CLOUD · DEVOPS · ARCHITECTURE · AUTOMATION

Architecture ideas, made clear.

Explore reference designs across AWS, Azure, Google Cloud, Kubernetes, infrastructure as code and secure CI/CD. Select any diagram to open the full-size image in a new tab.

Architecture showcaseThese diagrams communicate design approaches; they are not proof of a production or customer deployment. Project descriptions should be updated with verified implementation details and outcomes where applicable.
REFERENCE LIBRARY

Cloud and DevOps architecture

Review the design, security boundaries, delivery flow and operational considerations. Customer names, account IDs, IPs, credentials and confidential details should never be published.

01AWS · Kubernetes · GitOps

Amazon EKS GitOps Architecture

Reference design for deploying containerized workloads to Amazon EKS with Argo CD, Helm, ingress and Prometheus/Grafana monitoring.

Amazon EKSArgo CDHelmNGINX IngressAurora MySQLPrometheusGrafana
View architecture notes
Delivery

Connect source control and CI to container image publishing, then reconcile Kubernetes manifests through GitOps.

Networking

Plan ingress, subnet boundaries, cluster access and private data-layer connectivity.

Operations

Use metrics, dashboards, health checks and rollout/rollback procedures.

02Google Cloud · Kubernetes

Google Kubernetes Engine (GKE)

Reference design for a GKE application platform with GitHub Actions OIDC, Artifact Registry, Cloud Load Balancing and Cloud SQL.

GKEGitHub ActionsOIDCArtifact RegistryCloud SQLCloud Monitoring
View architecture notes
Identity

Use workload identity federation rather than long-lived cloud credentials in CI.

Delivery

Build and scan images, publish to Artifact Registry, and deploy through Helm or kubectl.

Resilience

Choose cluster mode, node strategy, scaling and database availability to match the workload.

03Azure · CI/CD · Identity

Azure Container Apps with OIDC CI/CD

Reference deployment flow using GitHub Actions, federated identity, Azure Container Registry and Azure Container Apps.

Azure Container AppsGitHub ActionsOIDCACRAzure Database for PostgreSQLAzure Monitor
View architecture notes
Authentication

Federate GitHub Actions identity to Microsoft Entra ID and avoid storing long-lived deployment secrets.

Deployment

Build and publish a container image, then update the Container App revision.

Operations

Use health probes, scaling rules, logs and alerts.

04Azure · Cloud Architecture

Azure Container Apps Architecture

Manually provisioned reference design for container hosting, custom-domain routing, scaling and a managed PostgreSQL data layer.

Azure Container AppsVirtual NetworkAzure Load BalancerAzure DNSAzure Database for PostgreSQLKey Vault
View architecture notes
Network

Validate the exact ingress and virtual-network integration capabilities for the selected Azure Container Apps environment.

Data

Keep database access private where supported and apply managed database backup and availability options.

Secrets

Use managed identity and Key Vault for application secrets where appropriate.

05AWS · Data Engineering

AWS Glue ETL with CloudFormation

Reference ETL workflow with Bitbucket OIDC, CloudFormation-managed resources, scheduled Glue jobs and Secrets Manager.

AWS GlueCloudFormationBitbucket PipelinesOIDCS3Secrets ManagerCloudWatch
View architecture notes
Provisioning

Define Glue jobs, execution roles, schedules and supporting resources as infrastructure as code.

Credentials

Retrieve database credentials at runtime from Secrets Manager with least-privilege access.

Operations

Monitor job status, duration, failures and output quality.

06AWS · Terraform · Containers

Amazon ECS Fargate Infrastructure

Reference design for multi-AZ container services with Terraform, Bitbucket OIDC, ALB routing and managed data services.

Amazon ECS FargateTerraformBitbucket OIDCALBElastiCacheAmazon RDSAWS Backup
View architecture notes
Infrastructure

Provision networking, load balancing, service/task configuration and supporting services using Terraform.

Pipeline

Validate and plan infrastructure changes before applying with short-lived federated credentials.

Reliability

Configure health checks, scaling, backups and observability according to service requirements.

07DevSecOps · CI/CD

CI/CD Pipeline with Security Gates

Reference delivery pipeline that combines code-quality checks, container security and secret detection before deployment.

Bitbucket PipelinesOIDCSonarQubeAqua TrivyGitleaksDockerAmazon ECRAmazon ECS
View architecture notes
Quality

Run tests and code-quality checks before building a release artifact.

Security

Scan dependencies and images and detect accidentally committed secrets; define clear failure thresholds.

Deployment

Publish versioned images and deploy through a least-privilege OIDC role.

08AWS · Reliability · Operations

Production-Ready AWS Web Architecture

Reference multi-AZ web platform showing edge protection, load balancing, private application and data tiers, monitoring and recovery.

CloudflareCloudFrontALBEC2 Auto ScalingRDSS3CloudWatchAWS Backup
View architecture notes
Traffic flow

Separate edge/CDN responsibilities from application ingress and backend services.

Resilience

Use health checks, multi-AZ placement and tested backup/recovery procedures.

Operations

Centralize metrics, logs, alerting and incident-response integrations.

09AWS · Terraform · IaC

AWS EC2 Auto Scaling with Terraform

Reference infrastructure-as-code pipeline for a multi-AZ EC2 Auto Scaling application tier with remote state and managed backend services.

TerraformBitbucket PipelinesOIDCVPCALBEC2 Auto ScalingS3 StateCloudWatch
View architecture notes
IaC workflow

Format, validate, review a plan and apply reviewed changes through CI/CD.

State

Use a protected, versioned remote state location and separate environments appropriately.

Access

Use least-privilege deployment roles and avoid long-lived AWS keys in pipeline variables.

HAVE A SIMILAR CHALLENGE?

Let's design a solution around your requirements.

Share your cloud, delivery or operations challenge and we can discuss scope and next steps.

Discuss your project →