mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 15:27:27 +00:00
doc: removed specifics
This commit is contained in:
@@ -45,8 +45,8 @@ A typical Infisical Cloud deployment consists of the following components:
|
|||||||
|
|
||||||
The Infisical application runs as multiple containerized services on ECS:
|
The Infisical application runs as multiple containerized services on ECS:
|
||||||
|
|
||||||
- **Main Server**: 10-30 instances (2048 CPU, 4096 MB memory) with auto-scaling
|
- **Main Server**: Auto-scaling containerized application services
|
||||||
- **License API**: 2-4 instances (2048 CPU, 4096 MB memory) with dedicated infrastructure (shared globally)
|
- **License API**: Dedicated service with separate infrastructure (shared globally)
|
||||||
- **Monitoring**: AWS OTel Collector and Datadog Agent sidecars
|
- **Monitoring**: AWS OTel Collector and Datadog Agent sidecars
|
||||||
|
|
||||||
Container images are pulled from Docker Hub and managed via GitHub Actions for deployments.
|
Container images are pulled from Docker Hub and managed via GitHub Actions for deployments.
|
||||||
@@ -77,17 +77,15 @@ Each region operates in a separate AWS account, providing strong isolation bound
|
|||||||
### US Cloud (us.infisical.com or app.infisical.com)
|
### US Cloud (us.infisical.com or app.infisical.com)
|
||||||
|
|
||||||
- **AWS Account**: Dedicated US AWS account
|
- **AWS Account**: Dedicated US AWS account
|
||||||
- **Cluster**: `infisical-core-platform` ECS cluster
|
- **Infrastructure**: ECS-based containerized deployment
|
||||||
- **Scaling**: 10-30 main server instances, 2-4 license server instances
|
- **Monitoring**: Integrated with Datadog for observability and security monitoring
|
||||||
- **Monitoring**: Integrated with Datadog
|
|
||||||
|
|
||||||
### EU Cloud (eu.infisical.com)
|
### EU Cloud (eu.infisical.com)
|
||||||
|
|
||||||
- **AWS Account**: Dedicated EU AWS account
|
- **AWS Account**: Dedicated EU AWS account
|
||||||
- **Cluster**: `infisical-core-platform` ECS cluster
|
- **Infrastructure**: ECS-based containerized deployment
|
||||||
- **Scaling**: 15-30 main server instances, 2-4 license server instances
|
|
||||||
- **Monitoring**: Integrated with Datadog
|
|
||||||
- **Compliance**: GDPR compliant with data residency within EU
|
- **Compliance**: GDPR compliant with data residency within EU
|
||||||
|
- **Monitoring**: Integrated with Datadog for observability and security monitoring
|
||||||
|
|
||||||
## Configuration Management
|
## Configuration Management
|
||||||
|
|
||||||
@@ -104,14 +102,13 @@ Application configuration and secrets are managed through AWS SSM Parameter Stor
|
|||||||
|
|
||||||
- **AWS OTel Collector**: Prometheus metrics collection
|
- **AWS OTel Collector**: Prometheus metrics collection
|
||||||
- **Datadog Agent**: Application performance monitoring and infrastructure metrics
|
- **Datadog Agent**: Application performance monitoring and infrastructure metrics
|
||||||
- **Auto Scaling**: CPU and memory-based scaling triggers at 60% utilization
|
|
||||||
|
|
||||||
## Container Management
|
## Container Management
|
||||||
|
|
||||||
- **Images**: `infisical/staging_infisical` and `infisical/license-server` from Docker Hub
|
- **Images**: `infisical/staging_infisical` and `infisical/license-server` from Docker Hub
|
||||||
- **Deployment**: Automated via GitHub Actions updating SSM parameter for image tags
|
- **Deployment**: Automated via GitHub Actions updating SSM parameter for image tags
|
||||||
- **Registry Access**: Docker Hub credentials stored in AWS Secrets Manager
|
- **Registry Access**: Docker Hub credentials stored in AWS Secrets Manager
|
||||||
- **Platform**: ECS Fargate with 70% standard capacity, 30% Spot instances
|
- **Platform**: ECS Fargate serverless container platform
|
||||||
|
|
||||||
## Security Overview
|
## Security Overview
|
||||||
|
|
||||||
@@ -125,9 +122,8 @@ Application configuration and secrets are managed through AWS SSM Parameter Stor
|
|||||||
### Network Architecture
|
### Network Architecture
|
||||||
|
|
||||||
- **VPC Design**: Dedicated VPC with public and private subnets across multiple Availability Zones
|
- **VPC Design**: Dedicated VPC with public and private subnets across multiple Availability Zones
|
||||||
- **NAT Gateway**: All outbound traffic from private subnets routes through NAT Gateway for external connectivity
|
- **NAT Gateway**: Controlled outbound connectivity from private subnets
|
||||||
- **Load Balancing**: Application Load Balancer with SSL termination and health checks
|
- **Load Balancing**: Application Load Balancer with SSL termination and health checks
|
||||||
- **Service Communication**: AWS Service Connect for internal service discovery
|
- **Security Groups**: Restrictive firewall rules and controlled network access
|
||||||
- **Security Groups**: Restrictive firewall rules (port 8080 for main server, 4000 for license API)
|
|
||||||
- **High Availability**: Multi-AZ deployment with automatic failover
|
- **High Availability**: Multi-AZ deployment with automatic failover
|
||||||
- **Network Monitoring**: VPC Flow Logs with 365-day retention for traffic analysis
|
- **Network Monitoring**: VPC Flow Logs with 365-day retention for traffic analysis
|
||||||
|
|||||||
Reference in New Issue
Block a user