System Overview
High-Level Architecture
PeopleHub is a serverless, microservices-based HRMS platform deployed entirely on AWS.
Component Breakdown
Frontend Layer
- Main Frontend: React 19 app for internal users (HR, managers, employees)
- Candidate Frontend: Isolated React app for candidate onboarding
- Deployment: Both hosted on S3, distributed via CloudFront globally
API Gateway Layer
- Single HTTP API Gateway routing all requests
- JWT validation before Lambda invocation
- Regional deployment (ap-south-1)
Backend Services
- Main API: Core HRMS functionality (employee, leave, performance, etc.)
- Candidate API: Onboarding workflows (security-isolated from main system)
- Integration API: External system integrations and cron jobs
- Notifications API: Email notification engine
- PDF Service: Document generation
All services:
- Built with Node.js 22 / Fastify (PDF service uses Python)
- Deploy as single Lambda function per service
- ~1.5MB package size each
- Share same RDS database
Data Layer
- RDS PostgreSQL 17.5: Multi-AZ for high availability
- 140+ tables: Complete HRMS data model
- S3: Document storage (employee docs, policies, images)
Supporting Services
- AWS Secrets Manager: Database credentials, API keys, JWT secrets
- AWS SES: Transactional email delivery
- CloudWatch: Logging and monitoring
Request Flow
Typical API Request
- User action in React frontend
- HTTP request to CloudFront
- CloudFront routes to API Gateway
- API Gateway validates JWT token
- Routes to appropriate Lambda function
- Lambda processes request (queries database if needed)
- Response returned through same path
Document Upload Flow
- Frontend requests presigned S3 URL from backend
- Backend generates presigned URL (valid 15 minutes)
- Frontend uploads file directly to S3
- Frontend notifies backend of successful upload
- Backend stores file metadata in database
Security Layers
- CloudFront: DDoS protection, TLS termination
- API Gateway: JWT validation, rate limiting
- Lambda: Business logic authorization (RBAC)
- RDS: Private subnet (production plan), encryption at rest
- S3: Private buckets, presigned URLs only
Scalability
Automatic Scaling
- Frontend: CloudFront scales automatically, no limit
- Lambda: Scales from 0 to 1000 concurrent executions automatically
- RDS: Vertical scaling (increase instance size as needed)
- S3: Unlimited storage
Current Limits
- Lambda concurrency: 1000 (AWS default, can be increased)
- RDS connections: Configurable based on instance size
- API Gateway: 10,000 requests per second per region
Availability
High Availability Features
- Multi-AZ RDS: Automatic failover <30 seconds
- CloudFront: 99.9% SLA, global edge locations
- Lambda: 99.95% SLA, distributed across AZs
- S3: 99.99% availability, 11 9's durability
System Composite SLA
Target: 99.9%+ uptime (less than 44 minutes downtime per month)
Environments
Development
- Region: ap-south-1
- Database: Open for dev team access
- Frontend:
https://peoplehub.dev.wysbryxapp.com
Staging
- Region: ap-south-1
- Database: Open for testing
- Frontend:
https://peoplehub.staging.wysbryxapp.com
Production
- Region: ap-south-1
- Database: VPC-isolated (planned)
- Frontend: Client's production domain
Each environment has isolated infrastructure, databases, and S3 buckets.
Data Flow
See Data Flow for detailed employee lifecycle flows.
Service Interactions
See Service Architecture for inter-service communication patterns.
Related Documentation
- Service Architecture - How services communicate
- Data Flow - Employee lifecycle
- Scalability Model - Scaling approach
- AWS Architecture - AWS services detail