A sales-tax collection and agent-management system for a national government. Tax agents are registered, grouped and managed; businesses' sales-tax reports are filed and analysed; penalties are calculated and reported; and addresses are resolved against regional administrative data.
Freelance, Aug 2024 to Dec 2024. I built the backend, the API and the AWS infrastructure, working alongside the client's own team, which built the frontend.
Infrastructure as code
Everything is defined in AWS CDK (TypeScript), split into separate stacks for network, authentication, audit, email, the application and the frontend's hosting. cdk-nag runs security checks against the stacks before they deploy.
Serverless API
API Gateway in front of AWS Lambda, described by an OpenAPI specification, with custom authorizers on every route. DynamoDB stores agents, reports, penalties and activity; S3 takes bulk file uploads through presigned URLs, and bucket events trigger processing.
Access control and audit
Amazon Cognito for users and groups, and Amazon Verified Permissions for role-based authorization, so what each user may do is policy, not scattered code. Every significant action is written to an audit activity log. Secrets live in AWS Secrets Manager.
Notifications
Email through Amazon SES and SendGrid, and SMS and WhatsApp through Twilio.
Delivery
GitHub Actions for pull-request checks, CI and continuous deployment. Input validated with Joi, tested with Jest.
Serverless sales-tax collection and agent-management backend for a national government: AWS CDK, Lambda, API Gateway, DynamoDB, Cognito and Verified Permissions.