Prices
Estimated monthly on-demand costs for this workload architecture.
Workload Costs Comparison
Prices by provider and services that enable users to run this workload. Shape the architecture based on cloud best practices using the four Architecture Priorities below — Capacity, Performance, Reliability, and Security. Components and prices recompute as you adjust each priority (e.g. higher Security adds a WAF, KMS, and threat monitoring), and you can switch region or billing period to compare like-for-like.
Architecture Priorities
Select level (High / Medium / Low) to adjust requirementsInfrastructure Architecture Blueprint
Copy or download (export) Terraform and OpenTofu architecture blueprints to deploy this workload in a cloud provider of your choice. Add parameters, credentials, or steps for CLI and DevOps CI/CD pipelines.
| 1 | # ============================================================================== |
| 2 | # ARCHITECTURE BLUEPRINT (TERRAFORM / OPENTOFU) |
| 3 | # Copyright (c) 2026 Cosell Plus, LLC. All Rights Reserved. |
| 4 | # |
| 5 | # DISCLAIMER & TERMS OF USE: |
| 6 | # This IaC blueprint is generated by CompareCloudCosts (CCC) for educational, |
| 7 | # planning, and directional architectural purposes. Provided "AS IS" without |
| 8 | # warranty of any kind, express or implied. Cosell Plus, LLC assumes no |
| 9 | # liability for operational costs, misconfigurations, or service interruptions. |
| 10 | # Always review and validate security, IAM, and compliance parameters before |
| 11 | # deploying to production environment. |
| 12 | # ============================================================================== |
| 13 | # |
| 14 | # ------------------------------------------------------------------------------ |
| 15 | # IDENTITY & CREDENTIAL PLACEHOLDERS (CLI & DEVOPS CI/CD PIPELINE) |
| 16 | # ------------------------------------------------------------------------------ |
| 17 | # Steps to execute this blueprint using Terraform: |
| 18 | # 1. Save this file as main.tf |
| 19 | # 2. Set provider authentication credentials: |
| 20 | # |
| 21 | # For AWS Local CLI Execution: |
| 22 | # export AWS_ACCESS_KEY_ID="<YOUR_AWS_ACCESS_KEY_ID>" |
| 23 | # export AWS_SECRET_ACCESS_KEY="<YOUR_AWS_SECRET_ACCESS_KEY>" |
| 24 | # export AWS_REGION="<REGION>" |
| 25 | # |
| 26 | # For AWS DevOps CI/CD Pipeline (GitHub Actions / GitLab CI / Azure DevOps): |
| 27 | # Recommended: Use AWS OpenID Connect (OIDC) Role Assumption: |
| 28 | # - role-to-assume: "arn:aws:iam::123456789012:role/GitHubActionsDeployerRole" |
| 29 | # - aws-region: "<REGION>" |
| 30 | # |
| 31 | # 3. Initialize and apply: |
| 32 | # $ terraform init |
| 33 | # $ terraform plan |
| 34 | # $ terraform apply |
| 35 | # ------------------------------------------------------------------------------ |
| 36 | |
| 37 | # ------------------------------------------------------------------------------ |
| 38 | # PROVIDER CONFIGURATION (TERRAFORM) |
| 39 | # ------------------------------------------------------------------------------ |
| 40 | 🔑 terraform { |
| 41 | required_version = ">= 1.5.0" |
| 42 | required_providers { |
| 43 | aws = { |
| 44 | source = "hashicorp/aws" |
| 45 | version = "~> 5.0" |
| 46 | } |
| 47 | } |
| 48 | } |
| 49 | |
| 50 | 🔑 provider "aws" { |
| 51 | region = var.aws_region |
| 52 | |
| 53 | default_tags { |
| 54 | tags = { |
| 55 | ManagedBy = "Terraform" |
| 56 | Environment = var.environment |
| 57 | Workload = var.workload_id |
| 58 | Vendor = "Cosell Plus LLC Blueprint" |
| 59 | } |
| 60 | } |
| 61 | } |
| 62 | |
| 63 | 🔑 variable "aws_region" { |
| 64 | type = string |
| 65 | default = "us-east-1" |
| 66 | description = "Target AWS Deployment Region" |
| 67 | } |
| 68 | |
| 69 | 🔑 variable "environment" { |
| 70 | type = string |
| 71 | default = "production" |
| 72 | description = "Deployment environment (e.g. dev, staging, production)" |
| 73 | } |
| 74 | |
| 75 | 🔑 variable "workload_id" { |
| 76 | type = string |
| 77 | default = "workload-blueprint" |
| 78 | description = "Identifier tag for the workload" |
| 79 | } |
| 80 | |
| 81 | # ------------------------------------------------------------------------------ |
| 82 | # WORKLOAD COMPONENT RESOURCES (RAG AI KNOWLEDGE BASE) |
| 83 | # ------------------------------------------------------------------------------ |
| 84 | # Component: Document Storage |
| 85 | 🔑 resource "aws_s3_bucket" "document_storage" { |
| 86 | bucket_prefix = "ccc-document_storage-" |
| 87 | force_destroy = false |
| 88 | } |
| 89 | |
| 90 | 🔑 resource "aws_s3_bucket_server_side_encryption_configuration" "document_storage_enc" { |
| 91 | bucket = aws_s3_bucket.document_storage.id |
| 92 | rule { |
| 93 | apply_server_side_encryption_by_default { |
| 94 | sse_algorithm = "AES256" |
| 95 | } |
| 96 | } |
| 97 | } |
| 98 | |
| 99 | |
| 100 | |
| 101 | # Component: API & Orchestration Compute (Serverless compute serving the retrieval/generation API) |
| 102 | 🔑 resource "aws_custom_🔑 resource" "api_compute" { |
| 103 | # Add required parameters for API & Orchestration Compute |
| 104 | } |
| 105 | |
| 106 | # Component: Embeddings Model (Embeds incoming queries and ingested documents) |
| 107 | 🔑 resource "aws_custom_🔑 resource" "embeddings" { |
| 108 | # Add required parameters for Embeddings Model |
| 109 | } |
| 110 | |
| 111 | # Component: Embedding / Metadata Store (Indexes embeddings and document metadata) |
| 112 | 🔑 resource "aws_custom_🔑 resource" "metadata_store" { |
| 113 | # Add required parameters for Embedding / Metadata Store |
| 114 | } |
| 115 | |
| 116 | # Component: RAG Pipeline Orchestration (Serverless compute & message routing that coordinates retrieval and prompt assembly) |
| 117 | 🔑 resource "aws_custom_🔑 resource" "orchestration" { |
| 118 | # Add required parameters for RAG Pipeline Orchestration |
| 119 | } |
| 120 | |
| 121 | # Component: Inference Endpoint (Generates responses from retrieved context) |
| 122 | 🔑 resource "aws_custom_🔑 resource" "inference" { |
| 123 | # Add required parameters for Inference Endpoint |
| 124 | } |
| 125 | |
| 126 | # Component: Backup Storage |
| 127 | 🔑 resource "aws_s3_bucket" "backup_storage" { |
| 128 | bucket_prefix = "ccc-backup_storage-" |
| 129 | force_destroy = false |
| 130 | } |
| 131 | |
| 132 | 🔑 resource "aws_s3_bucket_server_side_encryption_configuration" "backup_storage_enc" { |
| 133 | bucket = aws_s3_bucket.backup_storage.id |
| 134 | rule { |
| 135 | apply_server_side_encryption_by_default { |
| 136 | sse_algorithm = "AES256" |
| 137 | } |
| 138 | } |
| 139 | } |
| 140 | |
| 141 | |
| 142 | |
| 143 | |
| 144 | # ------------------------------------------------------------------------------ |
| 145 | # OUTPUTS |
| 146 | # ------------------------------------------------------------------------------ |
| 147 | 🔑 output "blueprint_summary" { |
| 148 | value = { |
| 149 | workload_id = "rag-ai-knowledge-base" |
| 150 | 🔑 provider = "aws" |
| 151 | region = "us-east-1" |
| 152 | components = 7 |
| 153 | priorities = { |
| 154 | capacity = "medium" |
| 155 | performance = "medium" |
| 156 | reliability = "medium" |
| 157 | security = "medium" |
| 158 | } |
| 159 | } |
| 160 | } |
| 161 |