About This Architecture
SiPay's dual-VPC fintech platform in AWS af-south-1 separates production and UAT workloads across isolated networks, each spanning three availability zones for fault tolerance. The PROD VPC routes internet traffic through Cloudflare CDN/WAF and ACM-secured ALBs to PHP app servers, backed by RDS MySQL primary-standby clusters, ElastiCache Redis replicas, and EFS-mounted storage. Management, monitoring, and backup subnets isolate operational concerns—Pritunl VPN, GoCD/Graylog/Rundeck utilities, CloudWatch/X-Ray observability, and Data Lifecycle Manager policies enforce 30-day daily, 8-week weekly, and 12-month monthly retention. This architecture demonstrates defense-in-depth for regulated financial services: network segmentation, encryption in transit (HTTPS), secrets management via IAM and Secrets Manager, and comprehensive audit trails via CloudTrail and Config. Fork and customize this diagram on Diagrams.so to adapt subnet sizing, instance types, or backup policies for your fintech compliance requirements.