Kaizen Infrastructure Modules
Kaizen apps ship on a shared set of twelve AWS building blocks.
They take an app to a private, encrypted deployment in commercial AWS or AWS GovCloud from one codebase. Fifteen Kaizen apps run on them today, including federal workloads staged in Kaizen's own GovCloud account.
module "alb" { source = "git::ssh://git@github.com/the-kaizen-labs/terraform-modules.git//alb?ref=v1.7.0" app_name = local.app_name vpc_id = module.networking.vpc_id public_subnet_ids = module.networking.public_subnet_ids certificate_arn = local.certificate_arn container_port = 3000 ssl_policy = "ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04" access_logs_bucket = module.s3_logs.bucket_name tags = local.tags}Where to start
Each guide links to the module pages for detail.
Federal controls are written into the modules
The module code cites FedRAMP control IDs next to the settings that implement them. Federal stacks turn the stricter settings on; commercial stacks keep the defaults.
How to read this site
- The sidebar on every docs page lists the guides first, then the module catalog grouped by layer, then reference pages on examples and versioning.
- Press Cmd K or Ctrl K to search page titles, headings, and module input and output names.
- Every module page follows the same order: why it matters, when to use it, what it creates, secure defaults, commercial and GovCloud settings, how it connects, inputs, outputs, and the apps that use it.
What the pills mean
- GovCloudWorks in AWS GovCloud
- Runs unmodified in the aws-us-gov partition. ARNs are partition aware, or the module builds no partition specific ARNs.
- FIPSFIPS 140-3 option
- Exposes or enforces a FIPS 140-3 setting, such as a FIPS TLS policy or a FIPS crypto policy.
- CMKCustomer managed key
- Accepts a customer managed KMS key, so the agency or app team controls the encryption key (FedRAMP SC-13).
How the modules fit together
Each row is one layer of a deployed app. Click a box to open that module's page.
Every module
The same catalog as the sidebar, with the one line summary and the number of apps that use each module.
Edge
Where public traffic enters. TLS ends at the load balancer and a web application firewall screens requests first.
Compute
Where the app runs. Containers on AWS Fargate in private subnets, built from images in a scanned registry.
Data
Where the app keeps state. Postgres, Redis, and S3, each encrypted at rest and reachable only from the app.
Network
The private network every other module sits in, plus a locked down way for operators to reach it.
Observability
How the team sees what the app and its users are doing, from server logs to browser sessions.
15 Kaizen apps use these modules
Each app below pins at least one module to a release tag. ginkgo and saplings run in Kaizen's own AWS GovCloud account.
- BidBuddy
- castle
- dust
- evergreen
- forager
- ginkgoGovCloud
- juniper
- magnolia
- meridian
- oak
- poppy
- saplingsGovCloud
- skeddy
- taproot
- test-health-dashboard