Architecture Infrastructure is the map of everything the other pages touch — the ALBs, both ECS services, DynamoDB, Bedrock, the transcript Lambda, GCS, SES, the scheduled backup and drift-detection Lambdas, and the CodePipeline blue/green deploy. All of it is provisioned as Terraform IaC; click a node to see what it does and which page depends on it.
Interactive multi-cloud architecture

How it's all built

Every component below is provisioned by Terraform and cross-checked against terraform/main/*.tf. Click any node for what it does and why it's there, or trace a data flow end to end.

3
Clouds — AWS, Azure, Google Cloud
2
ECS Fargate services, 2–4 tasks each
2
Availability zones in ap-southeast-2
100%
Provisioned as Terraform IaC
Trace a flow
Scroll sideways to see the whole diagram
Click a component
Hover to highlight what it talks to. Click for a plain-English explanation, its build status, and the real Terraform-backed details.
AWS platform
Our containerised app
AWS CI/CD pipeline
Microsoft Azure
Google Cloud
Real data flow
Component breakdown
What each cloud is responsible for
Microsoft Azure
Identity & DNS
Entra ID — SAML 2.0 SSO. Enterprise App federated to AWS through an IAM SAML identity provider.
MFA & conditional access enforced at sign-in, before any AWS role is assumed.
Role mapping — SAML claims decide whether a user lands as DevOpsEngineer or ReadOnlyAuditor.
Azure DNS delegation. The delegated zone resolves both app hostnames to the AWS ALBs and carries the ACM validation records.
Amazon Web Services
Core platform · ap-southeast-2
VPC 10.0.0.0/16 — 2 public + 2 private subnets across 2 AZs, internet gateway and NAT gateway.
ECS Fargate — one cluster, two services in private subnets, step-scaling between 2 and 4 tasks.
2 Application Load Balancers on HTTPS 443 with an ACM certificate; port 80 redirects to 443.
CodePipeline → CodeBuild → CodeDeploy blue/green, one pipeline per service, images in ECR.
DynamoDB — yoobeecloud-courses, on-demand billing, serves /api/courses.
Bedrock — Claude Haiku 4.5, answers /api/chat grounded in the courses table.
Lambda (Node.js 20) renders the transcript PDF, uploads it to GCS and sends the SES confirmation.
Backup Lambda — daily EventBridge schedule snapshots the courses table to Google Cloud Storage.
Drift-detection Lambda — six-hourly check that each ALB listener still points at the target group with healthy tasks.
CloudWatch + SNS — dashboard, container logs, four CPU alarms, email alerts to the ops mailbox.
Google Cloud
Object storage
Cloud Storage bucket — the durable home for every generated transcript.
Transcript PDFs written directly by the AWS Lambda after each chat session.
DynamoDB snapshots under backups/ — the same bucket doubles as off-AWS disaster recovery.
Service-account credentials held in AWS Secrets Manager — no keys in code or container images.
Operations
Keeping it healthy
CloudWatch dashboard
One dashboard covers both ECS services and both ALBs, with Container Insights on the cluster and a dedicated log group per service.
Alarms & SNS alerts
CPU alarms at 70% (scale out) and 30% (scale in) on each service; the high-CPU alarms also publish to an SNS topic that emails the ops mailbox.
Autoscaling
Application Auto Scaling step policies add and remove Fargate tasks between 2 and 4 per service, without touching the load balancers.