About This Architecture
Production WorkSpaces architecture in us-east-1 with dual-AZ deployment across us-east-1b and us-east-1d, featuring five managed desktops (SysAdmin, DSS, SAP BA, Network, SAP Admin roles) connected via AD Connector to on-premises Domain Controllers. Network traffic flows through Transit Gateway for hybrid connectivity, Route 53 Resolver for DNS forwarding to corporate tsi.corp.com, and VPC endpoints for secure AWS service access without internet exposure. This architecture demonstrates high-availability WorkSpaces with redundant AD Connector ENIs, encryption-ready KMS keys, and pre-staged regional VPCs in Frankfurt, Mumbai, and Singapore for future expansion. Fork this diagram on Diagrams.so to customize subnets, add additional regions, or adjust security group rules for your organization. The design balances cost optimization (encryption disabled on current desktops) with security best practices (VPC endpoints, Secrets Manager for AD credentials, CloudWatch monitoring).