AWS vs Vercel: where should you actually deploy a Next.js app?
Vercel sells you time. AWS sells you control. The right answer depends on which of the two your team is short of.
Infrastructure as code defines your cloud resources in version-controlled files so environments are reproducible and reviewable. With Terraform the central concept is state — a record mapping your configuration to real resources — which must be stored remotely with locking, never committed, and never edited by hand.
State is a JSON file mapping resources in your configuration to real infrastructure identifiers, and it is what Terraform diffs against to produce a plan.
terraform {
backend "s3" {
bucket = "acme-tfstate"
key = "production/web/terraform.tfstate"
region = "ap-south-1"
dynamodb_table = "tfstate-locks" # prevents concurrent applies
encrypt = true
}
}infra/
modules/
network/ # reusable, no environment-specific values
web-service/
database/
environments/
staging/
main.tf # composes modules with staging variables
terraform.tfvars
production/
main.tf
terraform.tfvarsDrift is the gap between your configuration and reality — someone changed a setting in the console during an incident and never told the code. The next apply either reverts their fix or fails confusingly.
Terraform (or OpenTofu) has the broadest provider ecosystem and the largest hiring pool. Pulumi suits teams who want real programming languages. CloudFormation and CDK make sense for AWS-only shops wanting native integration.
Generally no. Use it for infrastructure that changes rarely and a separate pipeline for application deploys that happen many times a day. Mixing the two makes both slower and riskier.
Reference them from a secret manager rather than passing them as variables. Anything passed in ends up in state, which is why state must be treated as sensitive regardless.
An open-source fork of Terraform created after its licence change, largely compatible and community-governed. It is a reasonable choice if licensing matters to your organisation.
ROVQIX Engineering
Engineering team, ROVQIX
The ROVQIX engineering team builds and maintains web platforms, APIs and infrastructure for clients across SaaS, ecommerce and enterprise. These notes come out of real production work — deploys, incidents, migrations and audits.
ROVQIXdesigns and builds production web platforms — Next.js front ends, Node.js APIs and the infrastructure behind them. Tell us what you're building and we'll scope it with you.
Vercel sells you time. AWS sells you control. The right answer depends on which of the two your team is short of.
The question is not whether a secret will leak. It is whether you will know, and how long it takes to make the leaked one useless.
A pipeline that takes 25 minutes and fails randomly does not improve quality. It teaches the team to merge on red.
No spam. Just the occasional case study and craft breakdown.