Kaizen

Modules

All 12 modules, grouped by the layer of the stack they cover.

GovCloudWorks in AWS GovCloud
Runs unmodified in the aws-us-gov partition. ARNs are partition aware, or the module builds no partition specific ARNs.
FIPSFIPS 140-3 option
Exposes or enforces a FIPS 140-3 setting, such as a FIPS TLS policy or a FIPS crypto policy.
CMKCustomer managed key
Accepts a customer managed KMS key, so the agency or app team controls the encryption key (FedRAMP SC-13).

Where public traffic enters. TLS ends at the load balancer and a web application firewall screens requests first.

Where the app runs. Containers on AWS Fargate in private subnets, built from images in a scanned registry.

Where the app keeps state. Postgres, Redis, and S3, each encrypted at rest and reachable only from the app.

The private network every other module sits in, plus a locked down way for operators to reach it.

How the team sees what the app and its users are doing, from server logs to browser sessions.