> For the complete documentation index, see [llms.txt](https://flapjax.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://flapjax.gitbook.io/docs/hosting/architecture/provisioned-infrastructure.md).

# Provisioned Infrastructure

This document describes the full set of infrastructure components that Flapjax provisions in both hosting models (Option A: Flapjax-Hosted, Option B: Client-Hosted). These components form the complete production-ready environment required for a Flapjax application deployment.

***

### 1. Virtual Private Cloud (VPC)

A dedicated, isolated network environment containing all application and database resources.

#### **Included Components:**

* Dedicated VPC
* Public subnets (for ingress/load balancers)
* Private subnets (for application workloads)
* Database subnets (for RDS and other data services)
* Route tables and subnet associations
* Internet Gateway (IGW)
* NAT Gateway for secure outbound traffic from private subnets

***

### 2. NAT Gateway

Provides controlled, secure outbound connectivity to the internet for private workloads (e.g., EKS nodes pulling container images).

***

### 3. Kubernetes Cluster (EKS)

A fully managed Kubernetes control plane.

#### **Capabilities Provided:**

* Auto-scaling node groups
* Observability (logging, metrics, events)
* Secure networking & pod isolation
* Highly available control plane managed by AWS

***

### 4. EKS Node Groups

Worker nodes that run application workloads.

#### **Key Features:**

* Mix of Spot and On-Demand instances for cost optimisation
* Autoscaling groups with desired/min/max settings
* IAM roles scoped for cluster operations

***

### 5. IAM Roles & Permissions

Least-privilege IAM roles required for:

* EKS cluster operations
* Node groups
* Database access
* Secrets management
* Logging and monitoring

IAM boundaries are applied to ensure isolation and secure operation.

***

### 6. ElastiCache (Redis)

High-performance caching layer used for:

* Session storage
* Rate limiting
* In-memory caching
* Queueing or lightweight message passing (where applicable)

Provisioned in private subnets with restricted access.

***

### 7. Relational Database (Aurora RDS)

Primary relational database backend.

#### **Configured With:**

* Multi-AZ failover (where required)
* Automated backups
* Parameter groups tuned for Flapjax workloads
* Encrypted storage and connections

***

### 8. MongoDB

Document/event database for workloads requiring flexible schemas.

#### **Deployment Options:**

* MongoDB Atlas (via PrivateLink)
* Self-managed inside VPC (optional)

***

### 9. Load Balancers & Ingress

Used for routing public and internal Traffic.

#### **Included Components:**

* Application Load Balancer (ALB)
* Ingress controllers for Kubernetes services
* Health checks and path-based routing

***

### Summary

These components collectively provide a secure, scalable, production-ready hosting environment. They ensure reliability, observability, performance, and security across all Flapjax deployments, regardless of hosting option.
