Production deployment ownership

Who runs what, and where traffic crosses

Architecture12 nodes · 12 connections

diagram.html#The link keeps the view, selection, route and playback.

About this diagram

Components and what they call: services, stores and the infrastructure between them.

Ask for one like it

Make an architecture diagram of this repository, backed by evidence from the code.

Read about architecture diagrams

The JSON

production-deployment/diagram.json240 lines
{  "kind": "architecture",  "density": "compact",  "title": "Production deployment ownership",  "subtitle": "Who runs what, and where traffic crosses",  "direction": "RIGHT",  "groups": [    { "id": "us-east", "label": "AWS us-east-1 · production" },    {      "id": "private",      "label": "Private application network",      "parent": "us-east",      "tone": "security"    },    { "id": "eu-west", "label": "AWS eu-west-1 · disaster recovery" }  ],  "nodes": [    {      "id": "clients",      "type": "client",      "card": { "title": "Customers", "subtitle": "Web and mobile" }    },    {      "id": "edge",      "type": "gateway",      "group": "us-east",      "card": {        "title": "Global edge",        "subtitle": "CDN and WAF",        "brand": "cloudflare",        "tag": "Platform"      }    },    {      "id": "gateway",      "type": "security",      "group": "us-east",      "card": {        "title": "API gateway",        "subtitle": "Public :443",        "tag": "Platform"      }    },    {      "id": "api-a",      "type": "service",      "group": "private",      "card": {        "title": "API pods · AZ-a",        "subtitle": "Private subnet",        "brand": "kubernetes",        "tag": "Orders team"      }    },    {      "id": "api-b",      "type": "service",      "group": "private",      "card": {        "title": "API pods · AZ-b",        "subtitle": "Private subnet",        "brand": "kubernetes",        "tag": "Orders team"      }    },    {      "id": "redis",      "type": "cache",      "group": "private",      "card": {        "title": "Redis",        "subtitle": "Multi-AZ cache",        "brand": "redis",        "tag": "Platform"      }    },    {      "id": "postgres",      "type": "database",      "group": "private",      "card": {        "title": "PostgreSQL",        "subtitle": "Primary, encrypted",        "brand": "postgresql",        "tag": "Data"      }    },    {      "id": "events",      "type": "queue",      "group": "private",      "card": {        "title": "Event bus",        "subtitle": "orders.v1",        "tag": "Platform"      }    },    {      "id": "workers",      "type": "service",      "group": "private",      "card": {        "title": "Workers",        "subtitle": "Private workload",        "tag": "Orders team"      }    },    {      "id": "audit",      "type": "storage",      "group": "us-east",      "card": {        "title": "Audit archive",        "subtitle": "Immutable objects",        "tag": "Security"      }    },    {      "id": "replica",      "type": "database",      "group": "eu-west",      "card": {        "title": "DR replica",        "subtitle": "eu-west-1",        "brand": "postgresql",        "tag": "Data"      }    },    {      "id": "observability",      "type": "external",      "card": {        "title": "Observability",        "subtitle": "Metrics and traces",        "tag": "SRE"      }    }  ],  "edges": [    {      "id": "e1",      "from": "clients",      "to": "edge",      "label": "HTTPS",      "tone": "main"    },    {      "id": "e2",      "from": "edge",      "to": "gateway",      "label": "mTLS",      "tone": "security"    },    {      "id": "e3",      "from": "gateway",      "to": "api-a",      "label": "VPC route",      "tone": "main"    },    {      "id": "e4",      "from": "gateway",      "to": "api-b",      "label": "VPC route",      "tone": "main"    },    { "id": "e5", "from": "api-a", "to": "redis", "label": "cache" },    { "id": "e6", "from": "api-b", "to": "postgres", "label": "SQL" },    {      "id": "e7",      "from": "api-a",      "to": "events",      "label": "publish",      "kind": "async"    },    { "id": "e8", "from": "api-b", "to": "events", "kind": "async" },    { "id": "e9", "from": "events", "to": "workers", "tone": "main" },    {      "id": "e10",      "from": "postgres",      "to": "replica",      "label": "cross-region WAL",      "tone": "security"    },    {      "id": "e11",      "from": "workers",      "to": "audit",      "label": "evidence",      "kind": "async"    },    {      "id": "e12",      "from": "workers",      "to": "observability",      "label": "OTLP",      "kind": "async"    }  ],  "views": [    {      "id": "crossings",      "label": "Crossings",      "caption": "Public HTTPS ends at the edge; mTLS crosses into the private network; WAL crosses regions.",      "nodes": ["clients", "edge", "gateway", "postgres", "replica"]    },    {      "id": "async",      "label": "Async work",      "caption": "API pods publish to the event bus; workers drain it and leave evidence.",      "nodes": [        "api-a",        "api-b",        "events",        "workers",        "audit",        "observability"      ]    }  ],  "notes": [    {      "title": "Runtime ownership",      "items": [        "Platform owns the edge, gateway, cache and event bus",        "Application teams own API pods and workers",        "Data owns primary and disaster-recovery state"      ]    },    {      "title": "Named crossings",      "items": [        "Public HTTPS terminates at the managed edge",        "mTLS crosses into the application network",        "Cross-region WAL is explicit and encrypted"      ]    }  ]}

More architecture examples

All examples