60
Cameras: recorded straight to AWS.
A live-dealer studio with no storage on site now records every camera to AWS over encrypted tunnels, with playback on managed desktops and tamper-proof evidence storage.
Live-dealer studio · Client name withheld under NDA
Cameras: recorded straight to AWS.
Encrypted IPsec tunnels: across two internet providers.
Video stored on site: by design.
A live-dealer studio runs about 60 cameras into network video recorders that have no disks of their own. The requirement was strict: nothing is stored on site, every frame is encrypted in transit, and the local internet providers must never see video or internal traffic.
We tested the heavier options first and chose the simplest one the recorders support natively.
Everything is Terraform: KMS keys, a private network with one NAT gateway, the Site-to-Site VPN (two customer gateways, four IPsec tunnels with IKEv2 and AES-256), one recording host per recorder, the WorkSpaces directory, storage, and monitoring.
The iSCSI timeouts were tuned for the lossy link so a short drop does not disconnect a recorder. Exported clips go to an S3 evidence bucket with Object Lock, encrypted with a customer-managed KMS key, with CloudTrail auditing and a CloudWatch dashboard for recording health.
The rollout plan was a pilot of 3 cameras for 72 hours, then all 60 for 72 hours, with no recording gaps as the pass criterion.

Video leaves the building encrypted and there is nothing on site to steal or tamper with. The risk team reviews footage from managed desktops, and evidence clips cannot be altered or deleted once stored. At about 1.6 TB a day with H.265, the AWS Pricing Calculator estimate for the setup was about $3,400 a month.
Terraform for every component, a runbook for the VPN and recorders, and the recording-health dashboard.
Planning something similar? Talk to an AWS partner in Armenia that has built it before.