Modules
All 12 modules, grouped by the layer of the stack they cover.
- GovCloudWorks in AWS GovCloud
- Runs unmodified in the aws-us-gov partition. ARNs are partition aware, or the module builds no partition specific ARNs.
- FIPSFIPS 140-3 option
- Exposes or enforces a FIPS 140-3 setting, such as a FIPS TLS policy or a FIPS crypto policy.
- CMKCustomer managed key
- Accepts a customer managed KMS key, so the agency or app team controls the encryption key (FedRAMP SC-13).
Edge
Where public traffic enters. TLS ends at the load balancer and a web application firewall screens requests first.
Compute
Where the app runs. Containers on AWS Fargate in private subnets, built from images in a scanned registry.
GovCloudECS Clusterecs-clusterAn ECS cluster with Container Insights, or a handle on a customer owned cluster.Used by 13 Kaizen appsGovCloudCMKECS Fargate Serviceecs-serviceRuns the app container on Fargate in private subnets with IAM, logs, and secrets.Used by 14 Kaizen appsGovCloudCMKContainer RegistryecrA private ECR repository that scans every pushed image and expires old ones.Used by 14 Kaizen apps
Data
Where the app keeps state. Postgres, Redis, and S3, each encrypted at rest and reachable only from the app.
GovCloudCMKRDS Postgresrds-postgresAn encrypted Postgres 17 instance in private subnets that only accepts TLS connections.Used by 9 Kaizen appsGovCloudCMKElastiCache RedisredisA Redis OSS replication group with encryption at rest and TLS required in transit.Not used by a Kaizen app yetGovCloudCMKS3 Buckets3-bucketA private, versioned S3 bucket with public access blocked and optional TLS only access.Used by 9 Kaizen apps
Network
The private network every other module sits in, plus a locked down way for operators to reach it.
Observability
How the team sees what the app and its users are doing, from server logs to browser sessions.