ArchitectureInfrastructure is the map of everything the other pages touch — the ALBs, both ECS services, DynamoDB,
Bedrock, the transcript Lambda, GCS, SES, the scheduled backup and drift-detection Lambdas, and the CodePipeline blue/green deploy. All of it is provisioned as Terraform IaC; click a
node to see what it does and which page depends on it.
Interactive multi-cloud architecture
How it's all built
Every component below is provisioned by Terraform and cross-checked against terraform/main/*.tf. Click any node for what it does and why it's there, or trace a data flow end to end.
3
Clouds — AWS, Azure, Google Cloud
2
ECS Fargate services, 2–4 tasks each
2
Availability zones in ap-southeast-2
100%
Provisioned as Terraform IaC
Trace a flow
Scroll sideways to see the whole diagram
Click a component
Hover to highlight what it talks to. Click for a plain-English explanation, its build status, and the real Terraform-backed details.
AWS platform
Our containerised app
AWS CI/CD pipeline
Microsoft Azure
Google Cloud
Real data flow
Component breakdown
What each cloud is responsible for
Microsoft Azure
Identity & DNS
Entra ID — SAML 2.0 SSO. Enterprise App federated to AWS through an IAM SAML identity provider.
MFA & conditional access enforced at sign-in, before any AWS role is assumed.
Role mapping — SAML claims decide whether a user lands as DevOpsEngineer or ReadOnlyAuditor.
Azure DNS delegation. The delegated zone resolves both app hostnames to the AWS ALBs and carries the ACM validation records.
Amazon Web Services
Core platform · ap-southeast-2
VPC 10.0.0.0/16 — 2 public + 2 private subnets across 2 AZs, internet gateway and NAT gateway.
ECS Fargate — one cluster, two services in private subnets, step-scaling between 2 and 4 tasks.
2 Application Load Balancers on HTTPS 443 with an ACM certificate; port 80 redirects to 443.
CodePipeline → CodeBuild → CodeDeploy blue/green, one pipeline per service, images in ECR.