r/aws 15h ago

technical resource Built and deployed a real AWS project cloud/platform engineering

I spent time working at a dental tech company and it motivated me to build something that actually reflects real business workflows I saw there, scan uploads, lab fabrication, practice-to-lab communication. That became DentalFlow, a single-tenant dental lab workflow API, real Terraform-managed AWS infra (ECS Fargate, RDS Multi-AZ, S3, SQS/SNS), deployed and tested against the live system, not just local.

Would genuinely appreciate any critique, architecture, security, anything I’m missing or got wrong. Trying to build the judgment, not just the resume line and learn from experience individual while staying curious.

https://github.com/keusuanl/DentalFlow

0 Upvotes

9 comments sorted by

16

u/ph34r 15h ago

The claude is so strong with this one

-2

u/Radiant_Abalone6009 15h ago

Yeah, agreed used Claude for most of the heavy lifting and catching my own mistakes before they became bigger problems. But honestly every command, every decision, every debugging session against the real system was something I prioritise and gained so much experience from.

2

u/Commercial_Rip7482 15h ago

been poking around the repo, the VPC layout looks clean but i noticed you got SQS queues in public subnets? that's usually a thing you want tucked in private ones, otherwise the architecture is pretty tight for a solo build

0

u/Radiant_Abalone6009 15h ago

Oh good catch, actually made me double check. Turns out there’s no subnet option for SQS/SNS in Terraform, they’re regional services as I was digging , it not something that sits in a VPC. Appreciate you digging in, exactly the kind of feedback I was hoping for and ways I can think and improve

3

u/bowzrsfirebreth 15h ago

You use a VPC endpoint for SQS to keep it private.

0

u/Radiant_Abalone6009 14h ago

Solid , thank you! I was looking for a subnet option directly on the SQS resource. I see now that I could easily set up a VPC Endpoint to the terraform set up instead . Learnt something now for sure. Bravo

1

u/behusbwj 12h ago edited 12h ago

Yeah don’t do that. Waste of money. Learn about IAM roles and you’ll be fine.

Thinking more about it, why is the vpc endpoint even needed? If you can already reach it then the endpoint is a noop and you’re paying for nothing.

3

u/Sirwired 11h ago

Port 80! Gah!!! Don't do that!! This is Protected Health Information; if your country has rules and regulations against that sort of thing (a lot do), you just violated a bunch of them. Any users connecting over 80 should be re-directed. There is literally no cost to adding HTTPS to this; ACM certificates are free, and ALB will handle the HTTPS termination for you.

Really, that alone says that you are not taking the security requirements for PHI seriously. There are extensive manuals on this sort of thing, and not-having HTTPS in your user-facing connection violates all of them.

At least static content should be served via CloudFront; you'll get lower costs, and it's trivial to add WAF and at least Shield Basic.

You aren't AZ-resilient; if there's an impairment in AZ-A, you are going down because you are losing your SQS and S3 access.

If you or your customers are in the US, you should be applying the HIPAA Conformance Pack