Skip to content
Flexday AI Docs

Architecture

Reference deployment on AWS

The AWS services a private Flexday AI deployment uses, the same shape Flexday runs on ECS Fargate, and how traffic and data flow between them.

Written for
  • Technical

Last reviewed

A private deployment on AWS runs the six Flexday AI services on ECS Fargate in your own account, with Aurora PostgreSQL, ElastiCache, S3 and the surrounding managed services. It mirrors the environments Flexday itself runs: one region, private subnets for the application and the data, and the edge in front.

At a glance

  • Everything inside your account. Compute, database, cache, storage, keys, sign-in and email all run in your AWS account and region.
  • Managed services throughout. ECS Fargate for compute, Aurora for PostgreSQL, ElastiCache for Redis; the one server is a small host for reaching the database, which needs routine patching.
  • Private by default. Services and data stores sit in private subnets; outbound calls leave through a NAT gateway.
  • Three services, one image. The Studio API, the worker and the gateway are one image with three entry points.
Your AWS account in one region: Route 53 and ACM, CloudFront with WAF and a load balancer at the edge; ECS Fargate services in private subnets; Aurora PostgreSQL 17 and ElastiCache; S3 (GuardDuty scanning supported), EFS, Cognito, SES, Secrets Manager and KMS, CloudWatch and ECR; outside the account, the Anthropic API, other AI providers, your identity provider and Azure Bot Service
Figure: reference deployment on AWS.

The services

AreaAWS serviceRole
DNS and certificatesRoute 53, AWS Certificate ManagerRecords and TLS certificates for your domain, including the wildcard for workspace app addresses. Queries to the deployment's public zones are logged to CloudWatch Logs and kept 365 days.
EdgeAmazon CloudFront (optional) and AWS WAFEdge TLS and request filtering in front of the load balancer, which has web application firewall rules of its own.
Load balancingApplication Load BalancerRoutes the five host families to the right service.
ComputeAmazon ECS on AWS FargateStudio web, Admin Console, Apps server, Studio API, Gateway and Worker, plus the one-off Migrate task, in private subnets.
DatabaseAmazon Aurora PostgreSQL 17 with pgvectorThe system of record, one schema per Fact Base, and document search.
Cache and queuesAmazon ElastiCache for RedisJob queues, live events, rate counters.
Object storageAmazon S3Deployed apps, files and documents, with workspace-prefixed keys. The buckets refuse any request not made over TLS, and their cross-origin rule admits large browser uploads from the Studio, the shared apps address and every workspace apps address.
Shared file systemAmazon EFS, encryptedOlder copies of app Drafts and uploaded sample data, written before both moved to object storage and still read until they are migrated, plus temporary upload space.
Malware scanningAmazon GuardDuty Malware Protection for S3 (supported; not switched on in the reference configuration)When it is switched on, an upload is served only after a clean verdict.
Sign-inAmazon CognitoUser pools: shared, per workspace, or per Solution for app end users.
EmailAmazon SESSign-in and Flow email over SMTP.
Keys and secretsAWS Secrets Manager, AWS KMSDatabase passwords, provider keys, the platform master key, and encryption at rest. A separate KMS key and a role limited to one workspace per session are created for Secret Variables, and stay unused until the deployment is set to seal them in Secrets Manager.
OperationsAmazon CloudWatch, Amazon SNS, Amazon ECRLogs, metrics and alarms per service, with alerts by email; the four container images with immutable tags, scanned when pushed.

Outside the account

ServiceNeeded for
Anthropic APIClaude models for building, Agents and Flows
Azure AI Foundry, Voyage AI or OpenAIGPT models or embeddings, where you use them
Your identity providerOpenID Connect or SAML sign-in, if not Cognito
Azure Bot ServiceOnly for Teams Bots

How traffic flows

  1. People, Teams and API clients reach your domain over HTTPS. CloudFront (with WAF) terminates TLS at the edge, and the load balancer routes by host name.
  2. Services in private subnets reach Aurora over encrypted connections, ElastiCache inside the private network (encryption in transit is a setting, off in the reference configuration), and S3 over HTTPS through the NAT gateway.
  3. Calls to AI providers, identity providers and Microsoft leave through the NAT gateway.
  4. A CI/CD pipeline builds the images that changed, pushes them to ECR, runs the migrate task when the API image changed, then rolls each changed service.

Operating notes

  • Scaling. The gateway, the worker and the web apps scale between one and three tasks behind the load balancer and the queue. The Studio API runs as a single task.
  • Redundancy. The reference configuration runs one Aurora instance and one Redis node. A second database instance and a multi-zone cache with automatic failover are settings, and so is a second NAT gateway, so each availability zone has its own way out (it adds a second outbound address). See Reliability and business continuity.
  • Releases. When a release changes the API image, the migrate task runs first, holding a lock so only one copy runs; if it fails, no service rolls.
  • Permissions after a release. The database permissions the gateway holds are applied by the migrate step. Rebuilding an image alone does not change them.
  • Cognito pools. A dedicated pool per workspace can be created by Flexday's provisioning when a workspace is set up. Per-Solution pools for app end users are provisioned by operators, with self-registration switched off.