---
title: Design considerations
description: Review the architecture's service choices, access controls, reliability, and cost.
---

[Designing first architecture on AWS: CryptX 2.0 Hackathon Workshop](https://www.youtube.com/watch?v=OVOONoYWAjQ)

<WorkshopRecordingLink href="https://youtu.be/OVOONoYWAjQ" />

The workshop's main lesson is to choose services around the application's requirements. Managed services reduce operational work, but their limits, access model, and costs still need deliberate configuration.

## Match services to the workload

Use Lambda for bounded event-driven work; consider another compute option when processing needs a persistent server or exceeds execution limits. Store large unstructured files in S3. Choose DynamoDB around known access patterns, or a relational database when joins and relational transactions are central.

## Separate upload, analysis, and notification

SQS buffers work during traffic spikes. SNS distributes completion events independently of processing. Use job identifiers, processing status, and idempotent handlers so retries do not duplicate results. Plan how failed jobs will be inspected and recovered.

## Enforce access at each boundary

Cognito identifies users, while the API checks whether they may perform the requested operation. Keep S3 private, issue narrowly scoped presigned URLs, and use IAM policies to give each processing function the access it needs. Results and original files should remain associated with their owning user or event.

## Make deployment repeatable

Define resources, encryption, indexes, and policies in infrastructure code. Review changes in version control and keep development, test, and production settings explicit.

## Measure cost and capacity

Compare compute duration, request volume, storage retention, retrieval, database capacity, and AI usage. Pay-per-use billing can fit uneven traffic, but it does not guarantee the cheapest architecture. Monitor usage and compare current pricing for the actual region and workload.

## Keep AI analysis replaceable

Separate extraction and transcription from model analysis. Validate model responses and keep processing stages visible so the application can change models or recover a failed step without losing the original feedback.

[Return to the workshop overview](/docs/ta/workshops/aws-architecture)
