Standard Platform
OPEN SOURCE TERRAFORM PLATFORM
Production-ready AWS infrastructure, built as code
The GoCloud Standard Platform is an open-source, layered Terraform platform for AWS. It packages the patterns our team applies in real projects into reusable modules, so you can stand up secure and scalable infrastructure with consistent conventions instead of starting from scratch.
WHY IT EXISTS
One consistent way to build and govern your AWS accounts
Wiring together networking, security, compute, data and governance for every new account or project is slow and tends to drift over time. The Standard Platform provides a layered, opinionated structure on top of wrapper modules for individual AWS services, with security controls, backups, monitoring and cost control built in, and the same approach across Development, Staging and Production.
Licensed under Apache-2.0. Requires Terraform 1.10 or later and the AWS provider 6.0 or later.
ARCHITECTURE
Six layers, from organization to workload
Each layer is a Terraform module you instantiate on its own, so you can adopt only what you need and keep governance separate from application infrastructure.
Organization
AWS Organizations management, Identity Center (SSO) and the S3 backend for Terraform state, with optional delegated administration for security services. Instantiated once per organization.
- AWS Organizations
- Identity Center
- S3 backend
- GuardDuty
- Security Hub
- CloudTrail delegation
Security
Centralized security and audit services, starting with AWS CloudTrail, typically deployed in a log or security account separate from operational services.
- CloudTrail
Base
Foundational networking and shared services for each environment.
- VPC
- Route53 zones
- CloudMap
- SNS notifications
Foundation
Security, compliance, backup and operational services shared by the workloads of an account.
- ACM
- GitLab Runner
- IAM
- AWS Backup
- SES
- VPN
- WAF
- Monitoring
Project
Core infrastructure for a project, including load balancing, container platforms, databases, storage, messaging and encryption keys.
- ALB
- ECS
- ECR
- EKS
- RDS
- OpenSearch
- KMS
- S3
- EFS
Workload
Application-level services deployed on top of the project infrastructure.
- Static sites
- ECS services
- Lambda
- Batch jobs
- EC2 instances
KEY BENEFITS
What you get with the Standard Platform
Layered architecture
Separate layers for organization, security, networking, shared services, project infrastructure and workloads give flexibility and clear governance boundaries.
Wide AWS coverage
Dozens of wrapper modules for AWS services, each following the same conventions, from VPC, EKS and ECS to RDS, Lambda, WAF and AWS Backup.
Security by design
Security controls and best practices are built into the modules, including centralized audit trails and delegated security services.
Cost awareness
Cost control and monitoring capabilities are part of the platform rather than an afterthought.
Multi-environment
Deploy the same patterns across Development, Staging and Production environments.
Open and reusable
Published on the Terraform Registry under Apache-2.0, with blueprints and a companion CLI to speed up adoption.
HOW IT IS USED
Compose layers with a few lines of Terraform
Each layer is consumed as a module from the Terraform Registry and configured through parameter objects. This example shows the Base layer; the Organization, Security, Foundation, Project and Workload layers follow the same pattern.
module "base" {
source = "gocloudLa/standard-platform/aws//modules/base"
metadata = local.metadata
vpc_parameters = {
# VPC configuration
}
route53_parameters = {
# Route53 zones configuration
}
cloudmap_parameters = {
# CloudMap service discovery configuration
}
notifications_parameters = {
# SNS notifications configuration
}
}Snippet taken from the public module README; parameter values are intentionally left as placeholders. See the module documentation for the full set of options.
THE ECOSYSTEM
The platform, its tooling and the modules behind it
The Standard Platform is built on single-purpose wrapper modules, plus a CLI and ready-to-adapt blueprints. All of them are public on the GoCloud GitHub organization.
Tooling and CI/CD
Networking
Compute and containers
Data
Security and governance
TECHNOLOGIES
Trusted by leading companies using AWS










