
☁️ SaaS & Cloud · Deployment · Pro
A serverless backend on AWS: API Gateway, Lambda functions, DynamoDB, S3 events and Cognito for sign-in, with no servers to manage.
Deployment diagrams are part of Pro. Anyone can view this one; generating and editing it needs Pro.
Drawing diagram…
Serverless deployment on AWS: a single-page app on S3 and CloudFront signs users in with Amazon Cognito, calls API Gateway with a JWT, API Gateway routes to Lambda functions (orders, profile, uploads) that read and write DynamoDB. File uploads go to S3 via presigned URLs, and S3 events trigger a Lambda that processes images and publishes to SNS/SQS for notifications. Secrets in Secrets Manager, logs and traces in CloudWatch and X-Ray.
flowchart TB
U[Users] --> CF[CloudFront]
CF --> SPA[(S3 - single-page app)]
U --> COG[Amazon Cognito - sign-in]
U -->|JWT| APIGW[API Gateway]
subgraph Lambdas[Lambda functions]
L1[orders]
L2[profile]
L3[upload-url]
L4[process-image]
end
APIGW --> L1
APIGW --> L2
APIGW --> L3
L1 --> DDB[(DynamoDB)]
L2 --> DDB
L3 -->|Presigned URL| U
U -->|Upload| S3[(S3 uploads)]
S3 -->|Object created event| L4
L4 --> SNS[SNS / SQS notifications]
L1 -.logs, traces.-> CW[CloudWatch and X-Ray]How a microservices app runs on Kubernetes in the cloud: ingress, namespaces, services with multiple replicas, managed databases and monitoring.
A typical CI/CD pipeline from a pull request to production: build, tests, security scans, staging deploy, approval and a canary release.
The authorization code flow with PKCE used by most modern web and mobile apps to log users in through an identity provider.
A B2B SaaS product serving many customer organisations from one platform: tenant-aware services, per-tenant data isolation, billing and admin.
The classic three-tier web app on AWS: CloudFront and a load balancer, an autoscaling app tier in private subnets, and a Multi-AZ database.
Services that talk through events instead of direct calls: an order service publishes events that inventory, payments, notifications and analytics react to.