Skip to main content

🌐 AWS VPC Architecture for Production EC2 App with CloudFront, WAF, and ALB

This document outlines a production-ready AWS VPC network design for deploying a secure, scalable application backend on EC2 in the ap-south-1 (Mumbai) region. The stack includes:
  • πŸ–₯️ EC2 (Go Application)
  • 🌐 ALB (Application Load Balancer)
  • πŸ” WAF (Web Application Firewall)
  • πŸš€ CloudFront (Edge CDN)
  • πŸŒ‰ NAT Gateways (1 per AZ)
  • πŸ“Ά Public & Private Subnet Segmentation

πŸ“Œ Key Architecture Objectives

  • Multi-AZ fault tolerance
  • Edge security with AWS WAF (via CloudFront)
  • Secure, private EC2 backend
  • Scalable, high-availability NAT
  • Future-ready for RDS/ElastiCache deployments

πŸ“ VPC Design Summary


🧱 Subnet Layout


🧭 Topology Diagram (Simplified)


πŸ” Security Considerations

  • WAF: Deployed on CloudFront for global edge protection
  • SGs: EC2 only accepts traffic from ALB SG
  • Public subnets: Only ALB and NAT Gateways reside here
  • Private subnets: EC2 and future data services (e.g., RDS)
  • No direct internet access to EC2; only via NAT

🚦 Route Tables


🌍 DNS + TLS

  • Route53 record app.example.com β†’ CloudFront distribution
  • ACM certificate in us-east-1 for CloudFront (required)
  • Optional TLS cert in ALB (for origin verification)

πŸ“¦ Optional Modules for Extension

  • πŸ”’ Bastion Host in Public Subnet for SSH (restricted by SG)
  • πŸ›‘ NACLs for enhanced subnet-level filtering
  • πŸ§ͺ Flow Logs for auditing and compliance
  • πŸ“Š CloudWatch + VPC Flow Logs for visibility

βœ… Deployment Notes

  • Terraform modules highly recommended for reproducibility
  • Place EC2 instances in private subnets across all 3 AZs
  • Disable caching in CloudFront if backend is fully dynamic

πŸ“˜ References