← Back to Projects

Cloud Engineering & FinOps

TradeCore FinOps

TradeCore Deploy focused on preparing a transactional platform for a 14-day institutional banking audit. The project brings together AWS infrastructure, application deployment, identity integration, automated delivery, operational monitoring, and financial governance under a startup budget constraint.

AWSTerraformDockerAmazon ECS FargateAmazon ECRAmazon RDS PostgreSQLAmazon CognitoAWS Secrets ManagerApplication Load BalancerGitHub ActionsOIDCAmazon CloudWatchAWS BudgetsAmazon SNS

01

The Problem

Prepare a containerized transactional application for a technical banking audit within a short delivery window and a strict cloud budget. The environment needed secure authentication, reliable application and database connectivity, repeatable deployments, operational visibility, and a documented cost-control strategy.

02

Architecture

▧

Architecture Diagram

A visual representation of the infrastructure, services, networking, and data flow will be displayed here.

The React frontend is hosted on AWS Amplify and communicates with a Node.js REST API running on Amazon ECS Fargate. An Application Load Balancer provides HTTPS ingress, Amazon Cognito manages user authentication, Amazon RDS for PostgreSQL provides relational storage, Amazon ECR stores container images, and AWS Secrets Manager supplies sensitive runtime configuration. CloudWatch and SNS support monitoring and operational alerts.

Evidence

Project Evidence

▧

Project Screenshot

A screenshot of the deployed application, infrastructure dashboard, CI/CD pipeline, or relevant implementation evidence will be displayed here.

03

Implementation

The project covers cost estimation and budget alerts before provisioning, infrastructure configuration with Terraform, database schema migration, container image publishing, ECS deployment, Cognito integration, and frontend configuration. GitHub Actions supports automated staging delivery through OIDC authentication, while production promotion uses a manual approval gate. Scheduled staging scale-down and an ordered teardown runbook address ongoing and end-of-project costs.

04

Security

Security controls include HTTPS through ACM and the Application Load Balancer, security-group rules that restrict API ingress to the load balancer, database access limited to the application tier, Secrets Manager integration, Cognito token verification, and short-lived AWS credentials through GitHub Actions OIDC. The public-subnet ECS design is documented as a deliberate cost trade-off, with inbound access restricted to the load balancer rather than the public internet.

05

Challenges

The main architectural trade-off was eliminating the recurring baseline cost of a managed NAT Gateway during a short evaluation period. Public-subnet ECS tasks can reach required AWS services without NAT, but their public IP addresses make strict inbound security-group controls essential. The project documents migration options for a higher-budget production environment, including private subnets with NAT Gateways or suitable VPC endpoints.

06

Result

The project notes report a 184 MB container image, a 4-minute-12-second staging deployment, and a 2-minute-34-second rollback recovery drill. They also report successful API smoke tests, end-to-end authentication and transaction testing, CI/CD approval controls, and an operational monitoring and teardown plan. Cost governance is built around a $25 monthly AWS Budget with 50% and 90% alert thresholds. Final actual spend should be supported by the AWS Cost Explorer report.