Skip to content
Cloud architecture templates

Hybrid — On-Premises to Cloud Over a VPN

A migration-shaped diagram: a mainframe and a file server still on-premises, a VPN into the cloud, and a third-party payment provider outside both. Reports clean. It is the clearest demonstration of what the boundary check is for — every edge that leaves one network for another names the gateway it goes through.

Template previewCloud architecture
Hybrid platform during migrationAn AWS architecture diagram: 11 resources in 11 scopes (1 network, 3 availability zones), joined by 10 connections. Categories drawn: Compute, Containers, Storage, Databases, Networking, Clients, External systems. No error or warning across 11 resources and 10 edges, every line read; 1 ran only in part — so this is a clean result on the part that could be checked, not a clean bill of health.Hybrid platform during migrationAWS · 11 resources · 11 scopes · 1 network · 3 zones · 10 connectionsNo error or warning across 11 resources and 10 edges, every line read; 1 ran only in part — so this is a clean result on the part that could be checked,not a clean bill of health.Internetintern…8AccountProduction8On-premisesFrankfurt data centre8Regioneu-central-18NetworkVPC10.0.0.0/168+Availability zoneeu-central-1a8Availability zoneeu-central-1b8Availability zoneeu-central-…8SubnetApp…10.0.11.…private8+SubnetApp…10.0.12.…private8+SubnetDa…10.0.21.…isolated8+Customers—2+Stripe—2+Load balanceraws2+VPN gatewayaws2+Banking APIaws×22+Banking APIaws×22+Read modelaws2+NAT gatewayaws5+Core banking—2+Document archive—1+Directoryaws2+https 443http 8080http 8080postgres 5432postgres 5432tls 443mq 1414nfs 2049ldap 389https 443 · via natLegendComputeContainersStorageDatabasesNetworkingClientsExternal systemsRequest trafficData movementChecks — what ran, and what could notWhether the internet reaches something that ho…ran over 10 subjects, found nothingWhether anything holding data at rest sits in …ran over 1 subject, 1 gap — a partial passWhether anything claiming redundancy is spread…ran over 2 subjects, found nothingEdges that leave one network for another, or c…ran over 11 subjects, found nothingResources that appear in no edge at all. A leg…ran over 11 subjects, found nothingEvery id an edge or a scope names is one that …ran over 11 subjects, found nothingEach id is declared once. Two declarations mak…ran over 22 subjects, found nothingType words that did not resolve. A hole in thi…ran over 11 subjects, found nothingDeclared ranges: that each parses, sits inside…ran over 4 subjects, found nothingWhether every line was read and no shape cap b…ran over 22 subjects, found nothingFindings1`files` holds data at rest and sits inside no subnet at all, so nothing in this document says whether it is publicly routable and this check had nothing to read.in the figure: files2The walk reached 10 resources from the internet; every one of the 2 that hold data at rest — `cache-db` and `files` — sits behind an ingress.in the figure: customers, stripe, lb, api-a, api-b +5 more3The one datastore this check could read — `cache-db` — sits in a subnet declared private or isolated.in the figure: cache-db (badge 2)42 resources were read against the 3 declared zones: every redundancy claim and every multi-member tier among them spans more than one zone.in the figure: api-a (badge 2), api-b (badge 2)5Every edge this check could read stays inside one network, stays outside all of them, or names a gateway to cross at; 11 endpoints were read across 1 declared network.in the figure: customers (badge 2), lb (badge 2), api-a (badge 2), api-b (badge 2), cache-db (badge 2) +6 more6All 11 declared resources appear in at least one edge.in the figure: customers (badge 2), stripe (badge 2), core (badge 2), files (badge 1), dirsrv (badge 2) +6 more7All 11 ids named by edges and scopes were declared somewhere in this document.in the figure: customers (badge 2), lb (badge 2), api-a (badge 2), api-b (badge 2), cache-db (badge 2) +6 more8All 22 declared ids are distinct.in the figure: internet, dc, prod, eu-central-1, vpc +17 more9All 11 resources resolved to a type this engine knows, so every check above had the full vocabulary to read.in the figure: customers (badge 2), stripe (badge 2), core (badge 2), files (badge 1), dirsrv (badge 2) +6 more10All 4 declared ranges parse, each of the 3 drawn inside an addressed network sits inside it, and no two ranges under one parent share an address. The 3 subnets thathave instances drawn in them hold them. Ranges under different parents were not compared — two networks numbered alike is ordinary and correct.in the figure: vpc (badge 8), app-a (badge 8), app-b (badge 8), data (badge 8)11Every line was read and no shape cap bit: the 22 declarations above are the whole document, so the counts are totals rather than floors.

Make it your own.

title "Hybrid platform during migration"
provider aws

internet {
  user customers "Customers"
  payment-provider stripe "Stripe"
}

onprem dc "Frankfurt data centre" {
  mainframe core "Core banking"
  file-store files "Document archive"
  server dirsrv "Directory"
}

cloud prod "Production" {
  region eu-central-1 {
    network vpc "VPC" cidr 10.0.0.0/16 {
      alb lb "Load balancer"
      vpn-gateway vpn "VPN gateway"

      zone eu-central-1a {
        subnet app-a "App A" private cidr 10.0.11.0/24 {
          ecs api-a "Banking API" count 2 tier api
        }
      }
      zone eu-central-1b {
        subnet app-b "App B" private cidr 10.0.12.0/24 {
          ecs api-b "Banking API" count 2 tier api
        }
      }
      zone eu-central-1c {
        subnet data "Data" isolated cidr 10.0.21.0/24 {
          rds cache-db "Read model"
        }
      }
      nat nat "NAT gateway"
    }
  }
}

customers -> lb : https 443
lb -> api-a : http 8080
lb -> api-b : http 8080
api-a -> cache-db : postgres 5432
api-b -> cache-db : postgres 5432
api-a -> vpn : tls 443
vpn -> core : mq 1414
core => files : nfs 2049
core -> dirsrv : ldap 389
api-a -> stripe : https 443 via nat