Webhook Delivery Service  ·  View 15 of 20  ·  Operations

Deployment Architecture

Two regions, four subnet tiers, and an egress range that is a public interface.

Editable source SVG draw.io All views
AWS eu-west-1 — active Public subnets Application Load Balancer intake + console NAT Gateways published /28, 3 AZ Private subnets — capture and control Intake Service Fargate, 3 AZ Fan-out Service Fargate Control Plane subscriptions, replay Egress subnets — delivery only, no inward route Delivery Workers Fargate, autoscaled Replay Workers separate pool Regional services SQS FIFO per-endpoint groups DynamoDB global tables S3 payloads, CRR KMS multi-region key AWS eu-central-1 — warm standby Compute at floor Intake Service minimum tasks Delivery Workers scaled to zero Replicated state DynamoDB Global Tables RPO ≤ 5 s S3 Replica payloads NAT Gateways second published /28 Product Services Customer Endpoints signed POST replicates Deployment — Regions, Subnets and Egress Interface / broker Security / platform Application we own Queue / topic Data store External / third party synchronous event / async Both regions' egress ranges are published from day one, so a failover is not also an allowlist change for 40,000 consumers. v 1.0 · owner Integration Platform Architecture · date 2026-09

Decisions

  • Delivery workers live in egress-only subnets with no route into the capture, control or product networks. That topology is the control that holds when the address guard has a bug (ADR-12).
  • Both regions' NAT ranges are published from day one. Otherwise a failover is also an allowlist change for 40,000 consumers, which is a failover nobody will ever perform (ADR-11).
  • Standby is warm, not active-active: intake at a minimum task floor, delivery workers scaled to zero, state replicated continuously. Delivery RTO ≤ 15 minutes is cheaper to buy this way than active-active is to operate.
  • DynamoDB global tables and S3 cross-region replication carry the RPO. Accepted events are RPO 0 in-region and ≤ 5 s cross-region.

Assumptions

  • Three availability zones per region; SQS, DynamoDB, S3 and KMS are taken as regionally available services with their own multi-AZ properties.
  • Delivery RTO ≤ 15 min, intake RTO ≤ 5 min, subscription store RPO ≤ 5 s / RTO ≤ 10 min.
  • Duplicates after a regional failover are expected and are covered by the at-least-once contract rather than prevented.

Risks

  • NAT gateway port exhaustion presents as connection failures against perfectly healthy consumers, which is the hardest failure on this platform to diagnose. Egress capacity is tracked as a scaling dimension with its own headroom alarm.
  • Multi-region delivery is Phase 2. Single-region is the MVP, and a regional loss in the MVP is a delivery outage bounded by the retry window rather than a failover.