Skip to main content

Deployment Overview

The Bookstore platform supports two deployment modes:

ModeConfigurationUse case
Localdocker-compose.yml in this repositoryDevelopment and demos on localhost
Productionbookstore-infra (Terraform + Kubernetes + Argo CD)AWS EKS cluster with GitOps

Production deployment pipeline​

When a developer pushes a change to a service directory on main, GitHub Actions builds a new Docker image, pushes it to ECR, updates the image tag in the infra repo, and Argo CD automatically syncs the cluster to match Git.

See CI/CD Pipeline for workflow details and Kubernetes Deployment for manifest structure.

Local deployment (Docker Compose)​

The root docker-compose.yml is the local deployment artifact. It defines:

ComponentImage / buildPort
MySQL 8.4mysql:8.43306
Kafka 3.9.1 (KRaft)apache/kafka:3.9.19092
auth-service./auth-service/Dockerfile8081
user-service./user-service/DockerFile8082
book-service./book-service/Dockerfile8083
order-service./order-service/Dockerfile8084
notification-service./notification-service/DockerFile8085
payment-service./payment-service/DockerFile8087
analytics-service./analytics-service/Dockerfile8088
api-gateway./api-gateway/Dockerfile8080

Not included in Compose: frontend (run separately with npm run dev or build the production Docker image manually).

Start the full stack:

docker compose up --build -d

Start infrastructure only:

docker compose up mysql kafka -d

Docker containerization​

Each backend service uses a two-stage Dockerfile:

  1. Build stage — Maven 3.9 + Eclipse Temurin 17 compiles the JAR
  2. Runtime stage — Temurin 17 JRE, non-root spring user

The frontend production image (frontend/Dockerfile):

  1. Build stage — Node 22 builds the Vite bundle with VITE_* build args
  2. Runtime stage — nginx 1.27 serves static files and proxies /auth/, /api/, /analytics/ to the API gateway

Nginx configuration: frontend/nginx.conf (same-origin API proxy to avoid CORS in production).

A generic template also exists at docker/Dockerfile.service for reference.

Production Kubernetes (bookstore-infra)​

Kubernetes manifests are maintained in the bookstore-infra repository under k8s/:

ManifestKindNotes
auth-service.yamlDeployment + ServiceConnects to RDS MySQL
user-service.yamlDeployment + ServicePrometheus scrape annotations
book-service.yamlDeployment + Service + ServiceAccountIRSA for S3 access
order-service.yamlDeployment + ServiceKafka + Feign to book/user
payment-service.yamlDeployment + ServiceStripe secrets
notification-service.yamlDeployment + ServiceKafka consumer
analytics-service.yamlDeployment + ServiceKafka consumer
api-gateway.yamlDeployment + Service (LoadBalancer)Routes to all backends
frontend.yamlDeployment + Service (LoadBalancer)nginx on port 80
kafka.yamlStatefulSet + ServiceKRaft mode, single broker
argocd-app.yamlArgo CD ApplicationSyncs k8s/ → bookstore namespace
monitoring-apps.yamlArgo CD ApplicationsPrometheus, Grafana, Alertmanager

All application workloads run in the bookstore namespace. Monitoring runs in the monitoring namespace.

Kubernetes resources used​

ResourcePurpose
DeploymentsOne per microservice + frontend + api-gateway
StatefulSetKafka broker
ServicesCluster-internal DNS; LoadBalancer type for frontend and api-gateway
ServiceAccountsbook-service (IRSA for S3), prometheus
Secretsdb-credentials (RDS username/password from Kubernetes secret)
ConfigMapsPrometheus scrape configuration
PersistentVolumeClaimsPrometheus data (gp2 storage class, 10 Gi)

ConfigMaps and Secrets for application configuration are defined inline in the deployment manifests or referenced via secretKeyRef (e.g. db-credentials).

Argo CD GitOps​

The bookstore Argo CD Application (in k8s/argocd-app.yaml):

  • Source: https://github.com/ashishnamdeo16/bookstore-infra.git, path k8s/, branch main
  • Destination: in-cluster, namespace bookstore
  • Sync policy: automated with prune: true and selfHeal: true

Argo CD applies every manifest under k8s/ when the infra repo changes — including image tag updates committed by GitHub Actions.

Separate Argo CD Applications manage the monitoring stack (monitoring-prometheus, monitoring-grafana, monitoring-alertmanager).

AWS infrastructure​

Terraform modules in bookstore-infra provision:

  • VPC with public/private subnets and NAT gateway
  • Amazon EKS cluster with managed node groups
  • Amazon RDS MySQL (private, VPC-only access)
  • Amazon ECR repositories (one per service)
  • Amazon S3 bucket for book cover images
  • IAM roles for GitHub Actions OIDC and book-service IRSA

See AWS Architecture Overview for the full breakdown.

CI/CD services in scope​

GitHub Actions builds and deploys these 8 services on change:

book-service, payment-service, order-service, auth-service, user-service, notification-service, analytics-service, frontend

Not in CI: api-gateway (image is managed manually in the infra repo; ECR repository exists).