← Back to work

Case Study · 2026

AWS Infrastructure 3-Tier Architecture with Terraform

A production-style 3-tier AWS architecture provisioned entirely through Terraform — one module set, three isolated environments, no duplicated code.

RoleCloud & DevOps Engineer
TimelineSep 2026
FocusTerraform · AWS
SourceGitHub ↗
TERRAFORM AWS

Context

A 3-tier AWS architecture — load balancer, application compute, and a managed database — built with reusable Terraform modules and separate DEV, STAGE, and PROD environments.

The Problem

Standing up a VPC once is easy. Keeping DEV, STAGE, and PROD on the same architecture without copy-pasted Terraform, while each stays isolated, is the actual problem.

Process

01

01 — Tier before module

Defined the public, application, and database subnets and their trust boundaries first, before writing any resource.

02

02 — Modularize, then environment-ize

Built ten Terraform modules with zero environment logic inside them. Each environment supplies its own configuration — including CIDRs, sizing, database settings, and environment-specific variables.

03

03 — Chain security groups, not exceptions

ALB-SG → APP-SG → DB-SG. Only the ALB is internet-facing; the app and database tiers have no inbound path from the public internet.

Design Decisions

Separate state per environment

DEV, STAGE, and PROD each get their own directory and Terraform state instead of shared workspaces — the isolation is explicit, not implicit.

Modules that don't know the environment

No module contains a hardcoded CIDR, instance type, or environment name — the same `vpc` module builds DEV's `10.10.0.0/16` and PROD's `10.30.0.0/16`.

Private by default

App and database tiers have no public IP and no direct inbound path from the internet. Application instances use the NAT Gateway for outbound internet access, while the database tier has no internet route.

Outcome

✦ One module set drives three isolated environments with no duplicated infrastructure logic

✦ Private application and database tiers enforce controlled network paths through layered Security Groups

✦ CloudWatch provides baseline monitoring for ASG CPU, ALB 5XX errors, and RDS health

Reflection

“Terraform doesn't make infrastructure reusable by itself — the module has to be written so it doesn't care which environment is calling it.”