- [S01] Terraform core workflow
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Write, plan, apply and collaborative review.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S02] Purpose of Terraform state
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Resource addresses map to remote object identities; state retains metadata.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S03] Provider requirements
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Providers have source addresses and version constraints.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S04] Creating modules
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Modules should introduce an architectural abstraction.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S05] for_each reference
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Stable map keys identify instances and must be known before apply.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S06] AWS CDK core concepts
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: CDK synthesizes infrastructure into CloudFormation templates.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S07] AWS CDK constructs
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: L1 resource definitions, L2 abstractions, and higher-level patterns.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S08] CDK bootstrapping
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Per-environment asset stores and deployment/publishing roles.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S09] CDK assets
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: File and container image assets are published before stack deployment.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S10] AWS CDK best practices
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Stable logical IDs, deterministic synthesis and organization guardrails.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S11] CDK for Terraform deprecation
HashiCorp · documentation · accessed 2026-10-10 · Deprecation effective 2025-12-10 · Not stated / rolling documentation
Supports: CDKTF deprecated on December 10, 2025; maintenance ceased.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S12] ECS task IAM role
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Application containers use task-role credentials.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S13] ECS task execution IAM role
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Agent uses execution-role permissions for task startup operations.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S14] Fargate task networking
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Task ENIs, subnet routing and connectivity to image/dependency services.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S15] ECS deployment circuit breaker
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Rolling deployment health detection and rollback require a completed baseline.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S16] ApplicationLoadBalancedFargateService API
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Fargate pattern properties include certificate, subnets and circuit breaker.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S17] Terraform AWS ECS service resource
HashiCorp AWS provider maintainers · documentation · accessed 2026-10-10 · Maintainer documentation on main, retrieved through GitHub; not a pinned provider release · Not stated / rolling documentation
Supports: Service network, load balancer, lifecycle and wait-for-steady-state fields.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S18] EKS Pod Identity
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Pod Identity agent and EC2 workload support; excludes Fargate pods.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S19] IAM roles for service accounts
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: IRSA uses OIDC identities to scope pod AWS permissions.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S20] Amazon EKS on Fargate
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Fargate profiles, no DaemonSets or privileged containers, and EBS limitations.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S21] EKS cluster upgrade best practices
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Check APIs, add-ons, node versions and disruption constraints during upgrades.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S22] AWS CDK EKS Cluster API
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Cluster constructs and kubectl-managed addManifest resources.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S23] AFT and Terraform EKS Blueprints
AWS · maintainer architecture walkthrough · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Published account provisioning and repeatable EKS platform pattern.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S24] Using Lambda with SQS
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Lambda polls queues; event delivery can repeat.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S25] SQS event-source error handling
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: ReportBatchItemFailures and FIFO ordering considerations.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S26] Lambda reserved concurrency
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Reserved concurrency reserves and caps function concurrency.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S27] Lambda versions
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Published versions preserve immutable code/configuration snapshots.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S28] Lambda best practices
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Idempotency, connection reuse and operational measurements.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S29] SQS event-source scaling
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Maximum concurrency and provisioned polling mode are separate alternatives.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S30] CDK SqsEventSourceProps API
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Batch size, partial failure reporting and maxConcurrency properties.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S31] Terraform S3 backend
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Opt-in S3 lockfile, bucket versioning and deprecated DynamoDB locking.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S32] Managing sensitive Terraform data
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Sensitive redaction is distinct from omitting persisted values.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S33] Terraform dependency lock file
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Lockfile pins provider selections/checksums, not remote module versions.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S34] terraform plan
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Plan refresh, saved plan artifacts and sensitive contents.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S35] terraform apply
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Saved plans are applied without an additional interactive approval.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S36] IAM role for OIDC federation
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Constrain GitHub OIDC subject and audience in the role trust policy.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S37] Terraform tests
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Test runs can provision real infrastructure; mock/plan modes have limits.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S38] AWS CDK testing
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Fine-grained template assertions and snapshots serve different purposes.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S39] CloudFormation drift detection
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Drift covers supported types and explicit properties; nested stacks need separate checks.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S40] CloudFormation troubleshooting
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Rollback can fail when dependent resources cannot be restored.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S41] Apply Terraform configuration
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Dependency ordering and no automatic rollback of a partially completed apply.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S42] Refactoring Terraform modules
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: moved blocks retain compatible resource bindings through refactoring.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S43] Import Terraform resources
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Import binds a remote resource to a configured address.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S44] cdk diff
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Diff compares synthesized/deployed templates, with change-set support.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S45] AWS Fargate pricing
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Resource allocation, architecture and task/pod duration drive compute charges.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S46] Amazon EKS pricing
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Cluster support charges coexist with compute and other AWS charges.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S47] AWS Lambda pricing
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Function request and memory-duration charges; extra features have separate costs.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S48] Choosing EKS GitOps tools
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: GitOps ecosystem choices include Argo CD and Flux.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S49] Terraform Lambda event source mapping
HashiCorp AWS provider maintainers · documentation · accessed 2026-10-10 · Maintainer documentation on main, retrieved through GitHub; not a pinned provider release · Not stated / rolling documentation
Supports: SQS batch responses and mapping concurrency fields.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S50] Terraform EKS cluster resource
HashiCorp AWS provider maintainers · documentation · accessed 2026-10-10 · Maintainer documentation on main, retrieved through GitHub; not a pinned provider release · Not stated / rolling documentation
Supports: Control-plane IAM and private/public API endpoint fields.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S51] Amazon ECS task definitions
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Task definitions describe workload configuration and have revisions.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S52] Refresh-only state synchronization
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: Refresh-only operations update state observations without changing infrastructure.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S53] cdk import
AWS · documentation · accessed 2026-10-10 · Current documentation accessed on 2026-10-10 · Not stated / rolling documentation
Supports: CloudFormation-supported resource adoption requires target configuration and an import workflow.
Follow this primary reference for the linked mechanism; verify your pinned version before deployment.
- [S54] AWS CDK apps
AWS · documentation · accessed 2026-10-10 · Current documentation accessed 2026-10-10 · Not stated / rolling documentation
Supports: App, stack, construct hierarchy and synthesis.
Study this primary mechanism reference before changing deployment boundaries.
- [S55] Lambda quotas
AWS · documentation · accessed 2026-10-10 · Current documentation accessed 2026-10-10 · Not stated / rolling documentation
Supports: Workload fit depends on invocation and account limits.
Study this primary mechanism reference before changing deployment boundaries.
- [S56] Terraform dependency graph
HashiCorp · documentation · accessed 2026-10-10 · Current documentation accessed 2026-10-10 · Not stated / rolling documentation
Supports: References produce dependency edges; graph operations can run concurrently.
Study this primary mechanism reference before changing deployment boundaries.