This repository provisions a high-availability AWS infrastructure foundation for web applications using Terraform. The stack is organized into reusable modules for networking, compute, database, caching, CDN, DNS, and observability, and it is deployed across separate environment workspaces for staging and production.
The project is designed around a multi-region, layered architecture:
- Networking: VPCs, public/private subnets, internet gateways, NAT gateways, and security groups
- Compute: Application load balancers, target groups, launch templates, and autoscaling groups
- Data: PostgreSQL RDS instances with optional read replicas
- Caching: ElastiCache for Redis
- Edge delivery: CloudFront, WAF, ACM, and Route 53
- Monitoring: CloudWatch log groups and dashboards
- Shared state bootstrap: S3 bucket and DynamoDB lock table for Terraform state management
- environments/prod - Production deployment configuration
- environments/staging - Staging deployment configuration
- global - Shared bootstrap resources for Terraform state
- modules - Reusable infrastructure modules
- .github/workflows - CI/CD workflow placeholders
- modules/networking/Documentation.md
- modules/compute/Documentation.md
- modules/database/Documentation.md
- modules/cache/Documentation.md
- modules/cdn/Documentation.md
- modules/dns/Documentation.md
- modules/observability/Documentation.md
- environments/staging/Documentation.md
- environments/prod/Documentation.md
Before deploying, ensure you have:
- An AWS account with permissions to create VPCs, EC2, ALB, RDS, ElastiCache, CloudFront, WAF, ACM, Route 53, CloudWatch, S3, DynamoDB, and IAM policies
- Terraform installed locally
- AWS CLI configured with appropriate credentials
- A Route 53 hosted zone and domain name for production CDN/DNS integration
The shared bootstrap resources are defined in global/bootstrap.tf and global/iam_ci.tf.
Run the following from the repository root:
cd global
terraform init
terraform applyThis creates:
- An S3 bucket for storing Terraform state
- A DynamoDB table for state locking
- An IAM policy document for Terraform state access
The staging environment deploys the base HA stack in the us-east-1 region.
cd environments/staging
terraform init -backend-config=backend.hcl
terraform plan -var-file=terraform.tfvars
terraform apply -var-file=terraform.tfvarsThe production environment deploys a multi-region setup across us-east-1 and us-west-2 and includes CDN and DNS resources.
cd environments/prod
terraform init -backend-config=backend.hcl
terraform plan -var-file=terraform.tfvars
terraform apply -var-file=terraform.tfvars- The current configuration uses Terraform variables in each environment's tfvars file.
- Database credentials are provided as plain variables in the example configuration; for real deployments, use AWS Secrets Manager or another secret management solution.
- The production environment uses placeholder values for the domain name and hosted zone ID in environments/prod/terraform.tfvars.
- The compute module uses a simple Nginx-based user data script for initial application hosting.
After deployment, Terraform outputs include:
- VPC and subnet IDs
- Application load balancer DNS names
- Auto Scaling Group names
- Database endpoint and port
- CloudFront distribution details
- Security groups restrict traffic to application and database tiers.
- RDS instances are deployed with encryption enabled.
- CloudFront uses WAF managed rules for common protections.
- State is managed remotely via S3 and DynamoDB.
- The project is a solid baseline for a demo or MVP, but production hardening should include secrets management, stricter IAM boundaries, and more comprehensive monitoring.
- Replace placeholder domain values with real production values.
- Add CI/CD pipelines for plan and apply workflow enforcement.
- Extend the compute module to deploy your application stack instead of the placeholder Nginx bootstrap.
- Add additional environment-specific policies and tagging standards.