A drill-down view of the whole Adventive application, with Cloudflare as the front door. Click any block in the map to expand its detail: the zones, the Workers fleet, edge storage, Zero Trust, the AWS origins, and the private databases. Use Reset to return to the overview, and the toggle for light or dark. The map is generated read-only from the Cloudflare account inventory.
Open the architecture map full screen
The same layers as a single static diagram, for print and quick reference.
Adventive application architecture, end to end Cloudflare is the front door to the whole estate. Traffic enters at the edge and reaches AWS, Cloudflare-native services, and the private databases. ENTRY CLOUDFLARE EDGE COMPUTE & STORAGE ZERO TRUST ORIGINS & DATA Visitors HTTPS Public web and API traffic to every adventive hostname. Cloudflare DNS 13 zones Authoritative NS (igor / may). 5 operational, 8 brand / parked. Proxy / TLS / CDN Terminates TLS, caches, and reverse-proxies to origins. 78 proxied hostnames across 5 zones WAF / DDoS L7 DDoS alert on. Managed WAF rules need dashboard confirmation. Workers 31 Platform/API, Marketing/CMS, docs demos, legacy/ad. Pages 1 docs.adventive.dev (GitHub) Edge storage 24 R2 8 · KV 8 · D1 3 · Queues 2 Hyperdrive 3 (console/aggregate/ billing). All dev-tier. Access 15 Gates admin, API, and db hostnames. Session 6h. Identity 3 JumpCloud SAML, Google, OTP Tunnels 2 Only inbound path to private net AWS (us-east-1) ELB (ads, console), CloudFront, S3 buckets, EC2. Third-party SaaS 2 HubSpot (support), Stripe (SAML) Private databases 3 console, aggregate, billing. RDS / Aurora, never public. Via tunnel + Hyperdrive. DATABASE ACCESS CHAIN Worker binding → Hyperdrive → db-*-dev.adventive.dev (Access token) → cloudflared tunnel → private RDS / Aurora endpoint. CROSS-CUTTING Observability OpenTelemetry to New Relic is the mandated baseline for every Worker and Pages SPA. NR proxy Worker deployed. Secrets Worker runtime: Cloudflare Secrets Store (bind by reference). IdP recovery + AWS: AWS Secrets Manager (MFA-gated). Account members 4 1 Super Admin, 2 Admin, 1 Domain Admin. Two-factor authentication enabled on all four. Cloudflare Zero Trust AWS SaaS Private data Entry Generated read-only from the Cloudflare API on 2026-07-16. WAF, SSL/TLS, and Logpush detail were outside the review token scope.
Account and Zones : the account, members, all 13 zones, and the environment mapping.
DNS and Request Routing : proxied hostnames through the edge to their origins.
Workers and Storage : the 31-Worker fleet and the KV, D1, R2, Queues, and Hyperdrive it binds.
Zero Trust and Security : Access, identity, tunnels, and the security posture.
Change Log : material changes over time, updated on each refresh.
The interactive map is self-contained and served from public/. It respects your light or dark preference; the site defaults to dark.