Skip to content
Cloud architecture templates

Provider-Agnostic — One Architecture, No Vendor Names

The same shape written entirely in the generic vocabulary, which is what a design document wants before the cloud has been chosen and what a comparison across two clouds needs. Reports clean. Categories still colour the boxes, so the figure reads by function rather than by vendor — which is the question anyone looking at it is trying to answer.

Template previewCloud architecture
Reference architecture — provider independentA Generic architecture diagram: 14 resources in 10 scopes (1 network, 2 availability zones), joined by 18 connections. Categories drawn: Containers, Storage, Databases, Edge & delivery, Security, Integration, Observability, Clients, External systems. No error or warning across 14 resources and 18 edges, every line read; 2 ran only in part — so this is a clean result on the part that could be checked, not a clean bill of health.Reference architecture — provider independentGeneric · 14 resources · 10 scopes · 1 network · 2 zones · 18 connectionsNo error or warning across 14 resources and 18 edges, every line read; 2 ran only in part — so this is a clean result on the part that could be checked,not a clean bill of health.Internetinternet9AccountPlatfo…9RegionPrimary region9NetworkPlatform network10.0.0.0/169+Availability zoneZone…9Availability zoneZone B9SubnetApplica…private9+SubnetDa…isolated9+SubnetApplica…private9+SubnetDa…isolated9+Web client—3+Mobile app—3+Partner API—3+Edge cache—2+Web applicationfirewall—2+API gateway—3+Applicationservice—×33+Primary database—HA3+Applicationservice—×33+Standby database—HA4+Objectstorage—1+Work queue—1+Secret store—1+Monitoring—2+https 443https 443https 443https 443https 443http 8080http 8080sql 5432sql 5432replicationobject apibackground workbackground worksecret readsecret readLegendContainersStorageDatabasesEdge & deliverySecurityIntegrationObservabilityClientsExternal systemsRequest trafficData movementReplicationAsynchronousDepends onChecks — what ran, and what could notWhether the internet reaches something that ho…ran over 11 subjects, found nothingWhether anything holding data at rest sits in …ran over 2 subjects, 1 gap — a partial passWhether anything claiming redundancy is spread…ran over 4 subjects, found nothingEdges that leave one network for another, or c…ran over 6 subjects, 1 gap — a partial passResources that appear in no edge at all. A leg…ran over 14 subjects, found nothingEvery id an edge or a scope names is one that …ran over 14 subjects, found nothingEach id is declared once. Two declarations mak…ran over 24 subjects, found nothingType words that did not resolve. A hole in thi…ran over 14 subjects, found nothingDeclared ranges: that each parses, sits inside…ran over 5 subjects, found nothingWhether every line was read and no shape cap b…ran over 24 subjects, found nothingFindings1`blobs`, `jobs` and `vault` hold data at rest and sit inside no subnet at all, so nothing in this document says whether they are publicly routable and this check hadnothing to read.in the figure: blobs, jobs, vault2`waf`, `edge`, `blobs`, `jobs`, `vault` and 1 more are joined to something inside a network but sit in no network, internet or on-premises scope of their own, sowhether those edges cross a boundary COULD NOT BE DECIDED.in the figure: waf, edge, blobs (badge 1), jobs (badge 1), vault (badge 1) +1 more3The walk reached 11 resources from the internet; every one of the 3 that hold data at rest — `db-a`, `blobs` and `vault` — sits behind an ingress.in the figure: web-client, mobile, partner, waf (badge 2), gw +6 more4Every one of the 2 datastores this check could read — `db-a` and `db-b` — sits in a subnet declared private or isolated.in the figure: db-a (badge 3), db-b52 resources claim redundancy from inside one zone and are drawn with a replicated peer in another — `db-a` and `db-b` — so the picture supports the claim.in the figure: db-a (badge 3), db-b (badge 4)6Every edge this check could read stays inside one network, stays outside all of them, or names a gateway to cross at; 6 endpoints were read across 1 declared network.in the figure: partner (badge 3), gw (badge 3), svc-a (badge 3), svc-b (badge 3), db-a (badge 3) +1 more7All 14 declared resources appear in at least one edge.in the figure: web-client (badge 3), mobile (badge 3), partner (badge 3), edge (badge 2), waf (badge 2) +9 more8All 14 ids named by edges and scopes were declared somewhere in this document.in the figure: web-client (badge 3), waf (badge 2), mobile (badge 3), partner (badge 3), gw (badge 3) +9 more9All 24 declared ids are distinct.in the figure: internet, platform, primary, net, zone-a +19 more10All 14 resources resolved to a type this engine knows, so every check above had the full vocabulary to read.in the figure: web-client (badge 3), mobile (badge 3), partner (badge 3), edge (badge 2), waf (badge 2) +9 more11The one declared range parses, it is not drawn inside another addressed network, so there was no containment to test, and no two ranges under one parent share anaddress. 4 further containers declare no range at all, so nothing about their addressing is claimed here either way. Ranges under different parents were not compared —two networks numbered alike is ordinary and correct.in the figure: net (badge 9), app-a (badge 9), data-a (badge 9), app-b (badge 9), data-b (badge 9)12Every line was read and no shape cap bit: the 24 declarations above are the whole document, so the counts are totals rather than floors.

Make it your own.

title "Reference architecture — provider independent"
provider generic

internet {
  browser web-client "Web client"
  mobile-app mobile "Mobile app"
  third-party-api partner "Partner API"
}

cloud platform "Platform" {
  region primary "Primary region" {
    cdn edge "Edge cache"
    waf waf "Web application firewall"

    network net "Platform network" cidr 10.0.0.0/16 {
      api-gateway gw "API gateway"

      zone zone-a "Zone A" {
      subnet app-a "Application A" private {
        container svc-a "Application service" count 3 tier app
      }
      subnet data-a "Data A" isolated {
        sql-database db-a "Primary database" ha
      }
    }

    zone zone-b "Zone B" {
      subnet app-b "Application B" private {
        container svc-b "Application service" count 3 tier app
      }
      subnet data-b "Data B" isolated {
        sql-database db-b "Standby database" ha
      }
    }

    }

    object-store blobs "Object storage"
    queue jobs "Work queue"
    secret-store vault "Secret store"
    monitoring obs "Monitoring"
  }
}

web-client -> waf : https 443
mobile -> waf : https 443
partner -> gw : https 443
waf -> edge : https 443
edge -> gw : https 443
gw -> svc-a : http 8080
gw -> svc-b : http 8080
svc-a -> db-a : sql 5432
svc-b -> db-a : sql 5432
db-a <=> db-b : replication
svc-a => blobs : object api
svc-a ~> jobs : background work
svc-b ~> jobs : background work
svc-a -> vault : secret read
svc-b -> vault : secret read
obs ..> svc-a
obs ..> svc-b
obs ..> db-a