NexusRetail — Multi-Tenant Retail Platform with AI Invoice Reconciliation
NexusRetail is a multi-tenant inventory and order management platform with a full AI invoice-reconciliation pipeline, designed, built, and operated solo in a real AWS account. The product itself was chosen because it’s messy enough to force real decisions across networking, compute, identity, multi-tenancy, security, AI document processing, CI/CD, and observability — in one system, not as separate exercises. It also doubled as the hands-on companion project for AWS Solutions Architect Associate study.
Network Isolation
Two-AZ VPC with public/private subnets — database and containers have no direct route to the internet.
Compute & Auth
ECS Fargate behind an ALB, RDS Postgres in the private subnet, Cognito for tenant-scoped access.
AI Invoice Reconciliation
Textract AnalyzeExpense extraction, automatic PO lookup, fuzzy line-item matching, human-in-the-loop on low-confidence matches.
Security
Separate ECS execution/task IAM roles, AWS WAF managed rules plus a custom rate-based rule, tuned from real false positives.
Observability
Terraform-defined CloudWatch dashboards, nine alarms on SNS — used in practice to distinguish a rolling deploy from an incident.
CI/CD
Two independent GitHub Actions pipelines — API to ECR/ECS, frontend to S3/CloudFront — each with its own IAM scope.
Every layer, built and operated end to end.
A custom VPC across two availability zones keeps the database and application containers off the public internet entirely. ECS Fargate runs behind an ALB fronted by WAF, RDS Postgres sits in the private subnet, and Cognito handles tenant-scoped auth. The invoice pipeline flows from S3 through Textract and fuzzy PO matching, routing to automatic stock updates or human review based on match confidence — with two independent GitHub Actions pipelines handling API and frontend deploys.
The build, narrated end to end.
Trade-offs made on purpose, not by default.
Task role vs. execution role, kept strictly separate
The execution role only pulls images and writes logs. A distinct task role is what the application actually uses to call S3, Textract, and Secrets Manager — conflating the two causes access-denied failures that look like code bugs but are an IAM gap.
Human-in-the-loop over full automation
The invoice pipeline could update stock automatically on every extraction. It doesn't. When a match is confident, stock updates immediately; when it isn't, the system stops and shows a person exactly what didn't align, with nothing written until they approve.
Landing page decoupled from the product
The marketing site at www.nexusretail.yuvarajai.com runs on its own S3 bucket, its own CloudFront distribution, and its own deploy pipeline — deliberately kept away from the authenticated app's release cadence.
WAF false positives fixed by exclusion, not by disabling rules
Two real false positives (SizeRestrictions_BODY and CrossSiteScripting_BODY, both against genuine PDF invoice uploads) were diagnosed from WAF sampled requests and excluded individually to count-only, with every other rule left fully enforced.
What it runs on.
AWS (eu-central-1) — VPC, ECS Fargate, ALB, RDS PostgreSQL, Cognito, S3, CloudFront, Route 53, ACM, Secrets Manager, Textract, Bedrock, CloudWatch, SNS, ECR, WAF · Terraform
Node.js, Prisma ORM, multer · GitHub Actions
Vite, React, Tailwind CSS
Currently blocked
A Bedrock orchestrator agent (a tool-calling loop over the Converse API for extract, match, and update-stock tools) is fully written but blocked on an AWS Marketplace payment-instrument issue unrelated to regular AWS billing — left documented as genuinely unresolved rather than implied working.
Want the Terraform, or a deeper walkthrough?
Happy to go through the networking, the WAF tuning, or the invoice pipeline in detail.
