Hybrid — On-Premises to Cloud Over a VPN
A migration-shaped diagram: a mainframe and a file server still on-premises, a VPN into the cloud, and a third-party payment provider outside both. Reports clean. It is the clearest demonstration of what the boundary check is for — every edge that leaves one network for another names the gateway it goes through.
Make it your own.
title "Hybrid platform during migration"
provider aws
internet {
user customers "Customers"
payment-provider stripe "Stripe"
}
onprem dc "Frankfurt data centre" {
mainframe core "Core banking"
file-store files "Document archive"
server dirsrv "Directory"
}
cloud prod "Production" {
region eu-central-1 {
network vpc "VPC" cidr 10.0.0.0/16 {
alb lb "Load balancer"
vpn-gateway vpn "VPN gateway"
zone eu-central-1a {
subnet app-a "App A" private cidr 10.0.11.0/24 {
ecs api-a "Banking API" count 2 tier api
}
}
zone eu-central-1b {
subnet app-b "App B" private cidr 10.0.12.0/24 {
ecs api-b "Banking API" count 2 tier api
}
}
zone eu-central-1c {
subnet data "Data" isolated cidr 10.0.21.0/24 {
rds cache-db "Read model"
}
}
nat nat "NAT gateway"
}
}
}
customers -> lb : https 443
lb -> api-a : http 8080
lb -> api-b : http 8080
api-a -> cache-db : postgres 5432
api-b -> cache-db : postgres 5432
api-a -> vpn : tls 443
vpn -> core : mq 1414
core => files : nfs 2049
core -> dirsrv : ldap 389
api-a -> stripe : https 443 via nat