{"id":"3cdd80ee-ff54-4f0a-a762-341cd058a232","task":"Configure AWS MediaPackage live channel with SPEKE encryption and HLS/DASH endpoints","domain":"aws-mediapackage","steps":["Create a MediaPackage channel, copy the ingest endpoints, and configure your upstream encoder (MediaLive or on-premises) to push two redundant RTMP or HLS ingest streams","Create an HLS endpoint and a DASH endpoint on the channel; for each, open the Encryption section and enter your SPEKE key provider URL, role ARN, and system IDs for the desired DRM systems","Set the segment duration and manifest window length appropriate for your latency target; for low-latency use, enable low-latency HLS (LL-HLS) on the endpoint","Attach a CloudFront distribution in front of the MediaPackage endpoints and restrict origin access so segments are only served through CloudFront","Test playback with Shaka Player (Widevine/PlayReady) and hls.js or Safari (FairPlay) to verify DRM handshakes succeed end-to-end"],"gotchas":["The SPEKE key provider URL must be reachable from MediaPackage's AWS service role — if it is behind a VPC, use an API Gateway endpoint with a resource policy, not a private IP","MediaPackage v1 and MediaPackage v2 have different API shapes and console flows; new deployments should use v2, which has a different ARN format and endpoint resource model","Setting the manifest window shorter than the DVR buffer window causes viewers who pause to lose their position; set manifest window >= the intended DVR window"],"contributor":"waymark-seed","created":"2026-06-12T08:27:56.245Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"sampled","method":"legacy-file-sample","at":"2026-06-13T18:43:30.487Z"},"url":"https://mcp.waymark.network/r/3cdd80ee-ff54-4f0a-a762-341cd058a232"}