Skip to content
Cloud architecture templates

AWS — Serverless API, Edge to Table

A serverless request path with no servers in it: CDN, API gateway, functions, a document store and an object store, with a queue for the asynchronous half. Reports clean — and shows the async edge style, which is drawn differently from request traffic because a queue between two services is a different claim from a call.

Template previewCloud architecture
Serverless order APIAn AWS architecture diagram: 10 resources in 3 scopes (0 networks, 0 availability zones), joined by 10 connections. Categories drawn: Serverless, Storage, Databases, Edge & delivery, Security, Identity, Integration, Clients. No error or warning across 10 resources and 10 edges, every line read; 4 of the 10 checks could not run at all — so this is a clean result on the part that could be checked, not a clean bill of health.Serverless order APIAWS · 10 resources · 3 scopes · 0 networks · 0 zones · 10 connectionsNo error or warning across 10 resources and 10 edges, every line read; 4 of the 10 checks could not run at all — so this is a clean result on the partthat could be checked, not a clean bill of health.Internetintern…8AccountProduction8Regionus-east…8Shoppers—5+Contentdeliveryaws5+Order APIaws5+Create orderaws5+Fulfil orderaws6+Order queueaws1+Orders tableaws1+Receiptsaws1+User poolaws5+Paymentcredentialsaws1+https 443https 443oidcinvokeputitemorder placedorder placedupdateitemput objectgetsecretLegendServerlessStorageDatabasesEdge & deliverySecurityIdentityIntegrationClientsRequest trafficData movementAsynchronousChecks — what ran, and what could notWhether the internet reaches something that ho…ran over 6 subjects, found nothingWhether anything holding data at rest sits in …could not run here — 1 reason givenWhether anything claiming redundancy is spread…could not run here — 1 reason givenEdges that leave one network for another, or c…could not run here — 1 reason givenResources that appear in no edge at all. A leg…ran over 10 subjects, found nothingEvery id an edge or a scope names is one that …ran over 10 subjects, found nothingEach id is declared once. Two declarations mak…ran over 13 subjects, found nothingType words that did not resolve. A hole in thi…ran over 10 subjects, found nothingDeclared ranges: that each parses, sits inside…could not run here — 1 reason givenWhether every line was read and no shape cap b…ran over 13 subjects, found nothingFindings1`queue`, `orders`, `receipts` and `creds` hold data at rest and sit inside no subnet at all, so nothing in this document says whether they are publicly routable andthis check had nothing to read.in the figure: queue, orders, receipts, creds2This document declares no availability zone, so the redundancy check DID NOT RUN AT ALL: nothing here claims redundancy either, so nothing was missed. Declare thezones (`zone az-a`, `zone az-b`) and put the resources inside them, and the claim becomes checkable.3This document declares no `network` scope, so there is no boundary for an edge to cross and this check DID NOT RUN over any of its 10 edges. Nothing here says thetraffic stays inside one network.4No network or subnet was declared, so there was no addressing to check.5The walk reached 6 resources from the internet; the one that holds data at rest — `orders` — sits behind an ingress.in the figure: shoppers, cdn, api, auth, create +1 more6All 10 declared resources appear in at least one edge.in the figure: shoppers (badge 5), cdn (badge 5), api (badge 5), create (badge 5), fulfil +5 more7All 10 ids named by edges and scopes were declared somewhere in this document.in the figure: shoppers (badge 5), cdn (badge 5), api (badge 5), auth (badge 5), create (badge 5) +5 more8All 13 declared ids are distinct.in the figure: internet, prod, us-east-1, shoppers (badge 5), cdn (badge 5) +8 more9All 10 resources resolved to a type this engine knows, so every check above had the full vocabulary to read.in the figure: shoppers (badge 5), cdn (badge 5), api (badge 5), create (badge 5), fulfil (badge 6) +5 more10Every line was read and no shape cap bit: the 13 declarations above are the whole document, so the counts are totals rather than floors.

Make it your own.

title "Serverless order API"
provider aws

internet {
  user shoppers "Shoppers"
}

cloud prod "Production" {
  region us-east-1 {
    cloudfront cdn "Content delivery"
    api-gateway api "Order API"
    lambda create "Create order"
    lambda fulfil "Fulfil order"
    sqs queue "Order queue"
    dynamodb orders "Orders table"
    s3 receipts "Receipts"
    cognito auth "User pool"
    secrets-manager creds "Payment credentials"
  }
}

shoppers -> cdn : https 443
cdn -> api : https 443
api -> auth : oidc
api -> create : invoke
create -> orders : putitem
create ~> queue : order placed
queue ~> fulfil : order placed
fulfil -> orders : updateitem
fulfil => receipts : put object
fulfil -> creds : getsecret