ACM Certificate
Provisions AWS Certificate Manager SSL/TLS certificates with Route53 validation
Provisions AWS Certificate Manager SSL/TLS certificates with Route53 validation
Decision to build parallel workload and management (Identity Center) accounts in parallel at zero cost (plan/validate); profile-only environment configuration with runtime account discovery via AWS APIs; legacy Terraform module consolidation into canonical submodule in waves; LLM-Docs engine applied to both this repository and private companion documentation repository.
Adopt compiled LLM documentation for Terraform modules to ensure drift-resistant SSOT and AI-discoverable infrastructure code
Provisions an AWS Application Load Balancer with listeners, target groups, and optional WAF integration
Provisions AWS Identity Center for centralized user access and multi-account permission management
Provisions an AWS Transfer Family SFTP server with S3 backend and user management
AWS workload account hosting application infrastructure (VPC, ECS, RDS, S3)
Provisions an AWS CloudFront CDN distribution with origins, behaviors, and SSL/TLS configuration
Comprehensive reference for all AWS Terraform modules, accounts, and identity architecture compiled from source code and design documentation.
When to use count and when to use for_each in Terraform
Provisions an AWS ECS cluster with EC2 or Fargate capacity providers and auto-scaling
Provisions an AWS EFS with mount targets, access points, and backup policies
Details about computed values can cause `terraform plan` to fail
IAM Identity Center with Entra ID federation for workforce SSO across AWS accounts
Provisions an AWS KMS master key with key policies, grants, and rotation policies
AWS Organizations hub account with IAM Identity Center, security controls, and central governance
Creates AWS S3 buckets with versioning, encryption, access logging, and bucket policies
Deep dive into Terraform implementation details and pitfalls
Some helpful hints for Terraform
Creates a Virtual Private Cloud with configurable subnets, NAT gateways, and network resources
Deploys AWS WAFv2 web ACLs with IP sets, rate limiting, and rule management
Provisions a complete web stack: Application Load Balancer, CloudFront distribution, WAF, and Route53 DNS