A supply-chain shipping & fulfillment SaaS platform
AWS-validated reference — full details available to AWS Partner Validation or on request. (Customer name held on file with VeUP.)
VeUP delivered a six-pillar AWS Well-Architected Review of the customer active-active, two-Region SaaS shipping platform on Amazon EKS, surfaced 7 owner-assigned High-Risk Issues with a 30-60-90 roadmap, and validated disaster recovery with AWS Fault Injection Service cross-region game-days.
The challenge
the customer runs a high-throughput, container-native shipping platform across two AWS Regions on mature Amazon EKS clusters with strong observability. As it scaled, the team needed an independent, structured assessment to surface the gaps engineering velocity outruns — edge protection at ingress, provable disaster recovery, autoscaling driven by application behavior rather than raw CPU, and resilience in the analytics tier — with a prioritized, owner-assigned remediation plan, not just a checklist.
The solution
A full six-pillar AWS Well-Architected Review consolidated in the AWS Well-Architected Tool through a scoped, ExternalId-gated read-only cross-account IAM role, producing a prioritized High-Risk Issue register and a sequenced 30-60-90 roadmap. VeUP then engineered the resilience proof with AWS Fault Injection Service, running cross-region failover game-days against the active-active architecture: Amazon EKS in both Regions (Terraform + Helm), Amazon Aurora PostgreSQL Global Database, Amazon S3 cross-region replication, Amazon ElastiCache global datastores, Amazon Route 53 region swap, and Amazon Redshift Serverless analytics. Representative remediations: piloting an ALB with AWS WAF managed rules at the edge, moving HPA onto application SLOs (RPS, latency, queue depth), and separating analytics via Redshift WLM/QMR. A managed FinOps review surfaced Savings Plans and commitment opportunities across Aurora, ElastiCache, and compute.
Production outcomes
| KPI | Result |
|---|---|
| Production outcomes | A complete six-pillar Well-Architected Review delivered against the live production workload via scoped cross-account access; 7 High-Risk Issues identified and prioritized, each assigned to a named customer owner with evidence and remediation timelines; a sequenced 30-60-90 day remediation roadmap separating quick wins from larger programs; disaster recovery validated through AWS Fault Injection Service game-days exercising a timed Region-impairment scenario and Route 53 failover against the active-active EKS architecture. |
| Engagement window | 2025-05-21 (AWS Referral Closed Won); WAR + remediations Closed Won 2025-09-30 → 2025-09-30 (WAR delivered, remediations underway); ongoing |
| Cost / TCO posture | A managed FinOps review identified Savings Plans / commitment opportunities across Amazon RDS/Aurora, ElastiCache, and compute (top spend = RDS, then compute, then caching; resources split across Oregon and Virginia). Realized $/% savings are delivered recommendations on the customer roadmap, not claimed outcomes. |
| Lessons & continuation | Provable DR beats documented DR — FIS game-days turn an RTO/RPO target into evidence; autoscaling on application SLOs (RPS/latency/queue depth) tracks real demand far better than raw CPU; edge protection (WAF managed rules) belongs in front of an ingress that previously had none. |
Amazon EKS · Amazon Aurora PostgreSQL Global Database · Amazon S3 cross-region replication · Amazon ElastiCache · Amazon Route 53 · Amazon Redshift Serverless · AWS WAF · AWS Fault Injection Service
Architecture
The six-pillar Well-Architected Review's active-active architecture: previous-state Amazon EKS clusters in two Regions behind an unprotected NLB/NGINX edge, remediated to a target state with an ALB + AWS WAF edge, SLO-driven autoscaling, and isolated Redshift Serverless analytics — annotated against all six WAFR pillars and proven via AWS FIS cross-region game-days.