Skip to content

System Overview ​

High-Level Architecture ​

PeopleHub is a serverless, microservices-based HRMS platform deployed entirely on AWS.

Component Breakdown ​

Frontend Layer ​

  • Main Frontend: React 19 app for internal users (HR, managers, employees)
  • Candidate Frontend: Isolated React app for candidate onboarding
  • Deployment: Both hosted on S3, distributed via CloudFront globally

API Gateway Layer ​

  • Single HTTP API Gateway routing all requests
  • JWT validation before Lambda invocation
  • Regional deployment (ap-south-1)

Backend Services ​

  • Main API: Core HRMS functionality (employee, leave, performance, etc.)
  • Candidate API: Onboarding workflows (security-isolated from main system)
  • Integration API: External system integrations and cron jobs
  • Notifications API: Email notification engine
  • PDF Service: Document generation

All services:

  • Built with Node.js 22 / Fastify (PDF service uses Python)
  • Deploy as single Lambda function per service
  • ~1.5MB package size each
  • Share same RDS database

Data Layer ​

  • RDS PostgreSQL 17.5: Multi-AZ for high availability
  • 140+ tables: Complete HRMS data model
  • S3: Document storage (employee docs, policies, images)

Supporting Services ​

  • AWS Secrets Manager: Database credentials, API keys, JWT secrets
  • AWS SES: Transactional email delivery
  • CloudWatch: Logging and monitoring

Request Flow ​

Typical API Request ​

  1. User action in React frontend
  2. HTTP request to CloudFront
  3. CloudFront routes to API Gateway
  4. API Gateway validates JWT token
  5. Routes to appropriate Lambda function
  6. Lambda processes request (queries database if needed)
  7. Response returned through same path

Document Upload Flow ​

  1. Frontend requests presigned S3 URL from backend
  2. Backend generates presigned URL (valid 15 minutes)
  3. Frontend uploads file directly to S3
  4. Frontend notifies backend of successful upload
  5. Backend stores file metadata in database

Security Layers ​

  1. CloudFront: DDoS protection, TLS termination
  2. API Gateway: JWT validation, rate limiting
  3. Lambda: Business logic authorization (RBAC)
  4. RDS: Private subnet (production plan), encryption at rest
  5. S3: Private buckets, presigned URLs only

Scalability ​

Automatic Scaling ​

  • Frontend: CloudFront scales automatically, no limit
  • Lambda: Scales from 0 to 1000 concurrent executions automatically
  • RDS: Vertical scaling (increase instance size as needed)
  • S3: Unlimited storage

Current Limits ​

  • Lambda concurrency: 1000 (AWS default, can be increased)
  • RDS connections: Configurable based on instance size
  • API Gateway: 10,000 requests per second per region

Availability ​

High Availability Features ​

  • Multi-AZ RDS: Automatic failover <30 seconds
  • CloudFront: 99.9% SLA, global edge locations
  • Lambda: 99.95% SLA, distributed across AZs
  • S3: 99.99% availability, 11 9's durability

System Composite SLA ​

Target: 99.9%+ uptime (less than 44 minutes downtime per month)

Environments ​

Development ​

  • Region: ap-south-1
  • Database: Open for dev team access
  • Frontend: https://peoplehub.dev.wysbryxapp.com

Staging ​

  • Region: ap-south-1
  • Database: Open for testing
  • Frontend: https://peoplehub.staging.wysbryxapp.com

Production ​

  • Region: ap-south-1
  • Database: VPC-isolated (planned)
  • Frontend: Client's production domain

Each environment has isolated infrastructure, databases, and S3 buckets.

Data Flow ​

See Data Flow for detailed employee lifecycle flows.

Service Interactions ​

See Service Architecture for inter-service communication patterns.