The foundation
A multi-account AWS Organization with a delegated Audit account, a Log Archive account, IAM Identity Center with least-privilege Permission Sets, a 3-tier VPC with private access via Twingate, org-wide CloudTrail, and AWS Config. Everything as Terragrunt code, in the module-and-live split we run on our own accounts.
- AWS Organizations
- IAM Identity Center
- Twingate
- CloudTrail
- AWS Config