Global Access and Security Protection Layer
Users access the platform domain through PCs, Android devices, iOS devices, and other endpoints. Requests are first resolved through Amazon Route 53 DNS and then distributed and accelerated through Amazon CloudFront — static resources are returned from nearby edge locations, while dynamic requests are accelerated back to the AWS application environment. Before traffic enters the VPC, AWS WAF filters web requests to defend against common web attacks, and AWS Shield provides DDoS protection to safeguard the security and availability of public access endpoints.
Application Ingress and Operations Access Layer
Requests processed by the edge layer enter the VPC and are received by ELB instances deployed in public subnets, which distribute them to backend EKS application services — multiple load-balancing entry points improve application availability and traffic-handling capacity. Operations personnel access private-network resources through a Bastion Host, avoiding direct exposure of applications, databases, and analytics components, while GitLab, Jenkins, and Amazon ECR support code management, automated builds, continuous integration, container image storage, and application releases.
Core Business Services Layer
Core business systems run in an Amazon EKS cluster in private subnets, with multiple application services deployed as containers. EKS manages container scheduling, service operations, failure recovery, and elastic scaling, enabling business services to adapt flexibly to changing workloads. Amazon SQS supports asynchronous messaging between applications — background processing, delayed tasks, retrying failed operations, and traffic smoothing during high-concurrency scenarios — reducing coupling between services and improving system stability.
AI Models, Agent Orchestration, and Knowledge Base Layer
Amazon API Gateway, AWS Lambda, and Amazon Bedrock provide a unified entry point for model invocation and governance, centrally managing AI requests, API authorization, routing, and model-service integration. Agent orchestration uses Amazon EventBridge, AWS Lambda, and AWS Step Functions to coordinate multi-step tasks, conditional logic, retries, and exception handling for complex intelligent-agent workflows. The knowledge base and RAG capabilities — built on Amazon S3, Bedrock Embeddings, Amazon OpenSearch, and Lambda — vectorize enterprise knowledge into OpenSearch and retrieve relevant context before Bedrock responds, improving answer accuracy and business relevance.
Database, Cache, and Streaming Data Layer
MySQL and ElastiCache are deployed in the data subnet: MySQL stores core business and transaction data, while ElastiCache caches hot data and frequently accessed results to reduce database load and improve system response times. Amazon Managed Streaming for Apache Kafka serves as the streaming-data and event-delivery platform, providing high-throughput, durable message streams that continuously transmit business events to downstream data-processing and analytics platforms.
Big Data and Analytics Layer
An independent big data analytics platform is composed of Amazon EMR, StarRocks, ClickHouse, OpenSearch, ZooKeeper, and Managed Workflows for Apache Airflow. EMR is used for large-scale data computation and processing; StarRocks and ClickHouse support high-performance analytical queries; OpenSearch supports search and log analytics; ZooKeeper provides coordination for selected distributed components; and Airflow manages data task scheduling and data-pipeline orchestration. The platform consumes Kafka streaming data and combines it with business data to produce analytical reports, operational insights, and search services.
Monitoring, Logging, and Auditing Layer
Amazon OpenSearch and Kibana provide logging and search capabilities, allowing application logs, system logs, and searchable operational data to be centrally collected and analyzed visually. Grafana provides unified monitoring dashboards for application, infrastructure, and business metrics; Amazon CloudWatch monitors AWS resource metrics, logs, and alarms; AWS CloudTrail records account and API activities to support auditability and traceability; and VPC Flow Logs capture network traffic information and can be archived in a dedicated S3 log bucket.
Security and Foundational Services Layer
AWS IAM manages permissions for users, operations personnel, application services, and CI/CD tools. AWS KMS manages encryption keys to protect data and logs, while AWS Certificate Manager manages HTTPS and TLS certificates. Amazon S3 serves as the foundational object storage service, storing knowledge-base documents, archived logs, data analytics files, backup files, and other business objects.