Provider-Agnostic — One Architecture, No Vendor Names
The same shape written entirely in the generic vocabulary, which is what a design document wants before the cloud has been chosen and what a comparison across two clouds needs. Reports clean. Categories still colour the boxes, so the figure reads by function rather than by vendor — which is the question anyone looking at it is trying to answer.
Make it your own.
title "Reference architecture — provider independent"
provider generic
internet {
browser web-client "Web client"
mobile-app mobile "Mobile app"
third-party-api partner "Partner API"
}
cloud platform "Platform" {
region primary "Primary region" {
cdn edge "Edge cache"
waf waf "Web application firewall"
network net "Platform network" cidr 10.0.0.0/16 {
api-gateway gw "API gateway"
zone zone-a "Zone A" {
subnet app-a "Application A" private {
container svc-a "Application service" count 3 tier app
}
subnet data-a "Data A" isolated {
sql-database db-a "Primary database" ha
}
}
zone zone-b "Zone B" {
subnet app-b "Application B" private {
container svc-b "Application service" count 3 tier app
}
subnet data-b "Data B" isolated {
sql-database db-b "Standby database" ha
}
}
}
object-store blobs "Object storage"
queue jobs "Work queue"
secret-store vault "Secret store"
monitoring obs "Monitoring"
}
}
web-client -> waf : https 443
mobile -> waf : https 443
partner -> gw : https 443
waf -> edge : https 443
edge -> gw : https 443
gw -> svc-a : http 8080
gw -> svc-b : http 8080
svc-a -> db-a : sql 5432
svc-b -> db-a : sql 5432
db-a <=> db-b : replication
svc-a => blobs : object api
svc-a ~> jobs : background work
svc-b ~> jobs : background work
svc-a -> vault : secret read
svc-b -> vault : secret read
obs ..> svc-a
obs ..> svc-b
obs ..> db-a