AWS and Terraform Architecture Audit
Your Terraform plan takes longer than your standup, and nobody can draw the architecture from memory.
Structured audit of AWS and Terraform: state layout, IAM blast radius, module boundaries, and a severity-ranked remediation roadmap.
You probably need this if…
- Terraform apply runs take 20+ minutes and the team dreads touching infra
- One state file or workspace owns most of the account; merge conflicts are routine
- Nobody can explain why a module exists or what breaks if you remove it
- Security findings reopen because fixes were pasted over root causes
- New environments are cloned by copying tfvars by hand
What's actually going wrong
The infrastructure wasn't designed, it accreted. Modules mirror org charts instead of boundaries. IAM is wider than anyone remembers, and there's no shared picture of what 'correct' looks like. Audits fail because the system has no stable shape to evaluate.
What I review or implement
- State partitioning, module boundaries, and blast radius per environment
- IAM chains: who can pass roles, cross-account assumptions, and over-privileged defaults
- Network topology and separation between data plane, control plane, and edge
- Environment parity and drift between staging and production
- Cost architecture signals: always-on vs event-driven, right-sizing opportunities
What you get
- Written audit with severity-ranked findings and evidence
- Architecture diagram: current state vs recommended target
- 30-day remediation roadmap with quick wins called out separately
- Optional pairing on the first two fixes so the pattern sticks
Proof
100+ Lambda serverless sprawl
Rose Digital · New York Lottery
A high-traffic public app had outgrown its serverless footprint, 100+ Lambdas with inconsistent auth, cold-start pain, and deploy risk on every release. The audit surfaced domain boundaries, layered dependencies, and IAM scope that made the next restructure possible instead of another band-aid.
- 100+
- Lambdas mapped to bounded domains
- Cognito
- Multi-tenant SSO replaced legacy auth
- Aurora
- RBAC admin console with audit logging
Request an architecture audit
Describe your symptoms, not a job spec. I'll reply within 48 hours with an honest read on whether the problem is structural, operational, or something else entirely.