← all services

AWS and Terraform Architecture Audit

Your Terraform plan takes longer than your standup, and nobody can draw the architecture from memory.

Structured audit of AWS and Terraform: state layout, IAM blast radius, module boundaries, and a severity-ranked remediation roadmap.

You probably need this if…

  • Terraform apply runs take 20+ minutes and the team dreads touching infra
  • One state file or workspace owns most of the account; merge conflicts are routine
  • Nobody can explain why a module exists or what breaks if you remove it
  • Security findings reopen because fixes were pasted over root causes
  • New environments are cloned by copying tfvars by hand

What's actually going wrong

The infrastructure wasn't designed, it accreted. Modules mirror org charts instead of boundaries. IAM is wider than anyone remembers, and there's no shared picture of what 'correct' looks like. Audits fail because the system has no stable shape to evaluate.

What I review or implement

  • State partitioning, module boundaries, and blast radius per environment
  • IAM chains: who can pass roles, cross-account assumptions, and over-privileged defaults
  • Network topology and separation between data plane, control plane, and edge
  • Environment parity and drift between staging and production
  • Cost architecture signals: always-on vs event-driven, right-sizing opportunities

What you get

  • Written audit with severity-ranked findings and evidence
  • Architecture diagram: current state vs recommended target
  • 30-day remediation roadmap with quick wins called out separately
  • Optional pairing on the first two fixes so the pattern sticks

Proof

100+ Lambda serverless sprawl

Rose Digital · New York Lottery

A high-traffic public app had outgrown its serverless footprint, 100+ Lambdas with inconsistent auth, cold-start pain, and deploy risk on every release. The audit surfaced domain boundaries, layered dependencies, and IAM scope that made the next restructure possible instead of another band-aid.

100+
Lambdas mapped to bounded domains
Cognito
Multi-tenant SSO replaced legacy auth
Aurora
RBAC admin console with audit logging

See the case study →

Request an architecture audit

Describe your symptoms, not a job spec. I'll reply within 48 hours with an honest read on whether the problem is structural, operational, or something else entirely.