATE LINK AWS STATE STATUS REGION DNS NAME na-datastores Pending Available Waiting Available Oregon, US vpce-0c41f9e2… payments-gateway Pending Available Waiting Available Virginia, US vpce-07d2b8e1… eu-datastores Pending Available Waiting Available Frankfurt, Germany vpce-0f8a3c61… eu-analytics Pending Available Waiting Available Frankfurt, Germany vpce-02b7e9d4… orders-rds-oregon Pending Available Waiting Available Oregon, US vpce-0a9e47c2… orders-rds-oregon wascreated. It could take a few minutes for the connection to establish and DNS updates to finish verification. Workspace Networking MONITOR MANAGE Metrics Private Links Dedicated IPs Network Access Changelog Invite a friend Contact support Render Status H Harbor Labs Networking / Private Links / New Private Link Search K New B Creating a Private Link
Render
The Render status and the AWS state sit side by side.
PRIVATE LINK orders-rds-oregon Available Read the docs Created September 14, 2026 at 3:42 pm Region Oregon, US AWS ID vpce-0a9e47c2d81b5f36e DNS Name Copy DNS Name Orders database in our AWS account, for the US services. Environments View the environments this Private Link is exposed to in this workspace. This selection can’t be changed once the Private Link has been configured. Learn more about using Private Links Accessible (2) Accessible (2) Accessible (2) Excluded (5) Excluded (5) Search environments and services SERVICE NAME REGION ACCESSIBLE harbor-us / harbor-us Production harbor-api Oregon, US Accessible harbor-web Oregon, US Accessible orders-worker Oregon, US Accessible billing-cron Oregon, US Accessible search-index Frankfurt, Germany Unavailable harbor-us / harbor-us Staging harbor-api Oregon, US Accessible harbor-web Oregon, US Accessible orders-worker Oregon, US Accessible search-index Frankfurt, Germany Unavailable This service is deployed to a different region than this Private Link, so connections from it will fail. Workspace Networking MONITOR MANAGE Metrics Private Links Dedicated IPs Network Access Changelog Invite a friend Contact support Render Status Networking orders-rds-oregon MONITOR MANAGE Metrics Environments Settings Changelog Invite a friend Contact support Render Status H Harbor Labs Networking / Private Links / orders-rds-oregon Search K New B Private Link environments
Render
A link’s read-only page: what it reaches, and what it leaves out.
Back to Dedicated IPs Read the docs Create Dedicated IPs Purchase and manage blocks of dedicated IP addresses to allowlist outbound traffic to the Internet and ensure consistent connections from your Render infrastructure. Name A friendly name to identify this block of IP addresses. production-oregon Description Optional Describe the purpose of this block of IP addresses for other collaborators. Dedicated outbound IPs for the US production services. Region The region your block of IP addresses will be available in when emitting outbound traffic from Render. Select a region Oregon, US Environments Select which services this block of IP addresses will be assigned to in your workspace. Learn more about Dedicated IPs All Environments This block of IP addresses will be assigned to all services in your workspace that are deployed in the same region. Select Environments Only assign these IP addresses to services in specific environments. Only services that are deployed in the same region will be assigned these IPs. Search for environments harbor-us Production 5 Staging 4 Unavailable Development 3 harbor-eu Production 3 Staging 3 Development 1 harbor-sandbox Preview 1 Dedicated IPs for this environment are managed by staging-oregon Added on September 2, 2026 at 12:31 pm Services deployed to a different region than this Dedicated IP block will continue to use their existing shared IP addresses for outbound traffic. Monthly Total Dedicated IP subscriptions are billed monthly. Dedicated Outbound IPs $100 / month Total $100 / month Standard outbound bandwidth charges will still apply. Pricing Create Dedicated IPs Create Dedicated IPs Cancel Workspace Networking MONITOR MANAGE Metrics Private Links Dedicated IPs Network Access Changelog Invite a friend Contact support Render Status H Harbor Labs Networking / Dedicated IPs / Create Dedicated IPs Search K New B Buying dedicated IPs
Render
An environment another block already covers stays locked.
All Environments This block of IP addresses will be assigned to all services in your workspace that are deployed in the same region. Select Environments Only assign these IP addresses to services in specific environments. Only services that are deployed in the same region will be assigned these IPs. Search for environments Select All harbor-us harbor-api harbor-web orders-worker billing-cron search-index Production 5 Staging 4 Development 3 harbor-eu Production 3 Staging 3 Development 1 harbor-sandbox Preview 1 Services deployed to a different region will continue to use their existing shared IP addresses for outbound traffic. All Environments This block of IP addresses will be assigned to all services in your workspace that are deployed in the same region. Select Environments Only assign these IP addresses to services in specific environments. Only services that are deployed in the same region will be assigned these IPs. Search for environments Select All harbor-us Production View environment Staging Development harbor-eu Production Staging Development harbor-sandbox Preview Services deployed to a different region will continue to use their existing shared IP addresses for outbound traffic. All Environments This block of IP addresses will be assigned to all services in your workspace that are deployed in the same region. Select Environments Only assign these IP addresses to services in specific environments. Only services that are deployed in the same region will be assigned these IPs. Search for environments harbor-us Production 5 Services Staging 4 Services Development 3 Services harbor-eu Production 3 Services Staging 3 Services Development 1 Services harbor-sandbox Preview 1 Services Services deployed to a different region than this Static IP block will continue to use their existing shared IP addresses for outbound traffic. All Environments This block of IP addresses will be assigned to all services in your workspace that are deployed in the same region. Select Environments Only assign these IP addresses to services in specific environments. Only services that are deployed in the same region will be assigned these IPs. Search for environments harbor-us harbor-api harbor-web orders-worker billing-cron search-index Production 5 Staging 4 Unavailable Development 3 harbor-eu Production 3 Staging 3 Development 1 harbor-sandbox Preview 1 Dedicated IPs for this environment are managed by staging-oregon Added on September 2, 2026 at 12:31 pm Services deployed to a different region than this Dedicated IP block will continue to use their existing shared IP addresses for outbound traffic. Environment picker studies
Render
Four ways to pick environments. The shipped one is on the right.
Networking Inbound Allowlist Limit incoming traffic to your services from specific IP ranges. Sources are specified in CIDR block notation. Edit All traffic 0.0.0.0/0 Workspace Internal Network 10.0.0.0/8 VPN Range 172.16.0.0/12 Office LAN 192.168.0.0/16 Environment Production VPC 10.20.0.0/16 Staging VPC 10.30.0.0/16 VPN gateway 172.16.10.0/24 SF office egress 203.0.113.0/28 GitHub Actions runners 198.51.100.0/30 PagerDuty webhooks 192.0.2.15/32 Service Select a source to see how its requests are evaluated GitHub Actions runners Inbound Request Request to this service from an address in 198.51.100.0/30 Workspace 198.51.100.0/30 passes workspace rules Environment 198.51.100.0/30 is blocked by environment rules Service 198.51.100.0/30 is never evaluated Add new rule to Environment This CIDR range is not permitted by the environment this service is in. Adding a new rule to cover this range will allow requests from addresses within it. Add new rule Inbound allowlist
Render
A proposal: pick a source, see where its requests land.
Security Center Jul 5, 2022, 9:59 PM UTC Coordinated Universal Time (UTC) Overview Threat Monitoring Threat Overview Last 7 days Security Center provides visibility of potential threat signals using an aggregate of event codes detected in your tenant’s traffic. Low levels of threats are expected, but a significant, large spike could indicate potentially malicious activity on your tenant’s traffic. Learn more about threat signals in our docs. Total traffic 501,239 +2.6% Total threats 29,573 +18.6% Threat % of total traffic 5.90% +0.8% Threat behavior Threat behavior trends 29,573 +18.6% 16000 8000 0 Jun. 29 Jun. 30 Jul. 1 Jul. 2 Jul. 3 Jul. 4 Jul. 5 Normal Traffic Credential Stuffing Signup Attack MFA Bypass App name Client ID Threat behavior by app User Profile k7TqP2mXv9LsR4wN... Landing Page Qe3ZbH8yJt1VcM6d... iOS App Rn5WfG0pLx2KaY7s... Android App Hd9CvB4tMq8ZeP1u... Billing Xw2LsN7gTj5RkF3b... Threat behavior types 0 +18.6% 0 Credential Stuffing Signup Attack MFA Bypass Authentication Login attempts 0 +0.5% 12000 6000 0 Jun. 29 Jun. 30 Jul. 1 Jul. 2 Jul. 3 Jul. 4 Jul. 5 Successful Logins Failed Logins Signup attempts 0 +2.8% 1200 600 0 Jun. 29 Jun. 30 Jul. 1 Jul. 2 Jul. 3 Jul. 4 Jul. 5 Successful Signups Failed Signups Jun. 29, 4 PM Normal Traffic 12,633 Credential Stuffing 1,814 Signup Attack 170 MFA Bypass 24 ATTACK PROTECTION Bot Detection Suspicious IP Throttling Brute-force Protection Breached Password Detection Multi-factor Auth Bot Detection ENABLED Configure Bots detected 0 +21.3% 400 200 0 Jun. 29 Jun. 30 Jul. 1 Jul. 2 Jul. 3 Jul. 4 Jul. 5 Bots Detected A acme-dev PRODUCTION Discuss your needs B Security Center overview
Auth0
A week of a tenant’s threats, then each attack protection signal.
Log in | Northwind login.northwind.app /u/login A Create a passkey for Northwind on this device? No need to remember a password With passkeys, you can use your fingerprint or face to log in. Works on all your devices Passkeys will automatically be available across your synced devices. Works alongside passwords Passkeys offer state-of-the-art phishing resistance. Don’t show me this again Create a new passkey Continue without a passkey Go back Passkey enrollment
Auth0
Offering a passkey after a password login, Touch ID and all.
Back to Database Connections passkey-db-connection Database Identifier con_DMSID8W6E0m6tDPR Try Connection Settings Identifiers Authentication Methods Custom Database Connections Manage the authentication methods your end users will be prompted with when authenticating to applications using this connection. Password Configure Passkey EARLY ACCESS Configure A acme-dev PRODUCTION Discuss your needs B Passkey Authentication Prerequisites Passkey authentication has a number of prerequisites that must be configured before they can work correctly in your end-user flows: New Universal Login Experience must be enabledDONE Custom Login Page must be disabledDONE Identifier First login flow must be enabledPENDING Requires username must be disabledPENDING Use my own database must be disabled unless“ Import Users to Auth0 ” is onPENDING Close Passkey guardrails
Auth0
Switching passkeys on checks the prerequisites first.
™ Gamer Security PERFORMANCE SETTINGS SECURITY GAME SESSION Assassin’s Creed Brother… Aug 9, 2019 · 8:14–8:25 pm Auto Game Boost BOOST EVENTS FPS 58 CPU 22% Temp 71°C GPU 72% RAM 61% 4.9/8.0 GB Network 40 kbps CPU Game Other apps McAfee 100 75 50 25 0 Started Boosted Ended SESSION SUMMARY Change settings Boosted Assassin’s Creed Brotherhood Blocked Windows and Discord notifications Paused Windows Update and 11 other services Deprioritized Google Chrome, Spotify 8:20 pm Game 26% Other 9% McAfee 2% 9% 14% Session analysis
McAfee
Where a boosted game session’s resources went.
™ Gamer Security PERFORMANCE SETTINGS SECURITY BACK We found threats that need your attention Scan again Restart my PC UNRESOLVED THREATS (6) FIXED THREATS (4) Try this to fix them: Check the full path of the infected item. If it’s removable, read-only media, try removing it. If it’s a network folder, disconnect from that network. Sign in to Windows as an Administrator and delete the program. Want a hand? Contact Support .INFECTED FILES Ravmon.exe Unable to fix %WinDir%\…\Media\arona.exe Unable to fix ModLoader.exe Unable to fix svchosts.exe Unable to fix fps-unlocker.dll Unable to fix %AppData%\…\Startup\update.vbs Unable to fix Location: C:\Windows\Media\arona.exe Why it wasn’t fixed: Windows is using this file. Restart your PC, then scan again. 0 Threats fixed INFECTED FILES free-skins-generator.exe %Temp%\…\setup_x64.tmp aimbot-v2.zip overlay-helper.js Quick scan
McAfee
A scan from start to finish, unfixed threats first.
9:41 Your info was stolen, but we can help These sites were hacked, and your info’s on the dark web for anyone to use. But don’t worry, we’ll guide you through steps to make yourself safer. Tumblr alex.morgan@gmail.com MyFitnessPal alex.morgan@gmail.com Canva alex.morgan@gmail.com Let’s do it Dark web check
McAfee
A breach check in onboarding, before the app is set up.
Illustrations by Sabrina Smelko.
9:41 Dashboard Recommended Has your personal info been stolen? We’ll look for your info on the dark web. And if we find anything, we’ll help you become safer. Let’s check Recommended VPN is on We’re boosting your security and privacy. Turn off VPN Go to my VPN settings Unsafe Wi-Fi
McAfee
Setting up the VPN the first time unsafe Wi-Fi turns up.
Illustrations by Sabrina Smelko.
9:41 Skip ™ 3 of 3 Enjoy life, worry-free So shop online, share photos, or check private accounts, even on coffee shop Wi-Fi. Because we’re right here with you. I want to know more 9:41 Skip ™ 2 of 3 We’re here for you You can trust us to help protect you from threats, guide you when you need it, and give you control of what matters. 9:41 Skip ™ 1 of 3 Protection you deserve Security is serious. But it doesn’t have to be scary. The dangers are worse than you might know, but together, we’re stronger. App intro
McAfee
The intro, turned by the handle on each slide.
Illustrations by Sabrina Smelko.