Skip to content
You are reading the docs for Backstory 0.2 (private beta). Behavior may change before general availability; the changelog lists every change.

AWS with Terraform

Backstory’s own SaaS runs on the Terraform in infra/terraform. You can use the same modules to run a private deployment on AWS.

RungWhenWhat runsMonthly cost
0 LaptopDevelopmentbundled profile on kind or k3d$0
1 Single VMShared testingk3s on one small VM, bundled profile$20–40
2 First AWS environmentDesign partnersEKS Auto Mode with one small node, Aurora Serverless v2 with auto-pause, S3, ClickHouse Cloud with idling (or in-cluster), CloudFront + WAF$150–250
3 Production postureFirst paying customerAdd replicas, Multi-AZ, GuardDuty and Security Hub, Object Lock, cross-region replication$450–1,300, then traffic-driven
  • envs/rung2-us: single account, single cluster, cheapest posture.
  • envs/prod-us: rung 3 with DR in us-west-2.
  • envs/prod-eu: rung 3 in eu-west-1 with DR in eu-central-1.

network, eks-auto, s3-chunks (versioning, SSE-KMS, retention-class lifecycle rules, optional Object Lock and cross-region replication), aurora-serverless, kms, cloudfront-waf, ecr, iam-service-roles (pod identities for gateway, worker, api), ses, budgets.

Terminal window
cd infra/terraform/envs/rung2-us
cp terraform.example.tfvars terraform.tfvars # edit
terraform init && terraform apply
cd ../../../..
infra/scripts/render-helm-values.sh infra/terraform/envs/rung2-us > deploy/helm/values-aws.yaml
helm upgrade --install backstory deploy/helm/backstory -f deploy/helm/values-aws.yaml -n backstory --create-namespace

The render script turns Terraform outputs (endpoints, bucket, role ARNs) into Helm values so the two stay consistent.

Nodes (EKS Auto Mode), Aurora capacity units, ClickHouse compute, S3, and CloudFront all grow with load. Turning on redundancy is deliberate: DR replica, Multi-AZ, and the security suite are single variables tied to having customers who need them.