Our architecture has been designed from the ground up to be scalable, redundant and secure. We selected the AWS cloud as the foundation for our infrastructure to leverage the built in security, high availability and flexibility which has allowed us to iterate quickly and try several permutations before landing on our current setup.
Six dedicated subnets Across Three Availability Zones
Producer nodes are running in a private subnet with no internet access
Relay nodes are in public subnets with internet access, but protected by a firewall which only allows access to port the relay port. Any management access must be done from the management subnet.
Management subnet contains a bastion host for jump-boxing to relays and producer nodes. The node sandbox is spun up when upgrading to new software versions to create a ‘golden image’ which will then be rolled out to the rest of the network
We are using several tools to help us achieve automation and keep a smoothly running stake pool
Keep an eye out on Github where we will be posting our scripts and libraries for the Cardano community!