Cloud Engineering & FinOps
TradeCore FinOps
TradeCore Deploy focused on preparing a transactional platform for a 14-day institutional banking audit. The project brings together AWS infrastructure, application deployment, identity integration, automated delivery, operational monitoring, and financial governance under a startup budget constraint.
01
The Problem
Prepare a containerized transactional application for a technical banking audit within a short delivery window and a strict cloud budget. The environment needed secure authentication, reliable application and database connectivity, repeatable deployments, operational visibility, and a documented cost-control strategy.
02
Architecture
Architecture Diagram
A visual representation of the infrastructure, services, networking, and data flow will be displayed here.
The React frontend is hosted on AWS Amplify and communicates with a Node.js REST API running on Amazon ECS Fargate. An Application Load Balancer provides HTTPS ingress, Amazon Cognito manages user authentication, Amazon RDS for PostgreSQL provides relational storage, Amazon ECR stores container images, and AWS Secrets Manager supplies sensitive runtime configuration. CloudWatch and SNS support monitoring and operational alerts.
Evidence
Project Evidence
Project Screenshot
A screenshot of the deployed application, infrastructure dashboard, CI/CD pipeline, or relevant implementation evidence will be displayed here.
03
Implementation
The project covers cost estimation and budget alerts before provisioning, infrastructure configuration with Terraform, database schema migration, container image publishing, ECS deployment, Cognito integration, and frontend configuration. GitHub Actions supports automated staging delivery through OIDC authentication, while production promotion uses a manual approval gate. Scheduled staging scale-down and an ordered teardown runbook address ongoing and end-of-project costs.
04
Security
Security controls include HTTPS through ACM and the Application Load Balancer, security-group rules that restrict API ingress to the load balancer, database access limited to the application tier, Secrets Manager integration, Cognito token verification, and short-lived AWS credentials through GitHub Actions OIDC. The public-subnet ECS design is documented as a deliberate cost trade-off, with inbound access restricted to the load balancer rather than the public internet.
05
Challenges
The main architectural trade-off was eliminating the recurring baseline cost of a managed NAT Gateway during a short evaluation period. Public-subnet ECS tasks can reach required AWS services without NAT, but their public IP addresses make strict inbound security-group controls essential. The project documents migration options for a higher-budget production environment, including private subnets with NAT Gateways or suitable VPC endpoints.
06
Result
The project notes report a 184 MB container image, a 4-minute-12-second staging deployment, and a 2-minute-34-second rollback recovery drill. They also report successful API smoke tests, end-to-end authentication and transaction testing, CI/CD approval controls, and an operational monitoring and teardown plan. Cost governance is built around a $25 monthly AWS Budget with 50% and 90% alert thresholds. Final actual spend should be supported by the AWS Cost Explorer report.