System Platform reference architectures
- Last UpdatedAug 14, 2026
- 3 minute read
Sample architecture
The following architectural diagram shows a sample deployment of AVEVA System Platform with AVEVA Manufacturing Execution System (MES) on AWS, and the paths through which authorized users would interact with it. The System Platform installation includes a redundant pair of AOS servers which also function as redundant visualization and MES nodes, a GR node, Historian node, and an MQTT broker as the data source. All System Platform nodes are running on AWS in a private subnet, while an application load balancer is running on a public subnet, which is also running on AWS.
The following architectural diagram shows a sample deployment of AVEVA System Platform with MES on AWS, and the paths through which a System Platform administrator accesses the environment to install and configure the application. The System Platform installation includes a redundant pair of AOS servers which also function as redundant visualization and MES nodes, a GR node, Historian node, and an MQTT broker as the data source. All System Platform nodes are running on AWS in a private subnet, while an application load balancer is running on a public subnet, which is also running on AWS.

-
System Platform Administrator(s) can establish secure connections to AVEVA System Platform and MES on AWS from any remote location through the EC2 Instance Connect Endpoint. This secure link enables administrators to perform essential installation and configuration tasks for multiple components, including the Domain Controller, Galaxy Repository (GR), Historian, Operations Management Interface (OMI), MES, and Application Object Server (AOS) running on various EC2 instances.
-
The GR Node is the central configuration database, built on Microsoft SQL Server. It stores all object definitions and project configuration in a database known as a Galaxy. An Integrated Development Environment (IDE) is typically also installed on the GR node, but these can be installed on other machines as well.
-
The Historian Node leverages Microsoft SQL Server to run the AVEVA Historian software. It stores all historical process and alarm data and provides history for trending, reporting, and analysis to System Platform client applications such as AVEVA OMI, Historian Client, and InTouch HMI.
-
In a redundant system, a redundant AOS pair consists of two AOS platforms. Primary AppEngines are deployed to one platform, with corresponding backup AppEngines on the other. Multiple primary engines can be distributed across both platforms to balance load, with each corresponding backup on the opposite node. This configuration provides the first level of redundancy, ensuring continuous operation and high system availability.
-
Increased resiliency can be achieved by deploying System Platform on a secondary availability zone (AZ) and configuring the system to fail over to the secondary AZ.
Authorized users paths
The following diagram shows the paths through which authorized System Platform and MES users would access the same environment on AWS.

-
Field or on-premises systems are connected to AVEVA System Platform on AWS via AWS Direct Connect. AWS Direct Connect provides a dedicated network connection between an on-premises network and AWS. This ensures a protected link between the local infrastructure and the cloud-based system. Other secure connection options customers can use are VPN and encrypted MQTT connection.
-
A MQTT broker, situated in a private subnet, is exclusively accessible through the secure connection. This configuration enables safe MQTT communication between the field devices and AVEVA System Platform on AWS, maintaining data integrity and confidentiality.
-
AVEVA's Application Object Server (AOS) Node is a runtime platform that hosts AppEngines and deployed object instances. These instances represent a real-time, hierarchical model of the physical site (devices, equipment, etc) and provides real-time data to clients such as Operations Management Interface (OMI), InTouch Human Machine Interface (HMI) and MES. It also hosts services like communication drivers, System Management servers, and OMI web servers, as well as run clients, Historian Client, diagnostics tools, logger, and System Monitor.
-
The AWS Application Load Balancer (ALB) enables secure access to System Platform on AWS for users and operators. Beyond ensuring secure connectivity, the ALB actively monitors and balances network traffic, resulting in optimized performance and enhanced user experience.
-
In the event of a failure, ALB automatically routes traffic to a healthy EC2 instance running AOS, OMI, and MES.