Skip to content

Architecture Map

A drill-down view of the whole Adventive application, with Cloudflare as the front door. Click any block in the map to expand its detail: the zones, the Workers fleet, edge storage, Zero Trust, the AWS origins, and the private databases. Use Reset to return to the overview, and the toggle for light or dark. The map is generated read-only from the Cloudflare account inventory.

Open the architecture map full screen

The same layers as a single static diagram, for print and quick reference.

Adventive application architecture, end to end Cloudflare is the front door to the whole estate. Traffic enters at the edge and reaches AWS, Cloudflare-native services, and the private databases. ENTRY CLOUDFLARE EDGE COMPUTE & STORAGE ZERO TRUST ORIGINS & DATA VisitorsHTTPS Public web and API traffic to every adventive hostname. Cloudflare DNS13 zones Authoritative NS (igor / may). 5 operational, 8 brand / parked. Proxy / TLS / CDN Terminates TLS, caches, and reverse-proxies to origins. 78 proxied hostnames across 5 zones WAF / DDoS L7 DDoS alert on. Managed WAF rules need dashboard confirmation. Workers31 Platform/API, Marketing/CMS, docs demos, legacy/ad. Pages1 docs.adventive.dev (GitHub) Edge storage24 R2 8 · KV 8 · D1 3 · Queues 2 Hyperdrive 3 (console/aggregate/ billing). All dev-tier. Access15 Gates admin, API, and db hostnames. Session 6h. Identity3 JumpCloud SAML, Google, OTP Tunnels2 Only inbound path to private net AWS (us-east-1) ELB (ads, console), CloudFront, S3 buckets, EC2. Third-party SaaS2 HubSpot (support), Stripe (SAML) Private databases3 console, aggregate, billing. RDS / Aurora, never public. Via tunnel + Hyperdrive. DATABASE ACCESS CHAIN Worker binding → Hyperdrive → db-*-dev.adventive.dev (Access token) → cloudflared tunnel → private RDS / Aurora endpoint. CROSS-CUTTING Observability OpenTelemetry to New Relic is the mandated baseline for every Worker and Pages SPA. NR proxy Worker deployed. Secrets Worker runtime: Cloudflare Secrets Store (bind by reference). IdP recovery + AWS: AWS Secrets Manager (MFA-gated). Account members4 1 Super Admin, 2 Admin, 1 Domain Admin. Two-factor authentication enabled on all four. Cloudflare Zero Trust AWS SaaS Private data Entry Generated read-only from the Cloudflare API on 2026-07-16. WAF, SSL/TLS, and Logpush detail were outside the review token scope.

The interactive map is self-contained and served from public/. It respects your light or dark preference; the site defaults to dark.