Infrastructure Architecture

This page covers the cloud deployment architecture. For conceptual architecture and request flows, see Architecture Overview.

Cloud architecture

                              Internet
                                  │
                                  ▼
                    ┌─────────────────────────────┐
                    │      Cloud Load Balancer    │
                    │    • TLS termination        │
                    │    • WAF rules              │
                    │    • Health checks          │
                    └─────────────┬───────────────┘
                                  │
        ┌─────────────────────────┼─────────────────────────┐
        │                         │                         │
        ▼                         ▼                         ▼
┌───────────────┐  ┌───────────────────────────────────────────────┐
│ CDN / Bucket  │  │              Private Network                  │
│(static assets)│  │                                               │
│               │  │  ┌─────────────────┐   ┌───────────────────┐  │
│ • SPA apps    │  │  │  Kong Gateway   │   │  Next.js Frontend │  │
│ • Edge cache  │  │  │  (api.*)        │   │  (example.com)    │  │
│               │  │  │  • JWT, CORS    │   │  • SSR container  │  │
└───────────────┘  │  └────────┬────────┘   └───────────────────┘  │
                   │           │                                   │
                   │     ┌─────┴─────────────────┐                 │
                   │     │           │           │                 │
                   │     ▼           ▼           ▼                 │
                   │  ┌───────┐ ┌─────────┐ ┌───────┐              │
                   │  │ Auth  │ │ Offers  │ │  BFF  │              │
                   │  │Service│ │ Service │ │       │              │
                   │  └───┬───┘ └────┬────┘ └───┬───┘              │
                   │      │          │          │                  │
                   │      ▼          ▼          ▼                  │
                   │  ┌───────────────────────────────────────┐    │
                   │  │          Managed PostgreSQL           │    │
                   │  │    • Private IP • Per-service DBs     │    │
                   │  └───────────────────────────────────────┘    │
                   │                                               │
                   │  ┌───────────────────────────────────────┐    │
                   │  │            Managed Redis              │    │
                   │  │    • Rate limiting • Sessions         │    │
                   │  └───────────────────────────────────────┘    │
                   │                                               │
                   │  ┌───────────────────────────────────────┐    │
                   │  │           Secret Manager              │    │
                   │  │    • JWT keys • DB credentials        │    │
                   │  └───────────────────────────────────────┘    │
                   │                                               │
                   └───────────────────────────────────────────────┘

Cloud components

ComponentServiceNotes
Load BalancerCloud LBTLS termination, WAF, health checks
CDNCloud CDNStatic assets, edge caching
API GatewayKong (containerized)Internal ingress, auth, rate limiting
Backend ServicesContainersInternal-only ingress
Frontend (Next.js)Container + CDNSSR container, static via CDN
SPA AppsBucket + CDNStatic hosting
DatabaseManaged PostgreSQLPrivate IP, automated backups
CacheManaged RedisPrivate IP, HA
Object StorageCloud Storage / S3 / Azure BlobPer-bucket, private access
SecretsSecret ManagerVersioned, access-controlled

Network isolation

Backend services are deployed with internal-only ingress. Only the Load Balancer is publicly accessible. Kong Gateway runs internally and receives traffic from the Load Balancer.

ComponentIngressReachable From
Load BalancerExternalInternet
Kong GatewayInternalLoad Balancer
Auth ServiceInternalKong only
Offers ServiceInternalKong only
BFF ServiceInternalKong only
PostgreSQLNonePrivate VPC only
RedisNonePrivate VPC only
Object StorageNonePrivate VPC only

This isolation ensures:

  • Services only accept requests from Kong (validated by trust headers)
  • External attackers cannot bypass authentication
  • Database, cache, and storage buckets are never exposed to the internet

Terraform resources

Infrastructure is managed with Terraform. The framework generates provider-specific configurations:

Networking

  • VPC with private and public subnets
  • Private service connections for managed databases
  • Firewall rules for service-to-service communication

Compute

  • Container runtime (Cloud Run, ECS, Container Apps)
  • Auto-scaling based on request volume
  • Health check configuration

Data

  • Managed PostgreSQL with per-service databases
  • Managed Redis for rate limiting and caching
  • Private IP connectivity only

Storage

  • Cloud-native object storage buckets (GCS, S3, Azure Blob)
  • Private access only — no public bucket URLs
  • IAM/managed identity access from services
  • See Object Storage for details

Load balancing

  • Global load balancer with TLS certificates
  • URL maps for routing (API vs static)
  • Cloud CDN integration

Security

  • Secret Manager for sensitive configuration
  • IAM roles with least-privilege access
  • WAF rules for common attack patterns

Security layers

  1. WAF - Blocks common attack patterns at the edge
  2. Load Balancer - TLS termination, DDoS protection
  3. Kong Gateway - JWT validation, rate limiting, header sanitization
  4. Network isolation - Services unreachable from internet
  5. Trust headers - Services verify requests came through Kong
  6. Secret Manager - Secrets never in code or environment variables

Local vs cloud comparison

AspectLocalCloud
Entry pointlocalhost:8000Load Balancer IP
TLSNone (HTTP)Managed certificates
WAFNoneCloud WAF
ServicesDirect port accessInternal only
DatabaseContainerManaged service
Secrets.secrets.local.jsonSecret Manager
ScalingSingle instanceAuto-scaling
Object StorageMinIO containerCloud-native (GCS/S3/Azure Blob)
ObservabilityLocal Prometheus/JaegerCloud Monitoring

Your code works identically in both environments. Only configuration differs.