AWS field guide
Make trust boundaries explicit
Model identity, data, network, and human access boundaries before choosing controls.
Use this pattern when
Services cross account, network, data, or human access boundaries.
Reference architecture
Responsibilities and controls, not a deployment template.
AWS IAM
Workload identity
Authorization
Narrow policy decision
Trust boundary
Account or data edge
AWS KMS
Key ownership and use
AWS CloudTrail
Auditable access record
Decisions that shape the pattern
- Assign ownership to every data class.
- Prefer workload identities over shared credentials.
- Make cross-account access explicit.
Security boundaries
- Use least privilege and short-lived credentials.
- Separate key administration from data use.
- Centralize auditable access events.
Reliability posture
- Test dependency behavior when access is denied.
- Keep a controlled recovery path.
- Prevent security logging failures from silently hiding activity.
Starter implementation
Start from deployable infrastructure
Review every permission, limit, Region, and cost assumption before production.
import { Duration, Stack, StackProps } from 'aws-cdk-lib';
import * as apigateway from 'aws-cdk-lib/aws-apigateway';
import * as athena from 'aws-cdk-lib/aws-athena';
import * as bedrock from 'aws-cdk-lib/aws-bedrock';
import * as budgets from 'aws-cdk-lib/aws-budgets';
import * as cloudfront from 'aws-cdk-lib/aws-cloudfront';
import * as origins from 'aws-cdk-lib/aws-cloudfront-origins';
import * as cloudtrail from 'aws-cdk-lib/aws-cloudtrail';
import * as cloudwatch from 'aws-cdk-lib/aws-cloudwatch';
import * as dynamodb from 'aws-cdk-lib/aws-dynamodb';
import * as ecs from 'aws-cdk-lib/aws-ecs';
import * as patterns from 'aws-cdk-lib/aws-ecs-patterns';
import * as events from 'aws-cdk-lib/aws-events';
import * as targets from 'aws-cdk-lib/aws-events-targets';
import * as glue from 'aws-cdk-lib/aws-glue';
import * as iam from 'aws-cdk-lib/aws-iam';
import * as kms from 'aws-cdk-lib/aws-kms';
import * as lambda from 'aws-cdk-lib/aws-lambda';
import * as sources from 'aws-cdk-lib/aws-lambda-event-sources';
import * as s3 from 'aws-cdk-lib/aws-s3';
import * as secretsmanager from 'aws-cdk-lib/aws-secretsmanager';
import * as sqs from 'aws-cdk-lib/aws-sqs';
import { Construct } from 'constructs';
export class PatternStack extends Stack {
constructor(scope: Construct, id: string, props?: StackProps) {
super(scope, id, props);
const key = new kms.Key(this, 'DataKey', { enableKeyRotation: true });
const secret = new secretsmanager.Secret(this, 'WorkloadSecret', { encryptionKey: key });
const role = new iam.Role(this, 'WorkloadRole', {
assumedBy: new iam.ServicePrincipal('lambda.amazonaws.com'),
});
secret.grantRead(role);
new cloudtrail.Trail(this, 'AuditTrail', {
managementEvents: cloudtrail.ReadWriteType.ALL,
sendToCloudWatchLogs: true,
});
}
}
Before production
Adoption checklist
- 01Draw the trust boundaries.
- 02Map identities to actions.
- 03Remove wildcard permissions.
- 04Define key ownership.
- 05Test access revocation.
From the journal
Related field notes
Selected from service names and architecture signals used by this pattern.
IAM Identity Center Adds Network Controls for Identity Store
New network access controls for Identity Store let you restrict API access by VPC endpoint or IP range.
Netflix's Workload Attestation: Trading Cloud Identity for Control
Netflix details their custom workload attestation system, trading cloud provider IAM for deeper control and security.
AWS Bedrock Managed Agents preview: OpenAI's tech, AWS glue
AWS and OpenAI collaborate on managed agents for Bedrock, bringing OpenAI's Agents API into AWS with IAM and CloudTrail integration.
Was this playbook useful?
One click helps prioritize deeper examples and updates.