Amazon CloudFront
The front door for every site and app: caching, TLS, and CloudFront Functions running at the edge.
Cloud · AWS · Terraform
My own products run on AWS, and I orchestrate all of it with Terraform: serverless where it fits, managed services where mistakes are expensive, and every piece written as code.
Architecture
Pick a path. These are the patterns my projects actually use.
Loading a page: DNS resolves to CloudFront, which serves the site from a private S3 bucket and caches it at the edge.
The services
Every service here is in production in my own projects.
Everything a visitor touches first.
The front door for every site and app: caching, TLS, and CloudFront Functions running at the edge.
Static sites and SvelteKit assets behind CloudFront, plus file storage. Private buckets, encrypted and versioned.
DNS for every domain and subdomain, pointed at CloudFront and API custom domains.
TLS certificates for CloudFront and API domains, validated and renewed automatically.
Serverless by default: pay per request, nothing to patch.
HTTP APIs with custom domains, routes into Lambda, and authorizers that check the user before any code runs.
Where the application code runs: API handlers, queue workers and scheduled jobs, on Node.js.
Cron and rate schedules that trigger Lambda jobs, defined alongside the function they run.
Slow or unreliable work moves off the request path.
Queues between the API and background work, feeding Lambda workers, with dead-letter queues for anything that keeps failing.
Transactional email from my own domains, with DKIM and a custom MAIL FROM so it lands in the inbox.
Managed services for the parts that are expensive to get wrong.
The main relational database, PostgreSQL, running in private subnets.
User sign-up and sign-in, including Google and Sign in with Apple, wired into API Gateway authorizers.
Private by default, least privilege, and visible when something breaks.
Private networking for the database, with VPC endpoints so Lambda reaches AWS services without the public internet.
Small instances where they beat a managed service on cost: a NAT instance (fck-nat) and a jumpbox into the private network.
A role per service with only the permissions it needs, and deployments that assume a role instead of using long-lived keys.
Encryption keys for data at rest.
Logs and metrics for every Lambda, with log subscriptions to route them where they are needed.
Orchestration
Nothing is clicked together in the console. Each project is composed from a shared set of modules, so a new product starts with the same edge, API, queue and database setup instead of a blank page.
At a glance
| Service | What I use it for | Layer |
|---|---|---|
| Amazon CloudFront | The front door for every site and app: caching, TLS, and CloudFront Functions running at the edge. | Edge and delivery |
| Amazon S3 | Static sites and SvelteKit assets behind CloudFront, plus file storage. Private buckets, encrypted and versioned. | Edge and delivery |
| Amazon Route 53 | DNS for every domain and subdomain, pointed at CloudFront and API custom domains. | Edge and delivery |
| AWS Certificate Manager | TLS certificates for CloudFront and API domains, validated and renewed automatically. | Edge and delivery |
| Amazon API Gateway | HTTP APIs with custom domains, routes into Lambda, and authorizers that check the user before any code runs. | APIs and compute |
| AWS Lambda | Where the application code runs: API handlers, queue workers and scheduled jobs, on Node.js. | APIs and compute |
| Amazon EventBridge | Cron and rate schedules that trigger Lambda jobs, defined alongside the function they run. | APIs and compute |
| Amazon SQS | Queues between the API and background work, feeding Lambda workers, with dead-letter queues for anything that keeps failing. | Messaging and email |
| Amazon SES | Transactional email from my own domains, with DKIM and a custom MAIL FROM so it lands in the inbox. | Messaging and email |
| Amazon RDS for PostgreSQL | The main relational database, PostgreSQL, running in private subnets. | Data and identity |
| Amazon Cognito | User sign-up and sign-in, including Google and Sign in with Apple, wired into API Gateway authorizers. | Data and identity |
| Amazon VPC | Private networking for the database, with VPC endpoints so Lambda reaches AWS services without the public internet. | Network, security and operations |
| Amazon EC2 | Small instances where they beat a managed service on cost: a NAT instance (fck-nat) and a jumpbox into the private network. | Network, security and operations |
| AWS IAM | A role per service with only the permissions it needs, and deployments that assume a role instead of using long-lived keys. | Network, security and operations |
| AWS KMS | Encryption keys for data at rest. | Network, security and operations |
| Amazon CloudWatch | Logs and metrics for every Lambda, with log subscriptions to route them where they are needed. | Network, security and operations |
Agaya Cloud
TrueSignal and its APIs, portal and background jobs
Asklet
Survey API and Lambda deployment
dinocorreia.com
This site: S3 and CloudFront, deployed by assuming an IAM role
Whether it's a new product, a migration, or a stack that's grown messy, I'm happy to talk it through.
AWS service icons are the official AWS Architecture Icons, used here to illustrate architecture. Amazon Web Services, AWS and the service names are trademarks of Amazon.com, Inc. or its affiliates. Terraform is a trademark of HashiCorp. No endorsement is implied.