> ## Documentation Index
> Fetch the complete documentation index at: https://docs.springwinter.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Where the data lives

> Which resources are created in the customer AWS account, and what Springwinter reads without copying.

A project is pinned to one AWS region. Everything Springwinter creates for that project is created there. The application data, the logs, and the metrics stay in the account. Springwinter reads them when you open the page.

## What is created in the account

| Kind | Where it runs |
| - | - |
| Web server | ECS on Fargate, behind an Application Load Balancer, in the project VPC |
| Worker | ECS on Fargate in the same VPC, with no public URL and no load balancer |
| Static site | A private S3 bucket and a CloudFront distribution |
| Database | Aurora Serverless v2, PostgreSQL or MySQL, in the project VPC |
| Cache | ElastiCache Serverless, Valkey, in the project VPC |
| Logs and metrics | CloudWatch in the account |
| Images | ECR in the account, when the service is built from GitHub |

A project network is a VPC, subnets, and security groups for that project. Tasks that need to pull an image or reach the internet use a public IP on the task. There is not a separate NAT product in front of them.

The database security group allows the project service security group on the database port. It is written when the database is created and again when a server or worker is deployed.

The cache has no password. Clients in the project use TLS (`rediss://`). The endpoint is reachable from the project services, not published as a public website.

## What Springwinter reads, and does not copy

Opening Logs reads CloudWatch Logs for that resource. Opening Metrics reads CloudWatch for CPU, memory, requests, and errors. Opening Cost reads cost for the account. Those responses are shown to people in the organization. They are not indexed into a Springwinter search store, and they are not kept as a second copy of your logs.

A workflow run does keep the identifiers and the inputs of that deploy, as described on [Credentials](/security/credentials).

## Environment and images

Container environment lives on the task definition in your account. See [Credentials](/security/credentials).

A build from GitHub runs in CodeBuild in your account and pushes the image to ECR in your account. A service created from a public image does not create a CodeBuild project. Fargate pulls that image in the account. Registry passwords are not accepted.

## Reaching a private service

SQL, a cache, and a web server task can be reached with SSM port forwarding. An authenticated person opens a gateway in the project. Springwinter starts a Session Manager session in your account and returns a `session-manager-plugin` command. The gateway is a Fargate service in the project security group. Closing it scales that service to zero. The session is not a key Springwinter keeps.

## Previews

A preview is a second copy of a web server, worker, or static site, in the same account and the same project. It is not a second AWS account. A preview of a site gets its own CloudFront URL. A preview of a web server gets its own hostname when the project has one. SQL and caches do not have previews.

## When you delete

Deleting a resource starts teardown in your account. Deleting the project is refused while resources remain. An empty project teardown removes the leftover network and then marks the project deleted. Removing Springwinter's role does not, by itself, delete those AWS resources. They remain until you remove them.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.