Admin System
Table of contents
01
02
03
04
�Business Needs
Functional Requirements
Solution �Architecture
Key Quality Attributes
Business Needs
Business Needs
Streamlined Operations
Secure Access and User Management
Secures System Access and user Management �
Combines administrative and back-office tasks (User Storage, Points Ledger, Admin Proxy App) into a single UI.
Controlled Access and Action Protection
Safeguard sensitive operations while having controlled access to the system
Transparency and Accountability
Maintains an audit trail of critical actions through logging
Enhanced Operational Security
Double checking system for sensitive tasks
Functional Requirements
Main Functional Requirements
Authentication & Role-Based Access Control
Retrieving System Log Records
Adjusting of points w/ Maker-Checker Request
Use Case 1
Authentication & Role-Based Access Control
Stakeholders:
Software Systems:
Authentication & Role-Based Access Control
1) Admin Logs In and gets authenticated and gains access to resources according to their roles
Use Case 2
Stakeholders:
Software Systems:
Retrieve System Log Records
Retrieve System Log Records
2) Admin logs in and queries for the system logs
Use Case 3
Stakeholders:
Software Systems:
Adjusting of points w/ Maker-Checker Request
Adjusting of points w/ Maker-Checker Request
3) Admin logs in and makes a request for adjusting of points
Solution Architecture
Solution Architecture
Key Components
Key Quality Attributes
Key Quality Attributes
Performance
Security
Maintainability
Resilience
Maintainability
Simplified Development & Deployment
Simplified maintenance and operations
By abstracting away infrastructure management, developers can focus on writing code and building features rather than dealing with operational tasks.
With serverless architecture, the cloud provider is responsible for managing and maintaining the underlying infrastructure, including security updates, patching, and monitoring.
Serverless
Performance
API Gateway caching reduces latency and load on Lambda services, improving responsiveness for clients.
Up to 1000 concurrent requests per second
Reduced Latency & Load
with API Gateway Caching
100k+ transactions in fraction of a second with Amazon Aurora
AWS Lambda enables seamless horizontal scaling to handle increases in incoming requests.
With Aurora's auto-scaling capabilities, we can dynamically scale to >100,000 transactions per second at peak load
Resilience & Disaster Recovery
1hr Recovery Time Objective with �Automated Backup & Recovery
99.99% Availability Multi-Availability Zone Deployment
5mins Recovery Point Objective with Continuous Backup & Point-in-Time Recovery
We distribute our deployment across multiple availability zones to enhance fault tolerance and ensure high availability of 99.99%.
AWS Backup is used to regularly backup data with a retention policy, ensuring minimal data loss and facilitating swift recovery. This enables us to achieve an RTO of 1 hour.
Leveraging AWS Backup’s continuous backup and point-in-time recovery capabilities, we are able to restore databases to specific points in time, enabling us to achieve an RPO of 5mins.
System Security
Immutable Log Storage in S3 bucket
Secure Data Storage and Management for Amazon Aurora and DynamoDB
Proactive Protection and Filtering using AWS WAF
Threat Detection and Incident Response with AWS GuardDuty
Activity Logging and Monitoring with CloudTrail and CloudWatch
AWS WAF with Amazon API Gateway, enabling us to inspect and filter incoming HTTP(S) requests
Configured CloudTrail logs to be routed and stored into an Amazon S3 bucket with Object Lock, ensuring logs are immutable.
Enhanced threat detection and incident response solution, anomaly detection, and integrated threat intelligence to improve security
CloudTrail and CloudWatch record every API call made to AWS services. This allows us to obtain comprehensive visibility into user and resource activity.
Aurora and DynamoDB are used for their encryption at rest capabilities, ensuring that personal identifiable information (PII) is securely stored. AWS KMS manages the encryption keys, allowing us to control and rotate keys for added security.
Personal Security
User Identity Management
Compliance & Security
AWS Cognito
Budget
Development Budget
Activity Name | Description | Cost |
Frontend prototype design | Designing of frontend using figma | 10 hours |
Frontend development | Creation of front end pages | 60 hours |
Backend planning | Planning of backend using sequence diagrams and pseudocode | 10 hours |
Backend development | Development of backend code | 80 hours |
Deployment on to Aws | Hosting of the code on AWS | 10 hours |
Testing | Testing system (stress and load) | 10 hours |
CI / CD setup | Setting up CI/CD of services | 15 hours |
Product Management | Managing timelines and tasks for project | 10 hours |
Budget
Production Budget (1/2)
Service Name | Description | Cost |
Cloudfront | Less than 1TB data and 10 million requests | Free |
Amplify | 5 requests per second, each build time taking an average of 5 minutes and 100 000 ssr request a month | 4.33USD |
Route53 | One hosted zone | 0.50USD |
Web Application Firewall | One ACl | 5USD |
Api Gateway | 5 request per second | 45.99USD |
Cognito | 10000 active monthly users | Free |
Guard duty | 5gb lambda logs, 1 aurora serverless v2 instance | 5.25USD |
Security Hub & Shield Basic | | Free |
Budget
Production Budget (2/2)
Service Name | Description | Cost |
Cloudwatch | 5gb worth of logs and 10 lambda function with 100 000 calls per function per month | Free |
CloudTrail | 2 million s3 operations and 8 million lambda data events | 10USD |
S3 (Logs) | 5GB data per month | 0.12 USD |
Lambda | 1M requests | Free |
Aurora | Serverless V1, no RDS provisioned, 1 ACU per hour | 43.80 USD |
DynamoDB | Baseline write of 5 per second, peak of 20. Baseline read of 10 per second, peak of 40 | 11.41 USD |
Simple Email Service | 100 000 messages sent monthly with a total of 5gb | 10.60USD |
TOTAL | | 137 USD |
Thank you