Skip to content

Infrastructure & Deployment ​

Complete infrastructure, deployment, and environment documentation for PeopleHub.


AWS Architecture ​

AWS Services Used ​

Compute:

  • AWS Lambda (Node.js 22.x, Python 3.11)
  • 1024 MB memory, 10-30s timeout
  • Serverless, auto-scaling

API & Networking:

  • API Gateway HTTP API
  • CloudFront CDN (global)
  • Route 53 (future - multi-region)

Database & Storage:

  • RDS PostgreSQL 17.5 (Multi-AZ)
  • S3 (documents, frontend hosting)
  • AWS Secrets Manager (credentials)

Messaging & Notifications:

  • AWS SES (email)
  • SNS (future - SMS, push notifications)
  • SQS (future - async processing)

Monitoring & Security:

  • CloudWatch Logs & Metrics
  • IAM (access control)
  • AWS KMS (encryption)
  • WAF (planned)
  • GuardDuty (planned)

Region: ap-south-1 (Mumbai)


Serverless Deployment ​

Serverless Framework ​

Configuration: Each service has serverless.yml

Deployment Process:

  1. serverless deploy --stage dev
  2. Package code with esbuild (backend) or Vite (frontend)
  3. Upload to S3
  4. Create/update Lambda function
  5. Configure API Gateway routes
  6. Set environment variables from Secrets Manager

Package Optimization:

  • esbuild minification
  • Tree shaking (remove unused code)
  • External dependencies excluded (aws-sdk, pg-native)
  • Result: ~1.5MB per Lambda

Infrastructure as Code ​

All infrastructure defined in code:

  • serverless.yml for Lambda and API Gateway
  • GitHub Actions for S3 and CloudFront

Benefits:

  • Version-controlled infrastructure
  • Reproducible deployments
  • Easy rollback
  • Environment parity (dev/staging/prod)

Environments ​

Development ​

Purpose: Active development and testing

Configuration:

  • Frontend: https://peoplehub.dev.wysbryxapp.com
  • API: Dev Lambda functions
  • Database: Open access for dev team (VPN not required)
  • S3: peoplehub-uploads-dev

Deployment: Automatic on push to dev branch

Staging ​

Purpose: Pre-production testing and QA

Configuration:

  • Frontend: https://peoplehub.staging.wysbryxapp.com
  • API: Staging Lambda functions
  • Database: Separate RDS instance (or schema)
  • S3: peoplehub-uploads-staging

Deployment: Automatic on push to staging branch

Production ​

Purpose: Live system for end users

Configuration:

  • Frontend: Client's production domain
  • API: Production Lambda functions
  • Database: RDS in private VPC (planned), Multi-AZ enabled
  • S3: peoplehub-uploads-prod

Deployment: Manual trigger or automatic on push to main branch (after approval)

Environment Isolation:

  • Separate AWS accounts (recommended) or separate VPCs
  • No cross-environment data access
  • Separate credentials and API keys

CI/CD Pipeline ​

GitHub Actions Workflows ​

Frontend Deployment (deploy-dev.yml, deploy-staging.yml):

Trigger: Push to dev/staging branch
Steps:
1. Checkout code
2. Setup Node.js 18
3. Install dependencies (npm ci)
4. Build with Vite (npm run build)
5. Sync to S3 (aws s3 sync)
6. Invalidate CloudFront cache
Duration: <2 minutes

Backend Deployment (deploy-backend-dev.yml):

Trigger: Push to dev/staging branch
Steps:
1. Checkout code
2. Setup Node.js 18
3. Install dependencies
4. TypeScript compilation check
5. Deploy with Serverless Framework
6. Test health endpoint
Duration: <3 minutes

Pre-Deployment Checks:

  • TypeScript compilation
  • ESLint validation
  • Pre-commit hooks (simple-git-hooks)

Deployment Strategy:

  • Blue/green: New Lambda version created, old version remains
  • Instant rollback: Revert to previous Lambda version
  • Zero downtime: Lambda versions coexist

Secrets Management ​

AWS Secrets Manager:

  • Database credentials
  • JWT secrets (access token + refresh token)
  • Cookie secret
  • External API keys (Digio, etc.)
  • AWS S3 bucket names

Rotation: Automatic every 30 days (planned)

Access: IAM roles grant Lambda access to specific secrets

Never in Code: No credentials in git repositories


Networking ​

Current State (Development) ​

Database: Publicly accessible (with password protection)

  • Allows dev team access for development
  • Sufficient for dev/staging environments

Lambda: Not in VPC

  • Faster cold starts
  • Direct internet access (no NAT Gateway cost)
  • Suitable for development phase

Production Plan ​

VPC Architecture:

  • Private subnets for RDS (no public IP)
  • Public subnets for NAT Gateway
  • Lambda in VPC (access RDS via private subnet)
  • Security groups: Least-privilege rules

Security Groups:

  • Lambda SG: Outbound to RDS, S3, internet
  • RDS SG: Inbound only from Lambda SG
  • No public inbound access to RDS

Benefits:

  • Network isolation
  • Defense in depth
  • Compliance readiness

Timeline: Before production launch


Cost Optimization ​

Serverless Benefits:

  • No idle costs (Lambda scales to zero)
  • Pay-per-use (only when Lambda executes)
  • No server management overhead

Current Monthly Costs (Dev environment):

  • Lambda: $15-25
  • RDS: $45-80
  • S3 + CloudFront: $5-10
  • API Gateway: $3-8
  • Total: $70-125/month

Traditional Equivalent: $250-400/month Savings: 65-75%