Three-tier app in a VPC architecture

The same three-tier shape drawn the way AWS actually organises it: edge in the public subnets, app and data in the private ones, two availability zones, and the pieces that live outside the VPC outside the box.

AWSvpcsubnetalbfargate
VPCprod-vpcSUBNETpublic aSUBNETpublic bSUBNETprivate aSUBNETprivate bDomain1 zone + queries,certificate freeLoad balancer (ALB)1 ALB + light LCUusageNAT gateway1 gateway + 100 GBApp service ×33 × 0.25 vCPU · 0.5 GBPrimary databasedb.t4g.large ·multi-AZ · 100 GBElastiCache Rediscache.t4g.smallUser uploads100 GB standard
12 nodes — 7 resources in 5 containers. Drawn by the same layout the product uses.
What is in it

Every resource, and what it costs.

Projections from August 2026 list prices for always-on resources. Connect an account and these become the figures your provider actually bills.

Resources in the Three-tier app in a VPC template with projected monthly cost.
NodeTypeWhat it isProjected
DomainNetwork1 zone + queries, certificate free$1.00/mo
Load balancer (ALB)Network1 ALB + light LCU usage$23/mo
NAT gatewayNetwork1 gateway + 100 GB$37/mo
App service ×3Compute3 × 0.25 vCPU · 0.5 GB$27/mo
Primary databaseDatabasedb.t4g.large · multi-AZ · 100 GB$215/mo
ElastiCache RedisDatabasecache.t4g.small$25/mo
User uploadsStorage100 GB standard$3.00/mo
prod-vpcgroup
public agroup
public bgroup
private agroup
private bgroup

Agent steps are priced from provider-reported token usage once the agent runs, not estimated. Guardrails cost nothing and are the reason a runaway agent cannot.

Open Three-tier app in a VPC on the canvas.

It loads as an editable graph. Connect an account or instrument an agent and the projected figures above become measured ones.