Cityworks AWS Production Network Architecture

aws · network diagram.

About This Architecture

Cityworks production network on AWS spans three architectural layers—core, distribution, and access—with an internet-facing Application Load Balancer routing traffic through a Transit Gateway to on-premises infrastructure. The VPC (10.0.0.0/16) distributes workloads across two availability zones: public subnets host a bastion, PowerBI gateway, and public works queries server, while private subnets isolate SQL Server and PostgreSQL RDS instances with Multi-AZ standby replicas. Security is enforced via layered security groups (BastionSecurityGroup, ServerSecurityGroup, UserManagerDBSg, EFSSecurityGroup), GuardDuty threat detection, and VPC endpoints, with S3 backup buckets and access logging for compliance. This architecture demonstrates high-availability hybrid cloud design with clear blast radius isolation and cross-AZ failover. Fork and customize this diagram on Diagrams.so to adapt the Transit Gateway attachment, subnet CIDR ranges, or instance types for your own production environment.

People also ask

How do you design a production AWS network with on-premises hybrid connectivity, Multi-AZ database failover, and security group isolation?

Cityworks' architecture uses a Transit Gateway to bridge on-premises and AWS, an internet-facing ALB in public subnets for ingress, private subnets for RDS Multi-AZ instances (SQL Server and PostgreSQL), and layered security groups (BastionSecurityGroup, ServerSecurityGroup, UserManagerDBSg) to enforce least-privilege access. GuardDuty and CloudWatch provide threat detection and monitoring across

Cityworks AWS Production Network Architecture

AWSadvancedTransit GatewayMulti-AZRDSVPChybrid-network
Domain: Cloud AwsAudience: AWS solutions architects designing multi-tier production networks with hybrid connectivity
0 views0 favoritesPublic

Created by

April 7, 2026

Updated

April 7, 2026 at 7:18 PM

Type

network

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI