About This Architecture
Multi-tier AWS Elastic Beanstalk architecture with layered security groups enforcing least-privilege access across public, app, and data tiers. Internet and Office VPC traffic routes through an Elastic Load Balancer protected by RedShield WAF and Route 53 health checks, with separate security groups controlling ingress to EC2 Auto Scaling instances, RDS PostgreSQL, and Amazon EFS. Security group self-references and CIDR-based rules isolate the app tier from direct external access while enabling internal east-west communication. Fork this diagram to customize security group rules, add additional WAF rules, or adapt CIDR ranges for your VPC design. This architecture demonstrates AWS best practices for defense-in-depth networking in production Elastic Beanstalk environments.