Terraform for commercial AWS and AWS GovCloud

Kaizen Infrastructure Modules

Kaizen apps ship on a shared set of twelve AWS building blocks.

They take an app to a private, encrypted deployment in commercial AWS or AWS GovCloud from one codebase. Fifteen Kaizen apps run on them today, including federal workloads staged in Kaizen's own GovCloud account.

infra/main.tfHighlighted: the GovCloud settings
module "alb" {  source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//alb?ref=v1.7.0"   app_name          = local.app_name  vpc_id            = module.networking.vpc_id  public_subnet_ids = module.networking.public_subnet_ids  certificate_arn   = local.certificate_arn  container_port    = 3000   ssl_policy         = "ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04"  access_logs_bucket = module.s3_logs.bucket_name   tags = local.tags}
12Terraform modules
15Kaizen apps run on them
2AWS partitions, commercial and GovCloud
v1.7.0Latest release tag
Start here

Where to start

Each guide links to the module pages for detail.

Federal posture

Federal controls are written into the modules

The module code cites FedRAMP control IDs next to the settings that implement them. Federal stacks turn the stricter settings on; commercial stacks keep the defaults.

FedRAMP SC-13Customer managed encryption keysnetworking, ecr, ecs-service, rds-postgres, redis, and s3-bucket accept a KMS key the team controls. bastion requires one.
FedRAMP SC-8TLS only storages3-bucket can deny every request that skips TLS. Postgres and Redis refuse unencrypted connections by default.
FIPS 140-3FIPS TLS on the load balancerOne alb setting switches the HTTPS listener to a FIPS policy that exists in both partitions. openobserve uses it by default.
FedRAMP AU-1190 day log retentionVPC flow logs record all traffic and keep it for 90 days. openobserve keeps 90 days of logs.
See every control and the setting behind it

How to read this site

  • The sidebar on every docs page lists the guides first, then the module catalog grouped by layer, then reference pages on examples and versioning.
  • Press Cmd K or Ctrl K to search page titles, headings, and module input and output names.
  • Every module page follows the same order: why it matters, when to use it, what it creates, secure defaults, commercial and GovCloud settings, how it connects, inputs, outputs, and the apps that use it.

What the pills mean

GovCloudWorks in AWS GovCloud
Runs unmodified in the aws-us-gov partition. ARNs are partition aware, or the module builds no partition specific ARNs.
FIPSFIPS 140-3 option
Exposes or enforces a FIPS 140-3 setting, such as a FIPS TLS policy or a FIPS crypto policy.
CMKCustomer managed key
Accepts a customer managed KMS key, so the agency or app team controls the encryption key (FedRAMP SC-13).
The stack

How the modules fit together

Each row is one layer of a deployed app. Click a box to open that module's page.

Catalog

Every module

The same catalog as the sidebar, with the one line summary and the number of apps that use each module.

Where public traffic enters. TLS ends at the load balancer and a web application firewall screens requests first.

Where the app runs. Containers on AWS Fargate in private subnets, built from images in a scanned registry.

Where the app keeps state. Postgres, Redis, and S3, each encrypted at rest and reachable only from the app.

The private network every other module sits in, plus a locked down way for operators to reach it.

How the team sees what the app and its users are doing, from server logs to browser sessions.

In use

15 Kaizen apps use these modules

Each app below pins at least one module to a release tag. ginkgo and saplings run in Kaizen's own AWS GovCloud account.

  • BidBuddy
  • castle
  • dust
  • evergreen
  • forager
  • ginkgoGovCloud
  • juniper
  • magnolia
  • meridian
  • oak
  • poppy
  • saplingsGovCloud
  • skeddy
  • taproot
  • test-health-dashboard