See https://cloudbees.atlassian.net/wiki/display/UX/Infrastructure for mini-design. I started the implementation.
ECR => we're using this for all our internal Ops tools. Much more reliable than self hosting - although authing to the ECR is painful unless you're inside AWS (in which case it's easy).
We're fairly isolated on that server, so don't go overboard with isolation etc.
I will check through your mini-design before we open it up.
Needs a mini-design doc and have Ben Walding review it.
Create a dedicated ECR environment to host deployed apps
Shh Ivan Meredith and I are conspiring
Should be tagged PRs as "needs-review" so that it is known to be ready to look at.
This seems like a neat hint towards that heroku pipeline feature of preview apps