Platform & Architecture

Infrastructure and deployment patterns used to ship and operate multi-service backend systems, with emphasis on secure configuration, repeatable releases, and operational clarity.

How it ships

AWS EC2 (Ubuntu) · Nginx reverse proxy (TLS via Let's Encrypt) · Dockerized Next.js (portfolio) on 127.0.0.1:3000 · GitHub Actions CI/CD (SSH deploy)

Blue/green deployments use Nginx upstream snippet (ports 3000/3001) for low-downtime releases and quick rollback. See repo docs: NGINX_BLUE_GREEN.md, CI_CD.md.

System Map

Platform Microservices Topology
Client Tier Blockchain Ingestion & Workers Datastores
CLIENT-FACING SERVICESCMS / Admin UIWeb ClientProduct UIApp & Webcms-apiNestJS / RBACdata-integrationNestJS / Externalchat-backendNode / WebSocketsBLOCKCHAIN INGESTION & OPSEVM Blockchain NetworkEthereum / RPC Nodes (Alchemy)contract-listenerUptime-critical Event Ingestion (NestJS)smart-contract-interactionIsolated Write Boundary & Nonce ManagerDATA PIPELINES & BATCH JOBSgames-importerScheduled Cron Ingestion & ETLserver-import / syncProvider Synchronization Jobsllm-evaluator (worker)Async Prompt Scoring (Django / Celery)PERSISTENCE & EVENT STORAGE BOUNDARYPostgreSQL (RDS / Primary)ACID Transactions & Relational EntitiesRedis (Cluster & Pub/Sub)Realtime State, Caches, Event BusAWS S3 & Secrets ManagerArtifacts, Blob Media, Rotatable Configs

Platform microservices topology showing client-facing services, blockchain ingestion, and shared datastores (Source: DIAGRAMS.md §3).

Infra Map

Terraform As Control Plane Pattern
IaC Control Plane AWS Cloud Kubernetes & Helm Observability
TERRAFORMControl Plane (CLI / Cloud)• Declarative VPC & IAM• RDS & EKS Provisioning• Reads Secrets Manager• Templates Helm Values• Idempotent State LockingAWS FOUNDATIONSVPC / Subnets / SG / IAMIsolated Network TopologyAWS Secrets ManagerRotatable CredentialsHELM RELEASESParameterized ChartsTemplated by TerraformKUBERNETES (EKS)Container OrchestrationMicroservice Podscontract-listener · cms · chatIngress & ServicesTLS / Internal Load BalancingConfigMaps & CSI SecretsInjected via Secrets ManagerOBSERVABILITYRuntime Signals• CloudWatch Logs• Prometheus Metrics• Grafana Dashboards• Liveness / Readiness

Terraform control plane pattern templating Helm releases, managing AWS Secrets, and delivering to Kubernetes (Source: DIAGRAMS.md §4).

Deployment Flow

Zero-Downtime Blue/Green CI/CD Pipeline
GitHub Actions Blue/Green Containers Nginx Upstream Switch Auto-Rollback Trap
1. COMMITgit push mainGitHub WebhookTriggers CI Pipeline2. GITHUB ACTIONS✓ npm ci✓ npm run lint✓ npm run typecheck✓ Standalone buildSSH to EC2 HostDeploy key authentication3. EC2 BLUE / GREEN ENGINETarget Color Selection (3000/3001)Prune Docker & Build Target ImageContainer Healthcheck Pollingwget -qO- http://localhost:3000/Origin Readiness (curl 127.0.0.1)Automated Rollback on ErrorReverts Nginx & destroys broken container4. NGINX CUTOVER & VERIFYSwitch Upstream Portportfolio_upstream.conf (snippet)nginx -t && reload (0ms down)Edge Check: curl https://...Stop Old Color & Prune Disk

Automated zero-downtime blue/green deployment workflow via GitHub Actions, Docker Compose, and Nginx upstream reloads (Source: DIAGRAMS.md §2).

Security Boundaries

Public: 80/443 via Nginx. App container bound to 127.0.0.1.

Secrets & Configuration

Centralized secrets and safe configuration injection to avoid leaking sensitive data into repos or images.

  • Prefer managed secrets (AWS Secrets Manager / secure env patterns)
  • Avoid committing secrets; keep production env separate
  • Promote rotatable credentials and auditable changes

Reverse Proxy & TLS

Nginx terminates TLS and exposes only HTTPS to the public, keeping app services private on localhost.

  • HTTP → HTTPS redirect
  • Let's Encrypt certificates with automatic renewal
  • Only ports 80/443 public; app binds to 127.0.0.1

Reliability Patterns

Operational Readiness

Production mindset: health, debugging, and visibility matter as much as features.

  • Service health and graceful failure handling
  • Logging and monitoring patterns (CloudWatch / Prometheus/Grafana style)
  • Incident-oriented debugging habits

CI/CD

Automated delivery pipelines with tight feedback loops and predictable deployments.

  • GitHub Actions / GitLab CI/CD / Jenkins experience
  • Build → test/lint → deploy via SSH (for EC2-hosted portfolio)
  • Container-based deployment to reduce host drift

Kubernetes + Helm Delivery (Platform Work)

For backend platform services, Helm enables templated deployments and consistent release workflows.

  • Helm charts for parameterized deployments
  • Support for rollouts, rollbacks, and repeatable releases
  • Service isolation with clear boundaries per microservice

Infrastructure patterns

Terraform as a Control Plane

Terraform is used not only for provisioning but also to standardize configuration patterns across services.

  • Provision and standardize AWS resources as infrastructure code
  • Maintain repeatable environment configuration patterns
  • Support multi-service deployments with consistent inputs/outputs

GitOps & Secret Synchronization

Continuous delivery with ArgoCD and Kubernetes External Secrets Operator syncing directly from AWS Secrets Manager.

  • ArgoCD declarative GitOps reconciling application state against Git
  • External Secrets Operator (ESO) syncing production credentials without manual secrets injection
  • Network Load Balancer (NLB) with TLS termination routing traffic to ingress-nginx

Related Projects

View all Projects →