One CloudFront address serves the site and the API. Everything below runs in ap-south-1 (Mumbai) and is deployed with one SAM template.
Why each service
EventBridge Scheduler + Lambda: works out run-dry times every 2 minutes, even when nobody is tapping, so silent stations and coming shortages are caught.
Step Functions: each runner job waits minutes for people; it reassigns when a runner does not respond and closes jobs nobody confirms.
SQS: a burst of taps at the headliner never waits on database writes; taps that keep failing go to a dead-letter queue instead of being lost.
DynamoDB: conditional writes make every tap count exactly once and stop two runners taking the same job.
CloudFront + S3: one https address, so the volunteer page works offline (service worker) and phones need no setup.