
Product
Introducing Socket Firewall Enterprise: Flexible, Configurable Protection for Modern Package Ecosystems
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.
@exogee/graphweaver-cdk
Advanced tools
This package simplifies the deployment of your Graphweaver GraphQL applications on AWS, leveraging the AWS CDK (Cloud Development Kit). It streamlines infrastructure provisioning and configuration for your GraphQL backend and admin UI.
Install the package:
pnpm install @exogee/graphweaver-cdk
Create Your CDK App:
import { App, Stack } from 'aws-cdk-lib';
import { GraphweaverApp } from '@exogee/graphweaver-cdk';
import { Vpc, SecurityGroup, Port} from 'aws-cdk-lib/aws-ec2';
const app = new App();
const stack = new Stack(app, 'GraphweaverStack');
const vpc = new Vpc(stack, 'GraphweaverVpc');
// Create Security Group for the Database
const dbSecurityGroup = new SecurityGroup(this, 'DbSecurityGroup', {
vpc,
description: 'Security group for the database',
});
// Security Group for GraphQL Lambda
const graphqlSecurityGroup = new SecurityGroup(this, 'GraphqlSecurityGroup', {
vpc,
description: 'Security group for GraphQL Lambda',
});
// Allow inbound traffic only from the GraphQL Lambda
dbSecurityGroup.addIngressRule(
graphqlSecurityGroup,
Port.tcp(5432),
'Allow access from Lambda to RDS instance'
);
// Create Security Group for the Secrets Manager endpoint
const secretManagerSecurityGroup = new SecurityGroup(this, 'SecretsManagerSecurityGroup', {
vpc: this.vpc,
description: 'Security group for the Secrets Manager endpoint',
});
// Allow inbound traffic only from the GraphQL Lambda
secretManagerSecurityGroup.addIngressRule(
this.graphqlSecurityGroup,
Port.tcp(443),
'Allow access from Lambda to Secrets Manager endpoint'
);
// Add VPC endpoint for Secrets Manager
this.vpc.addInterfaceEndpoint('vpc-secrets-manager-interface-endpoint', {
service: ec2.InterfaceVpcEndpointAwsService.SECRETS_MANAGER,
privateDnsEnabled: true,
securityGroups: [secretManagerSecurityGroup],
});
const config: GraphweaverAppConfig = {
name: 'my-graphweaver-app',
database: { /* ... your database config ... */ },
adminUI: { /* ... your admin UI config ... */ },
api: { /* ... your API config ... */ }
network: {
vpc,
graphqlSecurityGroup,
dbSecurityGroup
}
};
new GraphweaverApp(stack, 'GraphweaverApp', config);
Modify the GraphweaverAppConfig object to match your application's requirements.
Provide database credentials, certificates, domain names, environment variables, and other relevant settings.
cdk deploy
FAQs
Deploy Graphweaver to AWS
We found that @exogee/graphweaver-cdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Product
Socket Firewall Enterprise is now available with flexible deployment, configurable policies, and expanded language support.

Security News
Open source dashboard CNAPulse tracks CVE Numbering Authorities’ publishing activity, highlighting trends and transparency across the CVE ecosystem.

Product
Detect malware, unsafe data flows, and license issues in GitHub Actions with Socket’s new workflow scanning support.