Performance of AWS RDS <-> Wireguard bastion <-> Fly Private Networking

I’m trying to decide if I should be deploying my Hasura instances (and possibly Postgres read replicas) via fly or via AWS.

I’d personally prefer fly, but then I need to sort out how fly gets access to my AWS VPC where my RDS instance is running. Based on my research that seems like it’s via a Wireguard bastion host that I deploy in AWS.

Adding a hop like this seems like it would be a bottleneck (for both bandwidth and latency) as well as a single point of failure. But perhaps that’s not a problem in practice?

Does anyone here have real world experiences with a setup like this? How has it turned out?

This will work great in some AWS regions, and less great in others. In us-east-1, for example, it should work well because we’re <1ms away from AWS. In other regions latency is higher. The gateway is definitely another moving part to manage, though.

As much as I want you to use Fly for all the things, I would probably run Hasura on the same infrastructure as my database.

Well once postgres is dialed in (and closer to fully managed), I’ll experiment with moving this entire part of the stack over to fly. :slight_smile:

Soon! We’re working on Postgres full time now, there have been vast improvements in the last couple of weeks.