Kaizen

Start here

What the Kaizen Terraform modules are, who this site is for, and how to read a module page.

Kaizen apps ship on a shared set of twelve AWS building blocks. They take an app to a private, encrypted deployment in commercial AWS or AWS GovCloud from one codebase. Fifteen Kaizen apps run on them today, including federal workloads staged in Kaizen's own GovCloud account. Federal controls are written into the modules: customer managed encryption keys (FedRAMP SC-13), TLS only storage (SC-8), FIPS 140-3 TLS on the load balancer, and 90 day log retention (AU-11).

Each building block is a Terraform module: a folder of infrastructure code that an app calls with a few settings. The modules live in one repository, the-kaizen-labs/terraform-modules, and every app pins a release tag of it.

Pick your path

Investors and partners

See how the pieces fit, then how the same code meets federal requirements.

Engineers shipping an app

Point a coding agent at the playbook, then look up each module you use.

Security reviewers

Start with the control map, then check the exact settings and defaults.

Badges

GovCloudWorks in AWS GovCloud
Runs unmodified in the aws-us-gov partition. ARNs are partition aware, or the module builds no partition specific ARNs.
FIPSFIPS 140-3 option
Exposes or enforces a FIPS 140-3 setting, such as a FIPS TLS policy or a FIPS crypto policy.
CMKCustomer managed key
Accepts a customer managed KMS key, so the agency or app team controls the encryption key (FedRAMP SC-13).

Search everything

Press Cmd K (Ctrl K on Windows and Linux) to search every module, variable, and page on this site.

On this page