Skip to content

Cloud · AWS · Terraform

AWS is where I build.

My own products run on AWS, and I orchestrate all of it with Terraform: serverless where it fits, managed services where mistakes are expensive, and every piece written as code.

  • CloudFront
  • Lambda
  • API Gateway
  • SQS
  • RDS
  • Cognito
  • S3
  • EventBridge
  • SES

Architecture

How a request moves through the stack

Pick a path. These are the patterns my projects actually use.

  1. Route 53 Amazon Route 53
  2. CloudFront Amazon CloudFront
  3. S3 Amazon S3

Loading a page: DNS resolves to CloudFront, which serves the site from a private S3 bucket and caches it at the edge.

The services

What I reach for, layer by layer

Every service here is in production in my own projects.

Edge and delivery

Everything a visitor touches first.

  • Amazon CloudFront

    The front door for every site and app: caching, TLS, and CloudFront Functions running at the edge.

  • Amazon S3

    Static sites and SvelteKit assets behind CloudFront, plus file storage. Private buckets, encrypted and versioned.

  • Amazon Route 53

    DNS for every domain and subdomain, pointed at CloudFront and API custom domains.

  • AWS Certificate Manager

    TLS certificates for CloudFront and API domains, validated and renewed automatically.

APIs and compute

Serverless by default: pay per request, nothing to patch.

  • Amazon API Gateway

    HTTP APIs with custom domains, routes into Lambda, and authorizers that check the user before any code runs.

  • AWS Lambda

    Where the application code runs: API handlers, queue workers and scheduled jobs, on Node.js.

  • Amazon EventBridge

    Cron and rate schedules that trigger Lambda jobs, defined alongside the function they run.

Messaging and email

Slow or unreliable work moves off the request path.

  • Amazon SQS

    Queues between the API and background work, feeding Lambda workers, with dead-letter queues for anything that keeps failing.

  • Amazon SES

    Transactional email from my own domains, with DKIM and a custom MAIL FROM so it lands in the inbox.

Data and identity

Managed services for the parts that are expensive to get wrong.

  • Amazon RDS for PostgreSQL

    The main relational database, PostgreSQL, running in private subnets.

  • Amazon Cognito

    User sign-up and sign-in, including Google and Sign in with Apple, wired into API Gateway authorizers.

Network, security and operations

Private by default, least privilege, and visible when something breaks.

  • Amazon VPC

    Private networking for the database, with VPC endpoints so Lambda reaches AWS services without the public internet.

  • Amazon EC2

    Small instances where they beat a managed service on cost: a NAT instance (fck-nat) and a jumpbox into the private network.

  • AWS IAM

    A role per service with only the permissions it needs, and deployments that assume a role instead of using long-lived keys.

  • AWS KMS

    Encryption keys for data at rest.

  • Amazon CloudWatch

    Logs and metrics for every Lambda, with log subscriptions to route them where they are needed.

Terraform logo

Orchestration

All of it is Terraform, orchestrated by Terragrunt.

Nothing is clicked together in the console. Each project is composed from a shared set of modules, so a new product starts with the same edge, API, queue and database setup instead of a blank page.

  • static-site
  • cloudfront-sveltekit
  • cloudfront-apigw
  • lambda
  • lambda-cron
  • sqs
  • sqs-lambda-subscription
  • rds
  • cognito
  • ses
  • vpc
  • fck-nat
  • iam-role
  • certificate
  • route-53-hosted-zone
  • cloudwatch-lambda-log-subscription

At a glance

Every service, and what it's for

AWS services in my stack
ServiceWhat I use it forLayer
Amazon CloudFrontThe front door for every site and app: caching, TLS, and CloudFront Functions running at the edge.Edge and delivery
Amazon S3Static sites and SvelteKit assets behind CloudFront, plus file storage. Private buckets, encrypted and versioned.Edge and delivery
Amazon Route 53DNS for every domain and subdomain, pointed at CloudFront and API custom domains.Edge and delivery
AWS Certificate ManagerTLS certificates for CloudFront and API domains, validated and renewed automatically.Edge and delivery
Amazon API GatewayHTTP APIs with custom domains, routes into Lambda, and authorizers that check the user before any code runs.APIs and compute
AWS LambdaWhere the application code runs: API handlers, queue workers and scheduled jobs, on Node.js.APIs and compute
Amazon EventBridgeCron and rate schedules that trigger Lambda jobs, defined alongside the function they run.APIs and compute
Amazon SQSQueues between the API and background work, feeding Lambda workers, with dead-letter queues for anything that keeps failing.Messaging and email
Amazon SESTransactional email from my own domains, with DKIM and a custom MAIL FROM so it lands in the inbox.Messaging and email
Amazon RDS for PostgreSQLThe main relational database, PostgreSQL, running in private subnets.Data and identity
Amazon CognitoUser sign-up and sign-in, including Google and Sign in with Apple, wired into API Gateway authorizers.Data and identity
Amazon VPCPrivate networking for the database, with VPC endpoints so Lambda reaches AWS services without the public internet.Network, security and operations
Amazon EC2Small instances where they beat a managed service on cost: a NAT instance (fck-nat) and a jumpbox into the private network.Network, security and operations
AWS IAMA role per service with only the permissions it needs, and deployments that assume a role instead of using long-lived keys.Network, security and operations
AWS KMSEncryption keys for data at rest.Network, security and operations
Amazon CloudWatchLogs and metrics for every Lambda, with log subscriptions to route them where they are needed.Network, security and operations

What runs on it

  • Agaya Cloud

    TrueSignal and its APIs, portal and background jobs

  • Asklet

    Survey API and Lambda deployment

  • dinocorreia.com

    This site: S3 and CloudFront, deployed by assuming an IAM role

See the projects →

Building something on AWS?

Whether it's a new product, a migration, or a stack that's grown messy, I'm happy to talk it through.

AWS service icons are the official AWS Architecture Icons, used here to illustrate architecture. Amazon Web Services, AWS and the service names are trademarks of Amazon.com, Inc. or its affiliates. Terraform is a trademark of HashiCorp. No endorsement is implied.