All missions
Mission MSN-4417
Build Production AWS Platform
RUNNINGmedium riskAtlasDeployment requires human approval
Progress72%
Updated 2 min ago
Objective
Stand up a production-grade AWS landing zone with network segmentation, IAM baseline and a managed Kubernetes cluster, expressed entirely as reviewed infrastructure code.
Requirements
- Account and region topology defined
- Network segmentation model
- IAM baseline with least privilege
- Kubernetes platform layer
- Cost guardrails
Plan
- 1Derive requirements from the objective and existing account inventory
- 2Design network, identity and platform layers as separate capability units
- 3Generate Terraform per layer with policy checks in the loop
- 4Validate with plan-only runs, then request human approval before apply
Task graph
T1Analyze requirementsAtlaslow1m 12s
T2Design architectureAtlaslow3m 40s
T3Network layerForgelow2m 05s
T4IAM baselineForgemedium0m 48s
T5Kubernetes platformForgemedium—
T6Generate TerraformForgemedium1m 30s
T7Security reviewSentryhigh—
T8DeployForgehigh—
Live activity
streaming- 18:41:02ForgeWrote modules/iam/roles.tf (14 roles, 0 wildcard actions)
- 18:40:31SentryPolicy check passed: no public ingress on private subnets
- 18:39:58AtlasSelected capability iac.terraform.v3 for the platform layer
- 18:38:12Forgeterraform plan completed — 42 to add, 0 to destroy
- 18:36:44AtlasRequirement satisfied: network segmentation model
Workforce
A
Atlas
Platform architect
F
Forge
Infrastructure engineer
S
Sentry
Security reviewer
Artifacts
landing-zone.tf
Terraform
iam-baseline.json
Policy set
architecture.md
Document
plan-output.log
Log
Evaluation
Least-privilege IAMpass
No wildcard actions in generated roles
Network isolationpass
Private subnets have no direct internet route
Cost guardrailswarn
Budget alarm thresholds not yet defined
Deploy readinessfail
Awaiting human approval for apply
Experience
- Plan-only Terraform runs before approval cut rework on this objective class by roughly a third.
- IAM generation is more reliable when role intent is declared before permissions.
