Managed Drupal hosting,
on your own AWS account

We build and run a single-tenant Drupal stack inside the AWS account you own. You keep the account, the AWS bill and the compliance posture. We handle the architecture, the patching and the on-call. The stack is standard Drupal on standard AWS services, with no vendor lock-in.

A 30-minute technical call with the engineers who would run your infrastructure.

AWS Advanced Tier Services Partner
AWS Advanced Tier Partner
A managed partner, not a reseller. We run it day to day.
99.95%
Guaranteed uptime
On the production tier, backed by 24/7 on-call
Multi-AZ
Built-in redundancy
Compute, database and cache run across multiple data centers
Since 2012
Drupal for institutions
Including OBH, CBCNY and United Way
The landscape

Three ways teams run Drupal today

Production Drupal usually runs one of these three ways. Each one trades something away.

A managed platform

Acquia, Pantheon or Platform.sh run Drupal for you, on infrastructure they own. The bill arrives as one number, your site shares hardware with other tenants, and parts of it get built against their platform.

With our solutionThe same day-to-day operations, except the infrastructure is billed to you by AWS at their own price, rather than resold to you at a margin.

Your own servers

On-premises hardware, in-house virtual machines or a traditional host. Costs are predictable and you control everything, but capacity is fixed, patching is yours, and a hardware failure means downtime measured in hours rather than minutes.

With our solutionCapacity that scales with demand, redundancy across multiple data centers, and a documented recovery procedure maintained by our team.

Build it on AWS yourself

The right platform, but the Drupal-specific parts are the hard parts: cache configuration, safe deploys, rollback, egress and CDN invalidation. Your team is also the one that has to respond when the site goes down at night.

With our solutionThe same AWS account and the same control, with the architecture, runbooks and after-hours response handled by our team.

A managed Drupal product

What we run for you

The whole stack is defined as infrastructure-as-code and deployed into your account: managed containers for Drupal, a managed database and cache, shared file storage and a CDN at the edge. The same definition builds both tiers, so what runs for you is what we have already tested. You hold the account and the AWS contract. We hold the architecture, the runbooks and the day-to-day operations.

We are an AWS Advanced Tier Services Partner, which gives you access to AWS-funded migration programs and partner benefits that are not available buying AWS direct. The core of this stack has been running in production on high-traffic customer sites for years before it was packaged as a product.

You own
  • The AWS account & contract
  • Your AWS discounts, credits & commitments
  • The compliance posture
  • The right to walk away
We run
  • The architecture & IaC
  • Runbooks & 24/7 on-call
  • Patching & capacity planning
  • Backup verification & DR

Open to you throughout, and yours to keep if you leave.

Your AWS Account Managed by Cheppers
Edge
CloudFront Cloudflare (opt.) Route 53
Ingress
ALB WAF ACM TLS
Compute
ECS Fargate FrankenPHP Autoscaling
State
Aurora MySQL Valkey EFS S3
Egress
NAT VPC endpoints
Observe
CloudWatch SNS alerts Backup vault
What's different

Six differences from a traditional platform

Each of these is a property of how the service is built, not a service level we promise. Each one also comes up in procurement.

Your own AWS account

The stack is deployed into an account that you own and can audit at any time. Your existing AWS discounts, credits and enterprise agreement all continue to apply.

No vendor lock-in

We use the same contributed modules the rest of the Drupal community uses. There is no Cheppers-specific cache layer and no custom deploy hook, so the codebase runs anywhere Drupal runs.

Two separate bills

AWS invoices you for infrastructure at their list price or your negotiated rate, and we invoice you separately for operations. Prefer one invoice? We can bill both together.

Single-tenant isolation

Every customer gets their own infrastructure, so there is no shared capacity to contend for. For regulated workloads this is usually cheaper than the dedicated tier of a shared platform.

Runbooks and recovery

Staged deployments and a documented recovery path for failed updates, on both tiers. Large adds redundancy across multiple data centers, 24/7 on-call and a 99.95% uptime SLA.

AWS Advanced Tier Partner

We are co-sell eligible, so AWS can fund part of a qualifying migration. Partner programs and credits of this kind are not available to customers buying AWS directly.

Two tiers

Which tier fits your site

Small and Large are the same architecture. They differ in redundancy, capacity and how often we do maintenance. If you are between the two, the Assessment will say which one.

Compare

Specifications

Side by side, top to bottom. Pick what fits.

Tier 1

Small

Internal tools, brochureware, campaign sites, archival content, dev / staging.

Tier 2

Large

Production sites where downtime is a business problem.

Recommended
Availability architecture
SmallSingle-AZ
LargeMulti-AZ HA across every layer
Support (base fee)
SmallOffice-hours infrastructure support
LargeOffice-hours infrastructure support
24/7 on-call
SmallOn-call available as add-on
LargeIncluded 99.95% uptime SLA
Compute
Small1 Fargate task · 1 vCPU / 2 GB
Large2+ tasks autoscaling · 2 vCPU / 4 GB
Database
SmallAurora single instance
LargeAurora writer + reader (multi-AZ)
Cache
SmallSingle ElastiCache Valkey (Redis) node
LargeElastiCache Valkey (Redis) multi-AZ with replica failover
Search
SmallDatabase search · Solr on ECS as add-on
LargeOpenSearch managed cluster
Environments
SmallProduction only
LargeDev + staging + prod
Account model
SmallSingle customer account
LargeAWS Landing Zone · multi-account
Maintenance window
SmallMonthly cycle · 3-hour cap
LargeMonthly cycle · 6-hour cap
CI/CD pipeline
SmallIncluded build & deploy pipeline to ECS
LargeIncluded build & deploy pipeline across dev, staging & prod
Infrastructure maintenance is included. Drupal application maintenance covering core, contrib and security advisories is a separately contracted support engagement. Not sure which tier? Book a Drupal Assessment
How it works

From first call to live in your AWS account

Four steps. Each one ends in something written down, so you can stop after any of them.

  1. Step 01

    Discovery call

    30 min. Whether this fits, roughly which tier, and what it would cost against what you pay now.

  2. Step 02

    Drupal Assessment

    A fixed-fee written report with a go or no-go recommendation, and a remediation quote if the site needs work first.

    Required before migration
  3. Step 03

    Onboard into your AWS

    We deploy the full stack into the account you control. Cloud infrastructure ready in hours to a day for a healthy site.

  4. Step 04

    Migrate & go live

    Content cut-over, DNS swap and monitoring switched on, scheduled around your traffic. We run it from there.

Drupal Assessment

Find out what shape
the site is in.

Outdated cores, abandoned contrib modules and broken dependencies are what turn a fixed-price migration into an open-ended one. They are also invisible until somebody goes looking.

The Assessment is a short, fixed-fee review of the codebase and the infrastructure around it. You get a written report, findings ranked by severity, and one of three verdicts: ready to migrate, minor fixes needed, or high risk.

01

Code & dependencies

Drupal core and PHP version currency, contrib module health, static analysis (phpstan, phpcs), custom code review.

02

Infrastructure readiness

Cache configuration, secrets hygiene, search setup, .htaccess rules, PHP execution limits, third-party integrations.

03

Performance & scale

Current traffic, cache hit rate, response time, slow queries, known bottlenecks.

Book a Drupal Assessment

Buy it on its own, or as the required first step before migrating to our hosting.

Commercial model

Packages and pricing

Two numbers, and you can check both. AWS bills you for infrastructure, we bill a flat monthly fee for operations.

Small

Single-AZ

Internal tools, brochureware, campaign sites, archival content, dev / staging.

Typical total
$515–555per month
$490–535 with 1-year AWS commitments.
AWS infrastructure $160–200 Billed by AWS, on demand
Cheppers operations $355 Billed by us, flat. 4 engineer hours a month including CI/CD upkeep, $100/hr after that.
Included
  • Onboarding included · no setup cost
  • Office-hours infrastructure support
  • Monthly maintenance cycle (3-hour cap)
  • Backup verification & restore tests
  • 24/7 on-call available as add-on
  • CI/CD build & deploy pipeline to ECS
Talk to us about Small

Large

Multi-AZ HA

Production sites where downtime costs money, and anything carrying an uptime or compliance commitment.

Typical total
$2,070–2,230per month
$1,815–2,035 with 1-year AWS commitments.
AWS infrastructure $1,260–1,420 Billed by AWS, on demand
Cheppers operations $810 Billed by us, flat. 9 engineer hours a month including CI/CD upkeep, $100/hr after that.
Included
  • Onboarding included · no setup cost
  • Multi-AZ HA across compute, DB, cache
  • Dev + staging + prod environments
  • Monthly maintenance cycle (6-hour cap)
  • 24/7 on-call and 99.95% uptime SLA included
  • CI/CD build & deploy pipeline across dev, staging & prod
Talk to us about Large
Based on public AWS pricing. Your actual cost varies by region and by the AWS commitments you already hold. The Drupal Assessment is a fixed-fee engagement quoted at pre-sales.
Book a discovery call
Compliance & security

Your account, your compliance posture

The workload sits in your account, so AWS's certifications apply to it directly and your security team keeps its own IAM, CloudTrail and audit history. There is no third party to request evidence from during an audit. Single-tenant isolation also removes the shared-hosting questions that usually stall a security review.

ISO 27001
Information security management, certified by AWS.
SOC 1 / 2 / 3
Service organization controls, via AWS Artifact.
PCI DSS
Card data, on services already in PCI DSS scope.
HIPAA
Healthcare data, on BAA-eligible AWS services.
HECVAT
Higher-ed procurement, done at pre-sales.
GDPR-ready
EU data protection, in the region you choose.
Sectors

Organizations we run Drupal for

Four kinds of organization that make up most of the estates we operate today.

Media & publishing

High-traffic editorial sites and large content estates, where pages change constantly and cache behavior decides the hosting bill.

Higher education

Large multisite estates and Drupal installs that have been in place for a decade or more. We complete the HECVAT and design to FERPA expectations.

Nonprofits

Mission-driven organizations on fixed budgets, where the infrastructure has to outlast the people who commissioned it and survive a re-org.

Digital agencies

Agencies hosting Drupal for clients, who need infrastructure costs they can quote accurately and margins they can predict.

Customers

Running in production today

The architecture described above is the one currently running for OBH, CBCNY and United Way.

“
The Cheppers staff are second to none. They are proficient, accessible and always willing to help us meet our goals. They deliver ahead of schedule and under budget, and often suggest a more efficient approach. We remain very pleased with our partnership.
Karen Adams-Snyder
Karen Adams-Snyder
United Way Worldwide
FAQ

Common questions

If yours is not here, ask it on the call. You will be talking to the people who run the infrastructure.

Yes, and we complete it during pre-sales so it is ready when your RFP needs it. Because the stack runs on standard AWS services in your own account, most answers come from AWS's published compliance posture plus our operational controls.

Yes. Start with the Assessment, which sorts the site into ready to migrate, minor fixes needed, or high risk, and attaches a remediation quote. Drupal 7 sites usually land in one of the last two, and the difference between them is a large difference in budget.

Use the one you have. For Large we recommend an AWS Landing Zone with a multi-account structure, which is AWS's own guidance for production workloads. For Small, a single account is fine.

The infrastructure side takes hours to a day for a healthy site. The Drupal side takes longer. Both platforms ship modules that only work on their own infrastructure, such as acquia_purge and pantheon_advanced_page_cache, plus deploy hooks that have no equivalent elsewhere. The Assessment identifies and prices that work before you commit.

Yes, on every migration. Outdated cores, abandoned contrib modules and broken dependencies are the most common cause of a migration overrunning, and none of them are visible from outside the codebase. The Assessment is fixed-fee, takes days not weeks, and ends in a written report.

Everything at the infrastructure layer: AWS service updates, container base image refreshes, NAT patching, CloudWatch alarm review, capacity planning and backup verification. Drupal itself is not included. Core, contrib and security advisories are a separate support engagement, which you can buy from us or keep in-house.

Small includes office-hours infrastructure support, with 24/7 on-call available as an add-on. Large includes 24/7 on-call and a contractual 99.95% uptime SLA in the monthly fee.

On Large they are included: 24/7 on-call and a contractual 99.95% uptime SLA, excluding scheduled maintenance windows. On Small, on-call is available as an add-on and is quoted at pre-sales.

Small runs in a single Availability Zone, so an AZ outage could take the site down for hours. That is the trade Small exists to make, and it suits internal tools, dev and staging, campaign sites and brochureware. If the site cannot absorb an AZ-level event, it belongs on Large.

You pay AWS directly by default, which is how you keep your discounts and stay in control of your commitments. If your finance team needs a single invoice, we can resell the AWS portion and itemize your usage line by line.

Yes, and there is nothing to extract. The infrastructure is already in your account and the Terraform is yours. The Drupal codebase uses contributed modules only, so it runs on any other host without modification.

Yes, on both tiers. Traditional Drupal multisite adds onboarding work, and how much depends on how the sites share configuration, so we scope it per customer.

Small includes database search, which is enough for most sites of that size, with Solr on ECS available as an add-on. Large includes a managed OpenSearch cluster. The Assessment looks at your content volume and query patterns and confirms which one you need.

CloudFront by default, since it integrates most closely with the rest of the stack. Content-heavy sites that need fast tag-based purging often do better on Cloudflare. Existing Fastly or Akamai contracts can be kept and plugged in.

Talk to us

Talk to the engineers who would run it

Thirty minutes is usually enough to tell whether this is a fit. Bring your current bill and your traffic numbers and we can size it on the call. If it goes further, the next step is the Assessment.

We are an AWS Partner specialized in Drupal development, cloud-native solutions, and UX/UI design. Our mission is to solve our customers’ complex digital challenges by leveraging the latest technologies, with a strong focus on security, scalability, and user experience. As a team of experienced and passionate professionals, we deliver innovative and robust solutions through exciting projects that push the boundaries of what’s possible in the cloud.
AWS logos
Drupal book

Unlock the future of Drupal with AI

Download for free!