Infrastructure Architecture
This page covers the cloud deployment architecture. For conceptual architecture and request flows, see Architecture Overview.
Cloud architecture
Internet
│
▼
┌─────────────────────────────┐
│ Cloud Load Balancer │
│ • TLS termination │
│ • WAF rules │
│ • Health checks │
└─────────────┬───────────────┘
│
┌─────────────────────────┼─────────────────────────┐
│ │ │
▼ ▼ ▼
┌───────────────┐ ┌───────────────────────────────────────────────┐
│ CDN / Bucket │ │ Private Network │
│(static assets)│ │ │
│ │ │ ┌─────────────────┐ ┌───────────────────┐ │
│ • SPA apps │ │ │ Kong Gateway │ │ Next.js Frontend │ │
│ • Edge cache │ │ │ (api.*) │ │ (example.com) │ │
│ │ │ │ • JWT, CORS │ │ • SSR container │ │
└───────────────┘ │ └────────┬────────┘ └───────────────────┘ │
│ │ │
│ ┌─────┴─────────────────┐ │
│ │ │ │ │
│ ▼ ▼ ▼ │
│ ┌───────┐ ┌─────────┐ ┌───────┐ │
│ │ Auth │ │ Offers │ │ BFF │ │
│ │Service│ │ Service │ │ │ │
│ └───┬───┘ └────┬────┘ └───┬───┘ │
│ │ │ │ │
│ ▼ ▼ ▼ │
│ ┌───────────────────────────────────────┐ │
│ │ Managed PostgreSQL │ │
│ │ • Private IP • Per-service DBs │ │
│ └───────────────────────────────────────┘ │
│ │
│ ┌───────────────────────────────────────┐ │
│ │ Managed Redis │ │
│ │ • Rate limiting • Sessions │ │
│ └───────────────────────────────────────┘ │
│ │
│ ┌───────────────────────────────────────┐ │
│ │ Secret Manager │ │
│ │ • JWT keys • DB credentials │ │
│ └───────────────────────────────────────┘ │
│ │
└───────────────────────────────────────────────┘
Cloud components
Network isolation
Backend services are deployed with internal-only ingress. Only the Load Balancer is publicly accessible. Kong Gateway runs internally and receives traffic from the Load Balancer.
This isolation ensures:
- Services only accept requests from Kong (validated by trust headers)
- External attackers cannot bypass authentication
- Database, cache, and storage buckets are never exposed to the internet
Terraform resources
Infrastructure is managed with Terraform. The framework generates provider-specific configurations:
Networking
- VPC with private and public subnets
- Private service connections for managed databases
- Firewall rules for service-to-service communication
Compute
- Container runtime (Cloud Run, ECS, Container Apps)
- Auto-scaling based on request volume
- Health check configuration
Data
- Managed PostgreSQL with per-service databases
- Managed Redis for rate limiting and caching
- Private IP connectivity only
Storage
- Cloud-native object storage buckets (GCS, S3, Azure Blob)
- Private access only — no public bucket URLs
- IAM/managed identity access from services
- See Object Storage for details
Load balancing
- Global load balancer with TLS certificates
- URL maps for routing (API vs static)
- Cloud CDN integration
Security
- Secret Manager for sensitive configuration
- IAM roles with least-privilege access
- WAF rules for common attack patterns
Security layers
- WAF - Blocks common attack patterns at the edge
- Load Balancer - TLS termination, DDoS protection
- Kong Gateway - JWT validation, rate limiting, header sanitization
- Network isolation - Services unreachable from internet
- Trust headers - Services verify requests came through Kong
- Secret Manager - Secrets never in code or environment variables
Local vs cloud comparison
Your code works identically in both environments. Only configuration differs.