Infrastructure & Deployment
Complete infrastructure, deployment, and environment documentation for PeopleHub.
AWS Architecture
AWS Services Used
Compute:
- AWS Lambda (Node.js 22.x, Python 3.11)
- 1024 MB memory, 10-30s timeout
- Serverless, auto-scaling
API & Networking:
- API Gateway HTTP API
- CloudFront CDN (global)
- Route 53 (future - multi-region)
Database & Storage:
- RDS PostgreSQL 17.5 (Multi-AZ)
- S3 (documents, frontend hosting)
- AWS Secrets Manager (credentials)
Messaging & Notifications:
- AWS SES (email)
- SNS (future - SMS, push notifications)
- SQS (future - async processing)
Monitoring & Security:
- CloudWatch Logs & Metrics
- IAM (access control)
- AWS KMS (encryption)
- WAF (planned)
- GuardDuty (planned)
Region: ap-south-1 (Mumbai)
Serverless Deployment
Serverless Framework
Configuration: Each service has serverless.yml
Deployment Process:
serverless deploy --stage dev- Package code with esbuild (backend) or Vite (frontend)
- Upload to S3
- Create/update Lambda function
- Configure API Gateway routes
- Set environment variables from Secrets Manager
Package Optimization:
- esbuild minification
- Tree shaking (remove unused code)
- External dependencies excluded (aws-sdk, pg-native)
- Result: ~1.5MB per Lambda
Infrastructure as Code
All infrastructure defined in code:
serverless.ymlfor Lambda and API Gateway- GitHub Actions for S3 and CloudFront
Benefits:
- Version-controlled infrastructure
- Reproducible deployments
- Easy rollback
- Environment parity (dev/staging/prod)
Environments
Development
Purpose: Active development and testing
Configuration:
- Frontend:
https://peoplehub.dev.wysbryxapp.com - API: Dev Lambda functions
- Database: Open access for dev team (VPN not required)
- S3:
peoplehub-uploads-dev
Deployment: Automatic on push to dev branch
Staging
Purpose: Pre-production testing and QA
Configuration:
- Frontend:
https://peoplehub.staging.wysbryxapp.com - API: Staging Lambda functions
- Database: Separate RDS instance (or schema)
- S3:
peoplehub-uploads-staging
Deployment: Automatic on push to staging branch
Production
Purpose: Live system for end users
Configuration:
- Frontend: Client's production domain
- API: Production Lambda functions
- Database: RDS in private VPC (planned), Multi-AZ enabled
- S3:
peoplehub-uploads-prod
Deployment: Manual trigger or automatic on push to main branch (after approval)
Environment Isolation:
- Separate AWS accounts (recommended) or separate VPCs
- No cross-environment data access
- Separate credentials and API keys
CI/CD Pipeline
GitHub Actions Workflows
Frontend Deployment (deploy-dev.yml, deploy-staging.yml):
Trigger: Push to dev/staging branch
Steps:
1. Checkout code
2. Setup Node.js 18
3. Install dependencies (npm ci)
4. Build with Vite (npm run build)
5. Sync to S3 (aws s3 sync)
6. Invalidate CloudFront cache
Duration: <2 minutesBackend Deployment (deploy-backend-dev.yml):
Trigger: Push to dev/staging branch
Steps:
1. Checkout code
2. Setup Node.js 18
3. Install dependencies
4. TypeScript compilation check
5. Deploy with Serverless Framework
6. Test health endpoint
Duration: <3 minutesPre-Deployment Checks:
- TypeScript compilation
- ESLint validation
- Pre-commit hooks (simple-git-hooks)
Deployment Strategy:
- Blue/green: New Lambda version created, old version remains
- Instant rollback: Revert to previous Lambda version
- Zero downtime: Lambda versions coexist
Secrets Management
AWS Secrets Manager:
- Database credentials
- JWT secrets (access token + refresh token)
- Cookie secret
- External API keys (Digio, etc.)
- AWS S3 bucket names
Rotation: Automatic every 30 days (planned)
Access: IAM roles grant Lambda access to specific secrets
Never in Code: No credentials in git repositories
Networking
Current State (Development)
Database: Publicly accessible (with password protection)
- Allows dev team access for development
- Sufficient for dev/staging environments
Lambda: Not in VPC
- Faster cold starts
- Direct internet access (no NAT Gateway cost)
- Suitable for development phase
Production Plan
VPC Architecture:
- Private subnets for RDS (no public IP)
- Public subnets for NAT Gateway
- Lambda in VPC (access RDS via private subnet)
- Security groups: Least-privilege rules
Security Groups:
- Lambda SG: Outbound to RDS, S3, internet
- RDS SG: Inbound only from Lambda SG
- No public inbound access to RDS
Benefits:
- Network isolation
- Defense in depth
- Compliance readiness
Timeline: Before production launch
Cost Optimization
Serverless Benefits:
- No idle costs (Lambda scales to zero)
- Pay-per-use (only when Lambda executes)
- No server management overhead
Current Monthly Costs (Dev environment):
- Lambda: $15-25
- RDS: $45-80
- S3 + CloudFront: $5-10
- API Gateway: $3-8
- Total: $70-125/month
Traditional Equivalent: $250-400/month Savings: 65-75%