AWS Platform Guide
Procedures and Practices
thoughtbot implements the following procedures and practice to help with compliance:
Integrate cloud access with single sign on
Separate workflows by development life cycle
Encrypt all data at rest and in transit
Unique customer controlled encryption keys for each data store
Network isolation for data stores and backend services
Organization-wide AWS backup policies
Organization-wide AWS security policies
Organization-wide AWS config controls
Enforce SDLC workflows using CI/CD
Automated vulnerability scans for infrastructure and application dependencies
Encrypted logs with archives
Audit logs for infrastructure access and changes
AWS Platform Guide
The guide for building and maintaining production-grade Kubernetes clusters with built-in support for SRE best practices.
Source available on GitHub.