aws-network-and-identity-foundation
Installation
SKILL.md
AWS Network and Identity Foundation
When to use
Invoke when standing up the in-account network and identity layer for an environment, restructuring VPC/connectivity, or auditing/hardening IAM, KMS, and secret handling before workloads land in the account.
Do not use for: AWS Organizations/OU/SCP topology (use aws-account-and-organization-topology); workload compute primitives, load balancing, autoscaling (use aws-workload-runtime-and-deployment); CloudWatch/cost instrumentation (use aws-observability-and-cost-readiness); multi-region/DR (use aws-dr-and-multi-region-readiness); IaC module/state/plan/apply mechanics (the terraform Family H skills own those — this skill emits IaC-ready definitions, not the modules).
Inputs
Required:
- An account/OU layout from
aws-account-and-organization-topology(the accounts this network and identity foundation is built inside). - Approved
architecture/securitydecisions on trust zones, the IAM/identity model, and encryption posture, or explicit confirmation they are intentionally deferred.
Optional: