CloudSketch AI Logo
FeaturesTemplatesPricingEnterpriseAboutContactLog in
🌙☀️
Log inStart free
Home/Templates/SaaS & Cloud

☁️ SaaS & Cloud · Deployment · Pro

AWS Three-Tier Web Application

The classic three-tier web app on AWS: CloudFront and a load balancer, an autoscaling app tier in private subnets, and a Multi-AZ database.

More SaaS & Cloud templates

Deployment diagrams are part of Pro. Anyone can view this one; generating and editing it needs Pro.

Drawing diagram…

What this diagram shows

  • Public subnets hold only the load balancer and NAT
  • App servers run in private subnets across two availability zones
  • The database is Multi-AZ with automated backups

Prompt used

Deployment of a three-tier web app on AWS in one region with two availability zones: users reach CloudFront and AWS WAF, then an Application Load Balancer in public subnets. The app tier is an EC2 Auto Scaling group in private subnets across both AZs. The data tier is Amazon RDS PostgreSQL Multi-AZ plus ElastiCache Redis in isolated subnets. Static files are in S3, NAT gateways give outbound access, and CloudWatch monitors everything.

Mermaid code
flowchart TB
  U[Users] --> CF[CloudFront + WAF]
  CF --> S3[(S3 - static files)]
  subgraph VPC[VPC - ap-south-1]
    subgraph PUB[Public subnets]
      ALB[Application Load Balancer]
      NAT[NAT Gateways]
    end
    subgraph APP[Private app subnets - AZ a and b]
      EC2A[App server AZ-a]
      EC2B[App server AZ-b]
    end
    subgraph DATA[Isolated data subnets]
      RDS[(RDS PostgreSQL Multi-AZ)]
      REDIS[(ElastiCache Redis)]
    end
  end
  CW[CloudWatch]
  CF --> ALB
  ALB --> EC2A
  ALB --> EC2B
  EC2A --> RDS
  EC2B --> RDS
  EC2A --> REDIS
  EC2B --> REDIS
  EC2A --> NAT
  EC2A -.metrics.-> CW

Related templates

DeploymentProSaaS & Cloud

Kubernetes Microservices Deployment

How a microservices app runs on Kubernetes in the cloud: ingress, namespaces, services with multiple replicas, managed databases and monitoring.

FlowchartSaaS & Cloud

CI/CD Pipeline Flowchart

A typical CI/CD pipeline from a pull request to production: build, tests, security scans, staging deploy, approval and a canary release.

SequenceSaaS & Cloud

OAuth 2.0 / OpenID Connect Login

The authorization code flow with PKCE used by most modern web and mobile apps to log users in through an identity provider.

C4 ArchitectureProSaaS & Cloud

Multi-Tenant SaaS Architecture

A B2B SaaS product serving many customer organisations from one platform: tenant-aware services, per-tenant data isolation, billing and admin.

C4 ArchitectureProSaaS & Cloud

Event-Driven Architecture with Kafka

Services that talk through events instead of direct calls: an order service publishes events that inventory, payments, notifications and analytics react to.

State MachineSaaS & Cloud

SaaS Subscription Billing Lifecycle

The states of a SaaS customer's subscription: trial, active, past due with retries, paused, cancelled and expired.