DelegusDocsv0.2

Docs/Infrastructure security

Trust

Infrastructure security controls

What the AWS side of Delegus enforces, as built by infra/. This is the companion to docs/threat-model-mapping.md: that document maps spec threats to protocol and service controls; this one states the controls that live in the accounts, the network, and the key store. Everything here is Terraform in infra/ and can be re-derived from it.

Account structure#

Signing keys#

Evidence store#

Network and edge#

Secrets and deployments#

Logging and alerting#

What is deliberately not in place yet#