Skip to main content
The recommended AWS path is Helm on Amazon EKS with Amazon RDS for MySQL. For the smallest first deployment, use EKS Auto Mode and Kubernetes LoadBalancer Services so AWS provisions Network Load Balancers for Den web and Den API. Move to an ALB or an existing ingress platform when you need shared layer-7 routing, WAF policy, or more advanced certificate handling.

What AWS manages

  • EKS control plane, compute, pod networking, and load-balancer integration
  • VPCs, subnets, routing, security groups, and IAM
  • RDS for MySQL, encryption, backups, and failover
  • Route 53 DNS and ACM certificates when you use those services
The OpenWork chart manages Deployments, Services, ConfigMaps, Secret references, probes, and the database migration Job.

AWS checklist

  1. Create an EKS Auto Mode cluster with eksctl 0.195.0 or newer.
  2. Create an RDS MySQL 8-compatible database in private subnets.
  3. Allow database port 3306 only from the EKS workload or node security boundary.
  4. Store DATABASE_URL, BETTER_AUTH_SECRET, and DEN_DB_ENCRYPTION_KEY in a Kubernetes Secret.
  5. Start from the chart’s values.aws-load-balancer.yaml example.
  6. Install the chart, verify migrations and readiness, then point DNS at the generated load balancers.
  7. Enable trusted HTTPS before creating the first administrator.
For exact CLI commands, values, DNS/TLS choices, migration troubleshooting, verification, and cleanup, follow the AWS EKS operator runbook.

ECS Fargate with Terraform (draft)

If you run containers on ECS Fargate rather than Kubernetes, a draft Terraform module deploys the same two services without a cluster: Den API and Den web as Fargate services behind an HTTPS Application Load Balancer, RDS for MySQL, optional ElastiCache for Redis, and secrets in AWS Secrets Manager. Database migrations run before Den API starts on each deploy.
The module is an early draft. It has been applied end to end in a test account, but inputs may change. Pin it to a commit, and open an issue or pull request for anything that fails in your environment.
You provide a VPC, two hostnames (the web host and api. plus the web host), and an ACM certificate or a Route 53 zone the module can use to create one. HTTPS is required: Den API does not start with a plain-HTTP public URL. Email is optional for setup and sign-in, but member invites and password reset need SMTP or Resend. See the module README for inputs, a complete example, and cost notes. Next: Create the first administrator.