Prices
Estimated monthly on-demand costs for this workload architecture.
Workload Costs Comparison
Prices by provider and services that enable users to run this workload. Shape the architecture based on cloud best practices using the four Architecture Priorities below — Capacity, Performance, Reliability, and Security. Components and prices recompute as you adjust each priority (e.g. higher Security adds a WAF, KMS, and threat monitoring), and you can switch region or billing period to compare like-for-like.
Architecture Priorities
Select level (High / Medium / Low) to adjust requirementsInfrastructure Architecture Blueprint
Copy or download (export) Terraform and OpenTofu architecture blueprints to deploy this workload in a cloud provider of your choice. Add parameters, credentials, or steps for CLI and DevOps CI/CD pipelines.
| 1 | # ============================================================================== |
| 2 | # ARCHITECTURE BLUEPRINT (TERRAFORM / OPENTOFU) |
| 3 | # Copyright (c) 2026 Cosell Plus, LLC. All Rights Reserved. |
| 4 | # |
| 5 | # DISCLAIMER & TERMS OF USE: |
| 6 | # This IaC blueprint is generated by CompareCloudCosts (CCC) for educational, |
| 7 | # planning, and directional architectural purposes. Provided "AS IS" without |
| 8 | # warranty of any kind, express or implied. Cosell Plus, LLC assumes no |
| 9 | # liability for operational costs, misconfigurations, or service interruptions. |
| 10 | # Always review and validate security, IAM, and compliance parameters before |
| 11 | # deploying to production environment. |
| 12 | # ============================================================================== |
| 13 | # |
| 14 | # ------------------------------------------------------------------------------ |
| 15 | # IDENTITY & CREDENTIAL PLACEHOLDERS (CLI & DEVOPS CI/CD PIPELINE) |
| 16 | # ------------------------------------------------------------------------------ |
| 17 | # Steps to execute this blueprint using Terraform: |
| 18 | # 1. Save this file as main.tf |
| 19 | # 2. Set provider authentication credentials: |
| 20 | # |
| 21 | # For AWS Local CLI Execution: |
| 22 | # export AWS_ACCESS_KEY_ID="<YOUR_AWS_ACCESS_KEY_ID>" |
| 23 | # export AWS_SECRET_ACCESS_KEY="<YOUR_AWS_SECRET_ACCESS_KEY>" |
| 24 | # export AWS_REGION="<REGION>" |
| 25 | # |
| 26 | # For AWS DevOps CI/CD Pipeline (GitHub Actions / GitLab CI / Azure DevOps): |
| 27 | # Recommended: Use AWS OpenID Connect (OIDC) Role Assumption: |
| 28 | # - role-to-assume: "arn:aws:iam::123456789012:role/GitHubActionsDeployerRole" |
| 29 | # - aws-region: "<REGION>" |
| 30 | # |
| 31 | # 3. Initialize and apply: |
| 32 | # $ terraform init |
| 33 | # $ terraform plan |
| 34 | # $ terraform apply |
| 35 | # ------------------------------------------------------------------------------ |
| 36 | |
| 37 | # ------------------------------------------------------------------------------ |
| 38 | # PROVIDER CONFIGURATION (TERRAFORM) |
| 39 | # ------------------------------------------------------------------------------ |
| 40 | 🔑 terraform { |
| 41 | required_version = ">= 1.5.0" |
| 42 | required_providers { |
| 43 | aws = { |
| 44 | source = "hashicorp/aws" |
| 45 | version = "~> 5.0" |
| 46 | } |
| 47 | } |
| 48 | } |
| 49 | |
| 50 | 🔑 provider "aws" { |
| 51 | region = var.aws_region |
| 52 | |
| 53 | default_tags { |
| 54 | tags = { |
| 55 | ManagedBy = "Terraform" |
| 56 | Environment = var.environment |
| 57 | Workload = var.workload_id |
| 58 | Vendor = "Cosell Plus LLC Blueprint" |
| 59 | } |
| 60 | } |
| 61 | } |
| 62 | |
| 63 | 🔑 variable "aws_region" { |
| 64 | type = string |
| 65 | default = "us-east-1" |
| 66 | description = "Target AWS Deployment Region" |
| 67 | } |
| 68 | |
| 69 | 🔑 variable "environment" { |
| 70 | type = string |
| 71 | default = "production" |
| 72 | description = "Deployment environment (e.g. dev, staging, production)" |
| 73 | } |
| 74 | |
| 75 | 🔑 variable "workload_id" { |
| 76 | type = string |
| 77 | default = "workload-blueprint" |
| 78 | description = "Identifier tag for the workload" |
| 79 | } |
| 80 | |
| 81 | # ------------------------------------------------------------------------------ |
| 82 | # WORKLOAD COMPONENT RESOURCES (HYBRID CLOUD NETWORK BACKBONE) |
| 83 | # ------------------------------------------------------------------------------ |
| 84 | # Component: Virtual Private Cloud (Isolated private network for cloud resources) |
| 85 | 🔑 resource "aws_custom_🔑 resource" "vpc" { |
| 86 | # Add required parameters for Virtual Private Cloud |
| 87 | } |
| 88 | |
| 89 | # Component: VPN Gateway (Secure site-to-site IPsec tunnels) |
| 90 | 🔑 resource "aws_custom_🔑 resource" "vpn_gateway" { |
| 91 | # Add required parameters for VPN Gateway |
| 92 | } |
| 93 | |
| 94 | # Component: Dedicated Connection (High-speed, dedicated on-premises link) |
| 95 | 🔑 resource "aws_custom_🔑 resource" "dedicated_connection" { |
| 96 | # Add required parameters for Dedicated Connection |
| 97 | } |
| 98 | |
| 99 | # Component: NAT Gateway (Outbound internet access for private subnets) |
| 100 | 🔑 resource "aws_custom_🔑 resource" "nat_gateway" { |
| 101 | # Add required parameters for NAT Gateway |
| 102 | } |
| 103 | |
| 104 | # Component: Network Security (Perimeter firewall and threat protection) |
| 105 | 🔑 resource "aws_custom_🔑 resource" "network_security" { |
| 106 | # Add required parameters for Network Security |
| 107 | } |
| 108 | |
| 109 | |
| 110 | # ------------------------------------------------------------------------------ |
| 111 | # OUTPUTS |
| 112 | # ------------------------------------------------------------------------------ |
| 113 | 🔑 output "blueprint_summary" { |
| 114 | value = { |
| 115 | workload_id = "hybrid-cloud-network" |
| 116 | 🔑 provider = "aws" |
| 117 | region = "us-east-1" |
| 118 | components = 5 |
| 119 | priorities = { |
| 120 | capacity = "medium" |
| 121 | performance = "medium" |
| 122 | reliability = "medium" |
| 123 | security = "medium" |
| 124 | } |
| 125 | } |
| 126 | } |
| 127 |