100% AWS Cloud · Designed, Deployed & Operated Solo
Independent AWS Build · eu-central-1

NexusRetail — Multi-Tenant Retail Platform with AI Invoice Reconciliation

NexusRetail is a multi-tenant inventory and order management platform with a full AI invoice-reconciliation pipeline, designed, built, and operated solo in a real AWS account. The product itself was chosen because it’s messy enough to force real decisions across networking, compute, identity, multi-tenancy, security, AI document processing, CI/CD, and observability — in one system, not as separate exercises. It also doubled as the hands-on companion project for AWS Solutions Architect Associate study.

AWS services used
VPCECS FargateALBRDS PostgreSQLCognitoS3CloudFrontRoute 53ACMSecrets ManagerTextractBedrockCloudWatchSNSECRWAF
Source →

Network Isolation

Two-AZ VPC with public/private subnets — database and containers have no direct route to the internet.

Compute & Auth

ECS Fargate behind an ALB, RDS Postgres in the private subnet, Cognito for tenant-scoped access.

AI Invoice Reconciliation

Textract AnalyzeExpense extraction, automatic PO lookup, fuzzy line-item matching, human-in-the-loop on low-confidence matches.

Security

Separate ECS execution/task IAM roles, AWS WAF managed rules plus a custom rate-based rule, tuned from real false positives.

Observability

Terraform-defined CloudWatch dashboards, nine alarms on SNS — used in practice to distinguish a rolling deploy from an incident.

CI/CD

Two independent GitHub Actions pipelines — API to ECR/ECS, frontend to S3/CloudFront — each with its own IAM scope.

Reference Architecture

Every layer, built and operated end to end.

A custom VPC across two availability zones keeps the database and application containers off the public internet entirely. ECS Fargate runs behind an ALB fronted by WAF, RDS Postgres sits in the private subnet, and Cognito handles tenant-scoped auth. The invoice pipeline flows from S3 through Textract and fuzzy PO matching, routing to automatic stock updates or human review based on match confidence — with two independent GitHub Actions pipelines handling API and frontend deploys.

NexusRetail AWS architecture — Route 53, WAF, ALB, ECS Fargate, RDS Postgres in a two-AZ VPC, Cognito auth, Textract invoice pipeline with confidence-based human review, and dual GitHub Actions CI/CD pipelines
Click to view full size
Full Walkthrough

The build, narrated end to end.

Full architecture walkthrough, recorded end to end
Decisions I’d Defend

Trade-offs made on purpose, not by default.

Task role vs. execution role, kept strictly separate

The execution role only pulls images and writes logs. A distinct task role is what the application actually uses to call S3, Textract, and Secrets Manager — conflating the two causes access-denied failures that look like code bugs but are an IAM gap.

Human-in-the-loop over full automation

The invoice pipeline could update stock automatically on every extraction. It doesn't. When a match is confident, stock updates immediately; when it isn't, the system stops and shows a person exactly what didn't align, with nothing written until they approve.

Landing page decoupled from the product

The marketing site at www.nexusretail.yuvarajai.com runs on its own S3 bucket, its own CloudFront distribution, and its own deploy pipeline — deliberately kept away from the authenticated app's release cadence.

WAF false positives fixed by exclusion, not by disabling rules

Two real false positives (SizeRestrictions_BODY and CrossSiteScripting_BODY, both against genuine PDF invoice uploads) were diagnosed from WAF sampled requests and excluded individually to count-only, with every other rule left fully enforced.

Tech Stack

What it runs on.

Cloud & IaC

AWS (eu-central-1) — VPC, ECS Fargate, ALB, RDS PostgreSQL, Cognito, S3, CloudFront, Route 53, ACM, Secrets Manager, Textract, Bedrock, CloudWatch, SNS, ECR, WAF · Terraform

Backend & CI/CD

Node.js, Prisma ORM, multer · GitHub Actions

Frontend

Vite, React, Tailwind CSS

Currently blocked

A Bedrock orchestrator agent (a tool-calling loop over the Converse API for extract, match, and update-stock tools) is fully written but blocked on an AWS Marketplace payment-instrument issue unrelated to regular AWS billing — left documented as genuinely unresolved rather than implied working.

Want the Terraform, or a deeper walkthrough?

Happy to go through the networking, the WAF tuning, or the invoice pipeline in detail.

Get in touch →