Route53 DNS
interpres.io (Public Hosted Zone)
*.in.interpres.io → ACM Wildcard Cert
WAF
Rules: Geo-block, Rate Limit, Bot Detection
Logs → CloudWatch (30-day retention)
Region: ap-south-1
10.90.1.0/24
10.90.2.0/24
SSL Termination
10.90.11.0/24
10.90.12.0/24
(in-prod)
Node Group: m5.2xlarge (2-6 nodes)
Microservices:
• api-service
• app-service
• auth-service
• pipeline-*
• ai-chat
• secret-service
• worker-service
Add-ons:
• ALB Controller
• External-DNS
• Cluster Auto.
• Prometheus
• Grafana
• Velero (opt)
• Vault (HA)
10.90.21.0/24
10.90.22.0/24
PostgreSQL 14.17
db.r5.2xlarge
db.t3.medium
EXTERNAL SERVICES
• prd-in-app-data
• prd-in-doc-files
• prd-in-media
• prd-in-backup
• prd-in-velero
• EKS encryption
• RDS encryption
• S3 encryption
• Vault unseal
• DB passwords
• Service creds
• API tokens
• Logs
• Metrics
• Alarms
• Security Groups
• NACLs (DB subnets)
• VPC Flow Logs
• Private subnets
• KMS encryption
• SSL/TLS everywhere
• Certificate Manager
• IRSA roles
• K8s RBAC
• IAM policies
• Service accounts
by subh