01Secure Multi-AZ VPC Foundation
Networking, private access, observability and cost-aware egress
A reusable Terraform network foundation with public ingress subnets, private application subnets, isolated data subnets, controlled outbound routing, VPC Flow Logs, an S3 gateway endpoint and private Systems Manager endpoints.
TerraformAWS VPCSubnetsRoute TablesNAT Gateway
Evidencefmtinitvalidate
02Highly Available Three-Tier AWS Platform
HTTPS ingress, private compute, Auto Scaling and isolated PostgreSQL
A Terraform design for an HTTPS Application Load Balancer, private EC2 Auto Scaling application tier and private PostgreSQL RDS database tier distributed across two Availability Zones.
TerraformAmazon EC2Auto ScalingApplication Load BalancerAmazon RDS
Evidencefmtinitvalidate
03Private ECS Fargate Application Platform
Immutable delivery, private tasks, autoscaling and observable deployments
A Terraform platform for an ECS Fargate service behind an Application Load Balancer, with ECR image controls, private tasks, CloudWatch logs, Container Insights, rolling deployments and target-tracking autoscaling.
TerraformAmazon ECSAWS FargateAmazon ECRApplication Load Balancer
Evidencefmtinitvalidate
04Private Amazon EKS Platform Foundation
Private cluster access, managed nodes, KMS and controlled upgrades
A Terraform foundation for a private-endpoint Amazon EKS cluster with managed nodes, KMS envelope encryption, control-plane logging, core managed add-ons and controlled rolling node updates.
TerraformAmazon EKSKubernetesManaged Node GroupsAWS KMS
Evidencefmtinitvalidate
05Reliable Serverless Event-Driven Platform
Durable event buffering, retries, dead-letter handling and bounded concurrency
An event-driven Terraform design where S3 object-created events pass through EventBridge to an encrypted SQS queue, Lambda processes bounded batches, failed messages reach a DLQ and CloudWatch alarms notify through encrypted SNS.
TerraformAmazon S3Amazon EventBridgeAmazon SQSAWS Lambda
Evidencefmtinitvalidate
06IAM Governance and Cross-Account Access
Permission boundaries, explicit trust, MFA and access analysis
A Terraform IAM governance lab demonstrating a permission boundary, cross-account read-only role with MFA and an external ID, one-hour sessions, IAM Access Analyzer, a strict password policy and CloudTrail log-role preparation.
TerraformAWS IAMAWS STSPermission BoundariesMFA
Evidencefmtinitvalidate
07AWS Multi-Account Landing Zone Blueprint
Organizations, preventive guardrails and centralized audit logging
A safety-first Terraform blueprint for organizational units, an example regional Service Control Policy, centralized organization CloudTrail, KMS-encrypted versioned log storage and lifecycle retention around a Control Tower-managed landing zone.
TerraformAWS OrganizationsAWS Control TowerService Control PoliciesAWS CloudTrail
Evidencefmtinitvalidate