Cloud architecture
Cloud and platform architecture across AWS, Azure, Google Cloud and Kubernetes — 331 resource types, real containment (account, region, network, zone, subnet, cluster, namespace) and typed edges. Checks the architecture as well as drawing it: a datastore reachable from the internet with no ingress on the path, a datastore in a public subnet, a tier claiming redundancy from inside one zone, an edge crossing a network boundary with no gateway.

In the same space
Most users come to Cloud architecture from Lucidchart (cloud shapes), draw.io (AWS/Azure/GCP stencils), Cloudcraft, diagrams.net or CloudSkew. flowss runs this engine in the browser — no install, shareable via URL, exportable to PNG / SVG / PDF / source.
Syntax at a glance
provider aws
internet {
user customers "Customers"
}
cloud prod "Production" {
region us-east-1 {
network vpc "VPC" {
alb lb "Load balancer"
zone us-east-1a {
subnet app "App" private {
ec2 web "Web server"
}
}
}
}
}
customers -> lb : https 443Paste this in the Studio code pane to see Cloud architecture render live. The full grammar is at the upstream-docs link above.
Sample templates
All 13 →The reference architecture, drawn correctly and reported clean: a public load balancer, application servers in private subnets across two availability zones, and the database isolated with a standby in the other zone. Copy this one. Every check runs and finds nothing, which the engine states rather than implies.
Deliberately wrong, and the drawing of it is indistinguishable from a correct one — which is the point. The database sits in a subnet the document itself declares public, and the traffic path from the internet reaches it without passing through anything that terminates or filters. The engine names both, with the path it walked, so a reader can check the accusation rather than take it.
Three application servers and a database, every one of them marked highly available, all of them inside a single availability zone. The count is the trap: `count 3` looks like redundancy and is not, because three instances in one zone is one zone. The engine says exactly that, in those words.
The most important template in this set, and nothing in it is wrong. It is an ordinary, sensible diagram that declares no availability zones — which is what almost every real cloud diagram looks like. The availability check therefore cannot run at all, and the engine says so plainly instead of reporting a pass. That state is the one most tools never show anyone.
A serverless request path with no servers in it: CDN, API gateway, functions, a document store and an object store, with a queue for the asynchronous half. Reports clean — and shows the async edge style, which is drawn differently from request traffic because a queue between two services is a different claim from a call.
A Kubernetes cluster on GKE with its namespaces drawn as real containers, an ingress terminating outside traffic, and the stateful half deliberately outside the cluster in managed services. Reports clean. The pattern worth copying is that last part: the databases are managed, not StatefulSets, and the diagram makes that visible.
cloudarch · ← Browse all engines · Quick-start guide