Architecture
An active-active setup across three availability zones in the UAE region, with card data isolated in its own account and every change applied through code review and CI.
- Multi-account AWS Organization: shared services, PCI workloads and non-PCI workloads separated
- EKS clusters per environment with Karpenter autoscaling
- Aurora PostgreSQL with cross-AZ replicas and point-in-time recovery
- Route 53 weighted routing used for the gradual cut-over
- KMS-encrypted secrets, CloudTrail and GuardDuty feeding a central security account
- GitHub Actions and Argo CD for every infrastructure and application change