← all case studies

Rose Digital · New York Lottery

Production Platform with 100+ Lambda Functions

A high-traffic public app was running on 100+ Lambdas with no domain boundaries and deploy risk on every release.

Situation

The New York Lottery mobile and web apps ran on a serverless backend with more than 100 Lambda functions covering SSO, administration, games, retailers, ticket scanning, notifications, and content management. As traffic and features grew, the architecture became harder to maintain and extend.

Risk or constraint

Every release touched shared infrastructure with unclear blast radius. Cold starts degraded user-facing latency. Inconsistent patterns across functions meant onboarding a new engineer required weeks of archaeology, not days of documentation.

Diagnosis

This wasn't a 'too much serverless' problem, it was a boundaries problem. Functions were grouped by history, not domain. Dependencies were bundled monolithically, inflating cold starts. IAM was wider than any single function needed because nobody had mapped least privilege per boundary.

Work completed

  • Mapped 100+ Lambdas into bounded domains: SSO, Admin, Games, Retailers, Ticket Scan, Notifications, CMS
  • Owned and restructured a 3,000+ line Serverless Framework IaC with nested split-stacks to stay under CloudFormation limits
  • Applied per-function least-privilege IAM instead of shared execution roles
  • Introduced layered dependencies to shrink deployment packages and reduce cold-start duration
  • Established deploy patterns so domain teams could ship without cross-domain regressions

Measurable result

100+
Lambdas across bounded domains
Split-stacks
Nested stacks under CloudFormation limits
Cold starts
Reduced via layered dependencies

Architecture or technologies

  • Node.js
  • AWS Lambda
  • API Gateway
  • Serverless Framework
  • DynamoDB
  • Redis
  • CloudFormation
  • IAM

What I would improve next

  • Migrate high-traffic functions to provisioned concurrency with cost guardrails
  • Centralized observability dashboard per domain with SLO-based alarms
  • Gradual shift from Serverless Framework to CDK or Terraform where stack limits remain a constraint

Request an architecture audit

If this pattern matches what you're seeing, describe your situation, not a job spec. I'll reply within 48 hours with an honest read.