Network Diagram

Notation Meaning
Stadium External actor (users / staff)
Rectangle Cloudflare endpoint group
Framed box Gateway / load balancer
Rounded box Service / compute / API
Cylinder Data store
Violet, heavy border Customer / sensitive data store
Arrow Direction of data flow / connection
flowchart TB
  classDef untrusted fill:#eef1f4,stroke:#64748b,stroke-width:1.5px,color:#2b3542;
  classDef edge fill:#fde7da,stroke:#eb6834,stroke-width:1.5px,color:#7a3313;
  classDef compute fill:#ddf2e0,stroke:#1e8a3f,stroke-width:1.5px,color:#145a24;
  classDef netpub fill:#fbefcf,stroke:#c98a08,stroke-width:1.5px,color:#6b4c07;
  classDef data fill:#e8e4f5,stroke:#4a3aa7,stroke-width:2.5px,color:#2c2470;
  classDef jr fill:#d7f0e6,stroke:#14926a,stroke-width:1.5px,color:#0d5f45;
  classDef saas fill:#fbe4ee,stroke:#cf477d,stroke-width:1.5px,color:#7d2a4b;

  public(["Public Users"]):::untrusted
  staff(["JetRails Staff"]):::untrusted

  subgraph CF["Cloudflare · WAF, DDoS, CDN, DNS"]
    cfpub["Public Endpoints"]:::edge
    cfpriv["Private Endpoints"]:::edge
    cfdevops["DevOps Endpoints"]:::edge
  end

  subgraph AWS["AWS Production AutoPilot Account · us-east-1 · VPC 10.0.0.0/16"]
    direction TB

    subgraph DMZ["Public Subnets · 10.0.0.0/24, 10.0.1.0/24, 10.0.2.0/24"]
      elb[["Load Balancer<br/>SG: Cloudflare Prefix List"]]:::edge
      nat[["NAT Gateways (One per AZ)<br/>Outbound Egress · Static EIPs"]]:::netpub
      rds[("RDS Aurora MySQL · Publicly Accessible (SG-Restricted) · Encrypted")]:::data
    end

    subgraph PRIV["Private Subnets (Trusted) · 10.0.3.0/24, 10.0.4.0/24, 10.0.5.0/24"]
      eks("EKS Worker Nodes<br/>NetworkPolicy Segmentation"):::compute
      efs[("EFS Storage · Encrypted")]:::data
    end

    cp("EKS Control Plane<br/>Secrets KMS-Encrypted"):::compute
  end

  subgraph SAAS["3rd-Party APIs"]
    awsapi("AWS API"):::saas
    google("Google API"):::saas
    github("GitHub API"):::saas
    authnet("Authorize.Net API"):::saas
    slack("Slack Webhook"):::saas
    whmcs("WHMCS API"):::saas
  end

  subgraph JR["JetRails DevOps Network · DigitalOcean"]
    vault[("HashiCorp Vault")]:::jr
    registry[("Container Registry")]:::jr
    drone("Drone CI/CD"):::jr
  end

  cfdevops --> drone
  cfdevops --> registry
  cfdevops --> vault
  public -->|"Public HTTPS"| cfpub
  staff -->|"JetRails VPN Whitelisted · HTTPS"| cfpub
  staff -->|"JetRails VPN Whitelisted · HTTPS"| cfpriv
  staff -->|"JetRails VPN Whitelisted · HTTPS"| cfdevops
  staff -->|"JetRails VPN Whitelisted · EKS API"| cp
  staff -->|"JetRails VPN Whitelisted · MySQL"| rds
  drone -->|"KUBE API Whitelisted"| cp
  cfpub -->|"HTTPS"| elb
  cfpriv -->|"HTTPS"| elb
  elb -->|"Ingress · Cloudflare Origin-Pull mTLS"| eks
  cp --> eks
  eks -->|"MySQL"| rds
  eks --> efs
  eks -->|"Egress"| nat
  nat -->|"HTTPS"| SAAS
  nat -->|"NAT EIPs Whitelisted"| cfdevops