Three-environment .NET microservice backend on EC2 and ECR

Technologies
Summary
Web and mobile apps for hockey clubs, served by a .NET microservice backend on AWS across dev, preprod and prod.
This platform serves web and mobile apps for hockey clubs. A Vue.js frontend talks to a .NET microservice backend made up of a WebBFF, a MobileBFF and an SSO service. There are three environments, dev, preprod and prod, and each one has its own EC2 instance and ECR repositories. GitHub Actions builds every image, tags it with the Git commit SHA plus latest, pushes it to ECR and deploys to EC2 over SSH, so every release can be traced to a commit and rolled back. Container logs go to CloudWatch Logs through the Docker awslogs driver, CloudWatch alarms notify through SNS, and the WebBFF sends traces and metrics over OpenTelemetry to an ADOT collector. The SQL Server database runs on RDS in a private subnet, Nginx terminates TLS with Let's Encrypt, and DNS is on Cloudflare.
Details — Tech Stack
18 technologies across 5 layers
frontend
backend
database
cloud
tools
Details — Key Features
Three isolated environments (dev, preprod, prod), each with its own EC2 instance and ECR repositories
Images tagged with the Git commit SHA plus latest for traceable releases and rollback
GitHub Actions (workflow_dispatch) builds and pushes to ECR, then deploys to EC2 over SSH
Container logs shipped to CloudWatch Logs with the Docker awslogs driver, one log group per service and environment
CloudWatch alarms with SNS notifications, plus OpenTelemetry traces and metrics through an ADOT collector
RDS SQL Server in a private subnet, with images and documents stored on S3
Nginx with Let's Encrypt TLS and Cloudflare DNS
Environment-labelled images, so pruning only removes images from that environment
Methodology
01
Releases had to be traceable, and a bad deploy had to be easy to roll back in any of the three environments.
Every image is tagged with the Git commit SHA as well as latest and pushed to that environment's ECR repository. Any running container maps back to a commit, and rolling back means redeploying an earlier SHA tag.
02
Three environments share the same tooling, so cleanup or logging for one could easily affect another.
Each environment has its own EC2 instance and ECR repositories. Images carry an environment label so pruning only touches that environment, and logs go to a separate CloudWatch log group per service and environment.
Gallery
