Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Aws Cdk Cloud Architecture

ASecurity

Provision multi-tier, enterprise-grade cloud infrastructure on AWS using AWS CDK v2 (TypeScript). Triggers when designing or implementing AWS CDK stacks, L3 constructs, multi-region networking (VPC, Transit Gateway), ECS Fargate microservices, serverless architectures (Lambda, EventBridge, DynamoDB), IAM least-privilege, CDK Aspects compliance checks, or CDK Pipelines CI/CD.

8 stars
0 votes
0 copies
0 views
Added 9/29/2026
ai-agentstypescriptgoshellsqlnodeawsazuregitdatabaseci/cd

Works with

cli

Security Analysis

A100/100

Scanned 9/29/2026

$npx -y skills add hamzabellouch/agent-skills --skill aws-cdk-cloud-architecture --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Aws Cdk Cloud Architecture?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Aws Cdk Cloud Architecture
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hamzabellouch-aws-cdk-cloud-architecture/badge)](https://www.skillsdirectory.com/skills/hamzabellouch-aws-cdk-cloud-architecture)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: aws-cdk-cloud-architecture
metadata:
  category: Multi-Cloud Architecture (AWS and Azure)
description: >-
  Provision multi-tier, enterprise-grade cloud infrastructure on AWS using AWS CDK v2 (TypeScript).
  Triggers when designing or implementing AWS CDK stacks, L3 constructs, multi-region networking (VPC, Transit Gateway),
  ECS Fargate microservices, serverless architectures (Lambda, EventBridge, DynamoDB), IAM least-privilege,
  CDK Aspects compliance checks, or CDK Pipelines CI/CD.
compatibility: AWS CDK v2 (>= 2.100.0), Node.js (>= 18.x), TypeScript (>= 5.0), AWS CLI v2
---

# AWS CDK Cloud Architecture

Production-ready architectural patterns, L3 construct patterns, and TypeScript implementations for provisioning enterprise infrastructure using AWS Cloud Development Kit (CDK) v2.

---

## 1. Core Architecture Principles & Folder Structure

### Recommended Project Layout

```text
├── bin/
│   └── app.ts                  # App entrypoint & stack instantiation per environment
├── lib/
│   ├── aspects/                # CDK Aspects (compliance, tagging, security guards)
│   │   └── security-aspect.ts
│   ├── constructs/             # Modular L3 custom constructs
│   │   ├── network-construct.ts
│   │   ├── ecs-service-construct.ts
│   │   └── database-construct.ts
│   └── stacks/                 # Stack definitions
│       ├── network-stack.ts
│       ├── application-stack.ts
│       └── pipeline-stack.ts
├── config/                     # Environment configuration schemas
│   ├── dev.json
│   └── prod.json
├── cdk.json
├── package.json
└── tsconfig.json
```

---

## 2. Bootstrapping & Environment Configuration

### Environment Configuration Pattern

Always use typed configuration objects instead of hardcoded values or raw `process.env` lookups inside constructs.

```typescript
// config/environment.ts
export interface EnvironmentConfig {
  readonly account: string;
  readonly region: string;
  readonly environment: 'dev' | 'staging' | 'prod';
  readonly vpcCidr: string;
  readonly maxAzs: number;
  readonly ecsDesiredCount: number;
}

export const envConfigs: Record<string, EnvironmentConfig> = {
  dev: {
    account: '111111111111',
    region: 'us-east-1',
    environment: 'dev',
    vpcCidr: '10.0.0.0/16',
    maxAzs: 2,
    ecsDesiredCount: 2,
  },
  prod: {
    account: '222222222222',
    region: 'us-east-1',
    environment: 'prod',
    vpcCidr: '10.100.0.0/16',
    maxAzs: 3,
    ecsDesiredCount: 6,
  },
};
```

---

## 3. Production Multi-Tier Network & Core Constructs

### Multi-AZ Secure VPC Construct (`lib/constructs/network-construct.ts`)

```typescript
import { Construct } from 'constructs';
import * as ec2 from 'aws-cdk-lib/aws-ec2';

export interface NetworkConstructProps {
  readonly vpcCidr: string;
  readonly maxAzs: number;
}

export class NetworkConstruct extends Construct {
  public readonly vpc: ec2.IVpc;

  constructor(scope: Construct, id: string, props: NetworkConstructProps) {
    super(scope, id);

    this.vpc = new ec2.Vpc(this, 'ProductionVpc', {
      ipAddresses: ec2.IpAddresses.cidr(props.vpcCidr),
      maxAzs: props.maxAzs,
      natGateways: props.maxAzs, // High Availability across all AZs
      subnetConfiguration: [
        {
          cidrMask: 24,
          name: 'Public',
          subnetType: ec2.SubnetType.PUBLIC,
        },
        {
          cidrMask: 22,
          name: 'Application',
          subnetType: ec2.SubnetType.PRIVATE_WITH_EGRESS,
        },
        {
          cidrMask: 24,
          name: 'Database',
          subnetType: ec2.SubnetType.PRIVATE_ISOLATED,
        },
      ],
      enableDnsHostnames: true,
      enableDnsSupport: true,
    });

    // VPC Flow Logs to CloudWatch
    this.vpc.addFlowLog('VpcFlowLogs');
  }
}
```

---

## 4. Production Microservice Infrastructure (ECS Fargate + ALB + Aurora)

### Application & Database Stack (`lib/stacks/application-stack.ts`)

```typescript
import * as cdk from 'aws-cdk-lib';
import { Construct } from 'constructs';
import * as ec2 from 'aws-cdk-lib/aws-ec2';
import * as ecs from 'aws-cdk-lib/aws-ecs';
import * as ecsPatterns from 'aws-cdk-lib/aws-ecs-patterns';
import * as rds from 'aws-cdk-lib/aws-rds';
import * as kms from 'aws-cdk-lib/aws-kms';
import * as logs from 'aws-cdk-lib/aws-logs';
import { EnvironmentConfig } from '../../config/environment';

export interface ApplicationStackProps extends cdk.StackProps {
  readonly config: EnvironmentConfig;
  readonly vpc: ec2.IVpc;
}

export class ApplicationStack extends cdk.Stack {
  constructor(scope: Construct, id: string, props: ApplicationStackProps) {
    super(scope, id, props);

    const { config, vpc } = props;

    // Customer Managed KMS Key for storage encryption
    const kmsKey = new kms.Key(this, 'AppKmsKey', {
      enableKeyRotation: true,
      description: `Encryption key for ${config.environment} application resources`,
      removalPolicy: config.environment === 'prod' ? cdk.RemovalPolicy.RETAIN : cdk.RemovalPolicy.DESTROY,
    });

    // Aurora Serverless v2 PostgreSQL Cluster
    const dbCluster = new rds.DatabaseCluster(this, 'AuroraCluster', {
      engine: rds.DatabaseClusterEngine.auroraPostgres({
        version: rds.AuroraPostgresEngineVersion.VER_15_3,
      }),
      writer: rds.ClusterInstance.serverlessV2('writer', {
        publiclyAccessible: false,
      }),
      serverlessV2MinCapacity: 0.5,
      serverlessV2MaxCapacity: 16.0,
      vpc,
      vpcSubnets: { subnetType: ec2.SubnetType.PRIVATE_ISOLATED },
      storageEncrypted: true,
      kmsKey,
      defaultDatabaseName: 'appdb',
      removalPolicy: config.environment === 'prod' ? cdk.RemovalPolicy.RETAIN : cdk.RemovalPolicy.DESTROY,
    });

    // ECS Cluster with Container Insights enabled
    const ecsCluster = new ecs.Cluster(this, 'EcsCluster', {
      vpc,
      containerInsights: true,
    });

    // Application Load Balanced Fargate Service
    const fargateService = new ecsPatterns.ApplicationLoadBalancedFargateService(this, 'FargateService', {
      cluster: ecsCluster,
      cpu: 512,
      memoryLimitMiB: 1024,
      desiredCount: config.ecsDesiredCount,
      taskSubnets: { subnetType: ec2.SubnetType.PRIVATE_WITH_EGRESS },
      publicLoadBalancer: true,
      taskImageOptions: {
        image: ecs.ContainerImage.fromRegistry('public.ecr.aws/nginx/nginx:latest'),
        containerPort: 80,
        enableLogging: true,
        logDriver: ecs.LogDrivers.awsLogs({
          streamPrefix: `${config.environment}-app`,
          logRetention: logs.RetentionDays.ONE_MONTH,
        }),
        environment: {
          ENVIRONMENT: config.environment,
          DB_HOST: dbCluster.clusterEndpoint.hostname,
        },
        secrets: {
          DB_SECRET: ecs.Secret.fromSecretsManager(dbCluster.secret!),
        },
      },
    });

    // Allow ECS Tasks to communicate with Aurora Database
    dbCluster.connections.allowDefaultPortFrom(fargateService.service);

    // Auto-scaling policy based on CPU utilization
    const autoScaling = fargateService.service.autoScaleTaskCount({
      minCapacity: config.ecsDesiredCount,
      maxCapacity: config.ecsDesiredCount * 4,
    });

    autoScaling.scaleOnCpuUtilization('CpuScaling', {
      targetUtilizationPercent: 70,
      scaleInCooldown: cdk.Duration.seconds(300),
      scaleOutCooldown: cdk.Duration.seconds(60),
    });
  }
}
```

---

## 5. Security & Governance with CDK Aspects

Enforce organizational compliance rules (e.g., mandatory tags, SSL enforcement, encryption) across all stacks automatically.

### Security Compliance Aspect (`lib/aspects/security-aspect.ts`)

```typescript
import * as cdk from 'aws-cdk-lib';
import * as s3 from 'aws-cdk-lib/aws-s3';
import { IConstruct } from 'constructs';

export class SecurityComplianceAspect implements cdk.IAspect {
  public visit(node: IConstruct): void {
    // Rule 1: Ensure all S3 buckets enforce SSL and encrypt at rest
    if (node instanceof s3.CfnBucket) {
      if (!node.bucketEncryption) {
        cdk.Annotations.of(node).addError('S3 Bucket must have encryption enabled.');
      }
    }
  }
}

// In bin/app.ts:
// cdk.Aspects.of(app).add(new SecurityComplianceAspect());
```

---

## 6. Self-Mutating CI/CD Pipeline (CDK Pipelines)

### CDK Pipeline Stack (`lib/stacks/pipeline-stack.ts`)

```typescript
import * as cdk from 'aws-cdk-lib';
import { Construct } from 'constructs';
import { CodePipeline, CodePipelineSource, ShellStep } from 'aws-cdk-lib/pipelines';

export class PipelineStack extends cdk.Stack {
  constructor(scope: Construct, id: string, props?: cdk.StackProps) {
    super(scope, id, props);

    const pipeline = new CodePipeline(this, 'CdkPipeline', {
      pipelineName: 'EnterpriseCdkPipeline',
      synth: new ShellStep('Synth', {
        input: CodePipelineSource.gitHub('my-org/my-cdk-repo', 'main'),
        commands: [
          'npm ci',
          'npm run build',
          'npx cdk synth',
        ],
      }),
    });
  }
}
```

---

## 7. Best Practices & Production Checklist

1. **Construct Immutability**: Always pass CDK L2/L3 constructs by interface (`IVpc`, `IBucket`) rather than concrete types when referencing across stacks.
2. **Deletion Policies**: Use `RemovalPolicy.RETAIN` for production S3 buckets, DynamoDB tables, and Aurora clusters. Use `RETAIN_ON_UPDATE_OR_DELETE` for critical KMS keys.
3. **Deterministic Deployments**: Pin CDK npm package versions strictly (`"aws-cdk-lib": "2.120.0"`) to avoid version drift between developer workstations and CI/CD pipelines.
4. **Context & Caching**: Commit `cdk.context.json` to source control to lock AZ lookup responses and prevent non-deterministic stack synthesis.

Attribution

hamzabellouchhamzabellouch
View sourceSee grades on GitHubMore from hamzabellouch →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698621 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →