Track how long it takes and how much it costs to create projects with AI π€ in an attempt to optimize progress. Note that I have only been using Opus 6 and 8 same price per token. I have been trying to log my time but there are some gaps where I was working but making no progress because I'm fixing things that are broken or reworking code. Part of the rework is the model failing write the code as specifed. Part of it is my rearchitecting my data model after testing. See notes for details and time tracking file where I've strated tracking some (not all) rework.
| Status | Description |
|---|---|
| π’ | Done |
| π‘ | Broken |
| π΄ | Not attempted |
This is just the particular configuration I'm tesing. The configuration supports any AWS resources and account structure.
~~ Right now the reoprting below is a bit messed up so what is shown below is no longer accurate. I'll update it shortly. As explained on social media and in the details of the mistakes, fixed, and time tracking mds, I'm revamping the architecture to overcome some concurrency issues. I've pretty much fixed the concurrency issues and tracker diagram creation - though I have some slowness to address. Though it's "working" to some degree, I have to fix a role assumption issue (mfa v no mfa before trust policy is updated), diagram slowness, an eternal loop on certain resources, and the individual resource issues). More in mistakes.md. I'll update this hoepfully shortly.
=========================================
xxxxxx: Deploy Diagram
=========================================
π‘ org: xxxxxxx (xxxxxxxx)
|
| Organization Resources:
|____ π’ Organization (xxxxxxxx)
|____ π’ Enable All Features (xxxxxxxx)
|____ π’ Deny-All OU (xxxxxxxx)
|____ π’ SCP Require IMDSv2 (xxxxxxxx)
|____ π’ SCP Deny Leave Org (xxxxxxxx)
|____ π’ SCP Allowed Regions (xxxxxxxx)
|
|____ π‘ env: manage
| |
| | Environment Resources:
| |____ π’ OU (xxxxxxxx)
| |____ π’ SCP Deny External (xxxxxxxx)
| |
| |____ π’ account: manage-iam (xxxxxxxx)
| | |
| | | Resources:
| | |____ π΄ Move account to OU
| | |____ π’ Account alias (xxxxxxxx)
| | |____ π’ Xadmin role (xxxxxxxx)
| | |____ π’ Iadmin role (xxxxxxxx)
| | |____ π’ Oadmin role (xxxxxxxx)
| | |____ π’ Account Budget (xxxxxxxx)
| | |____ π’ Delete default VPCs (xxxxxxxx)
| | |
| | |____ region: us-east-2
| | | Resources:
| | |____ π’ iadmin-user (xxxxxxxx)
| | |____ π’ xadmin-user (xxxxxxxx)
| |
| |____ π’ account: manage-kms (xxxxxxxx)
| | |
| | | Resources:
| | |____ π΄ Move account to OU
| | |____ π’ Account alias (xxxxxxxx)
| | |____ π’ Xadmin role (xxxxxxxx)
| | |____ π’ Iadmin role (xxxxxxxx)
| | |____ π’ Oadmin role (xxxxxxxx)
| | |____ π’ Account Budget (xxxxxxxx)
| | |____ π’ Delete default VPCs (xxxxxxxx)
| | |
| | |____ region: us-east-2
| | | Resources:
| | |____ π’ kms-logs-key (xxxxxxxx)
| | |____ π’ kms-auth-key (xxxxxxxx)
| | |____ π’ kms-jobs-key (xxxxxxxx)
| | |____ π’ kms-secrets-key (xxxxxxxx)
| | |____ π’ kms-config-key (xxxxxxxx)
| |
| |____ π’ account: manage-security (xxxxxxxx)
| | |
| | | Resources:
| | |____ π’ Delegate Security Hub admin (xxxxxxxx)
| | |____ π’ Delegate GuardDuty admin (xxxxxxxx)
| | |____ π’ Delegate CloudTrail admin (xxxxxxxx)
| | |____ π’ Delegate AWS Config admin (xxxxxxxx)
| | |____ π’ Delegate Macie admin (xxxxxxxx)
| | |____ π’ Delegate Inspector admin (xxxxxxxx)
| | |____ π’ Delegate IAM Access Analyzer admin (xxxxxxxx)
| | |____ π’ Delegate Audit Manager admin (xxxxxxxx)
| | |____ π’ Delegate Health admin (xxxxxxxx)
| | |____ π’ Delegate Detective admin (xxxxxxxx)
| | |____ π’ Configure GuardDuty (xxxxxxxx)
| | |____ π’ Configure CloudTrail (xxxxxxxx)
| | |____ π’ Configure AWS Config (xxxxxxxx)
| | |____ π’ Configure Macie (xxxxxxxx)
| | |____ π’ Configure Inspector (xxxxxxxx)
| | |____ π’ Configure IAM Access Analyzer (xxxxxxxx)
| | |____ π’ Configure Security Alerts (xxxxxxxx)
| | |____ π’ Move account to OU (xxxxxxxx)
| | |____ π’ Account alias (xxxxxxxx)
| | |____ π’ Xadmin role (xxxxxxxx)
| | |____ π’ Iadmin role (xxxxxxxx)
| | |____ π’ Oadmin role (xxxxxxxx)
| | |____ π’ Account Budget (xxxxxxxx)
| | |____ π’ Delete default VPCs (xxxxxxxx)
| | |
| | |____ region: us-east-2
| | | Resources:
| | |____ π’ s3-log-bucket (xxxxxxxx)
| | |____ π’ configure-security-hub (xxxxxxxx)
| | |____ π’ s3-log-bucket-policy (xxxxxxxx)
| |
| |____ π’ account: manage-org (xxxxxxxx)
| | |
| | | Resources:
| | |____ π’ Org resource policy (xxxxxxxx)
| | |____ π’ Move account to OU (xxxxxxxx)
| | |____ π’ Account alias (xxxxxxxx)
| | |____ π’ Xadmin role (xxxxxxxx)
| | |____ π’ Iadmin role (xxxxxxxx)
| | |____ π’ Oadmin role (xxxxxxxx)
| | |____ π’ Account Budget (xxxxxxxx)
| | |____ π’ Delete default VPCs (xxxxxxxx)
| | |
| | |____ region: us-east-2
| | | Resources:
| | |____ π’ delegate-org-admin (xxxxxxxx)
| |
| |____ π’ account: manage-accounting (xxxxxxxx)
| | |
| | | Resources:
| | |____ π’ Delegate Cost Optimization Hub admin (xxxxxxxx)
| | |____ π’ Delegate Compute Optimizer admin (xxxxxxxx)
| | |____ π’ Move account to OU (xxxxxxxx)
| | |____ π’ Account alias (xxxxxxxx)
| | |____ π’ Xadmin role (xxxxxxxx)
| | |____ π’ Iadmin role (xxxxxxxx)
| | |____ π’ Oadmin role (xxxxxxxx)
| | |____ π’ Account Budget (xxxxxxxx)
| | |____ π’ Delete default VPCs (xxxxxxxx)
| | |
| | |____ region: us-east-2
| | | Resources:
| |
| |____ π’ account: manage-ipam (xxxxxxxx)
| | |
| | | Resources:
| | |____ π’ Delegate IPAM admin (xxxxxxxx)
| | |____ π’ IPAM (xxxxxxxx)
| | |____ π’ Delegate Network Manager admin (xxxxxxxx)
| | |____ π’ Delegate VPC Reachability Analyzer admin (xxxxxxxx)
| | |____ π’ Delegate Firewall Manager admin (xxxxxxxx)
| | |____ π΄ Move account to OU
| | |____ π’ Account alias (xxxxxxxx)
| | |____ π’ Xadmin role (xxxxxxxx)
| | |____ π’ Iadmin role (xxxxxxxx)
| | |____ π’ Oadmin role (xxxxxxxx)
| | |____ π’ Account Budget (xxxxxxxx)
| | |____ π’ Delete default VPCs (xxxxxxxx)
| | |
| | |____ region: us-east-2
| | | Resources:
| |
| |____ π‘ account: manage-kiro (xxxxxxxx)
| |
| | Resources:
| |____ π΄ kiro-cli-identity-center
| |____ π΄ Move account to OU
| |____ π’ Account alias (xxxxxxxx)
| |____ π΄ Xadmin role
| |____ π‘ Iadmin role (error)
| | β³ ERROR: exit-conditions.sh failed for iadmin-role. [...renamed account problem]
| |____ π‘ Oadmin role (error)
| | β³ ERROR: deployment of oadmin-role failed. [...renamed account problem]
| |____ π‘ Account Budget (error)
| | β³ ERROR: deployment of account-budget failed.[...renamed account problem]
| |____ π’ Delete default VPCs (xxxxxxxx)
| |
| |____ region: us-east-2
| | Resources:
|
|____ π‘ env: backup
| |
| | Environment Resources:
| |____ π΄ OU
| |____ π΄ SCP Deny External
| |
| |____ π‘ account: backup-work-test (xxxxxxxx)
| | |
| | | Resources:
| | |____ π’ Delegate Backup admin (xxxxxxxx)
| | |____ π΄ Move account to OU
| | |____ π‘ Account alias (error)
| | | β³ ERROR: Failed to list aliases
| | |____ π‘ Xadmin role (error)
| | | β³ ERROR: deployment of xadmin-role failed. [...renamed account problem]
| | |____ π‘ Iadmin role (error)
| | | β³ ERROR: deployment of iadmin-role failed. [...renamed account problem]
| | |____ π‘ Oadmin role (error)
| | | β³ ERROR: exit-conditions.sh failed for oadmin-role. [...renamed account problem]
| | |____ π‘ Account Budget (error)
| | | β³ ERROR: deployment of account-budget failed. org=o-vif30ez4ew env=backup account=backup-work-test
| | | resource=account-budget action=deploy [...renamed account problem]
| | |____ π‘ Delete default VPCs (error)
| | | β³ ERROR: deployment of delete-default-vpcs failed. o[...renamed account problem]
| | |
| | |____ region: us-east-2
| | | Resources:
| | |____ π΄ backup-work-test
| | |____ π‘ kms-backup-key (error)
| | | β³ ERROR: parallel run aborted: [...renamed account problem]
| |
| |____ π΄ account: backup-manage
| |
| | Resources:
| |____ π΄ Move account to OU
| |____ π΄ Account alias
| |____ π΄ Xadmin role
| |____ π΄ Iadmin role
| |____ π΄ Oadmin role
| |____ π΄ Account Budget
| |____ π΄ Delete default VPCs
|
|____ π΄ env: deny-all
| |
| | Environment Resources:
| |____ π΄ SCP Always Denied Actions
| |____ π΄ OU
| |____ π΄ SCP Deny External
|
|____ π΄ env: work-test
|
| Environment Resources:
|____ π΄ OU
|____ π’ SCP Deny External (xxxxxxxx)
|
|____ π’ account: work-test-iam
| |
| | Resources:
| |____ π΄ Iadmin user
| |____ π΄ Move account to OU
| |____ π΄ Account alias
| |____ π’ Xadmin role (xxxxxxxx)
| |____ π’ Iadmin role (xxxxxxxx)
| |____ π΄ Oadmin role
| |____ π΄ Account Budget
| |____ π΄ Delete default VPCs
| |
| |____ region: us-east-2
| | Resources:
| |____ π’ xadmin-user (xxxxxxxx)
|
|____ π΄ account: work-test-kms
| |
| | Resources:
| |____ π΄ KMS Secrets Key
| |____ π΄ Move account to OU
| |____ π’ Account alias (xxxxxxxx)
| |____ π΄ Xadmin role
| |____ π΄ Iadmin role
| |____ π΄ Oadmin role
| |____ π΄ Account Budget
| |____ π΄ Delete default VPCs
| |
| |____ region: us-east-2
| | Resources:
| |____ π’ kms-jobs-key (xxxxxxxx)
| |____ π΄ kms-ami-key
|
|____ π΄ account: work-test-network
| |
| | Resources:
| |____ π΄ Move account to OU
| |____ π΄ Account alias
| |____ π΄ Xadmin role
| |____ π΄ Iadmin role
| |____ π΄ Oadmin role
| |____ π΄ Account Budget
| |____ π΄ Delete default VPCs
| |
| |____ region: us-east-2
| | Resources:
| |____ π’ remote-access-prefix-list (xxxxxxxx)
| |____ π΄ auth-vpc
| |____ π΄ work-vpc
| |____ π΄ honeypot-vpc
| |____ π΄ backup-vpc
| |____ π’ ipam-pool (xxxxxxxx)
| |____ π’ vpc-flow-logs-role (xxxxxxxx)
| |____ π΄ jobs-vpc
|
|____ π΄ account: work-test-ami
| |
| | Resources:
| |____ π΄ Move account to OU
| |____ π΄ Account alias
| |____ π΄ Xadmin role
| |____ π΄ Iadmin role
| |____ π΄ Oadmin role
| |____ π΄ Account Budget
| |____ π΄ Delete default VPCs
| |
| |____ region: us-east-2
| | Resources:
| |____ π΄ collab-ami
| |____ π΄ base-ubuntu-ami
| |____ π΄ share-amis-to-ou
| |____ π΄ base-amazon-linux-ami
| |____ π΄ share-ami
|
|____ π’ account: work-test-repo
| |
| | Resources:
| |____ π΄ Move account to OU
| |____ π΄ Account alias
| |____ π΄ Xadmin role
| |____ π΄ Iadmin role
| |____ π΄ Oadmin role
| |____ π΄ Account Budget
| |____ π΄ Delete default VPCs
| |
| |____ region: us-east-2
| | Resources:
| |____ π’ code-commit-repository (xxxxxxxx)
|
|____ π΄ account: work-test-domains
| |
| | Resources:
| |____ π΄ Move account to OU
| |____ π΄ Account alias
| |____ π΄ Xadmin role
| |____ π΄ Iadmin role
| |____ π΄ Oadmin role
| |____ π΄ Account Budget
| |____ π΄ Delete default VPCs
|
|____ π΄ account: work-test-project-alnzbinsdvnasaosfil
|
| Resources:
|____ π΄ Move account to OU
|____ π΄ Account alias
|____ π΄ Xadmin role
|____ π΄ Iadmin role
|____ π΄ Oadmin role
|____ π΄ Account Budget
|____ π΄ Delete default VPCs
|
|____ region: us-east-2
| Resources:
|____ π΄ work-test-project-alnzbinsdvnasaosfil
| Status | Description |
|---|---|
| π’ | Configure Reosurce Types |
| π’ | Organization |
| π‘ | Deploy Environment & Resources |
| π‘ | Verify Environment & Resources |
| π‘ | Delete Environent & Resources |
| π΄ | Manage Drift |
| π‘ | Packaged Code |
| π‘ | QA |
| π΄ | Code Review |
| π΄ | Security Testing |
| Usage Dates | Plan | % usage | charges | days | cost per day |
|---|---|---|---|---|---|
| June 1 - 12 | $200 plan | 100% | $83 | 12 | $6.92 |
| June 13 - 17 9:00 pm | $200 plan | 100% | $67 | 4 | $16.75 |
| June 17 9:16PM - 23 3:00 AM | $200 plan | 100% | $120 | 6 | $20 |
| June 24 - 28 2:15 AM | $200 plan | 100% | $134.16 | 4 | $33.54 |
| June 30 - July 1 | partial $200 plan | ? | $53.55 | < 1 | $53.55 |
Total Kiro charged for June: $457.71
Note that I started a new $200 plan on the last day of June presumably a few hours before the UTC rollover time and the balance between what I was billed the full month and what I was billed prior to that was $53.55. Which equates to something like $20 per hour of churning nonsense since the models were going haywire at that point and didn't accomplish the current objective I was working on and was getting tons of noops. this was right after Fable came out. Happens every time a new Anthropic model comes out whether I have access to it or not.
| Usage Dates | Plan | % usage | charges | days | cost per day |
|---|---|---|---|---|---|
| July 1 - 2 4:00 AM | $200 plan | 100% | $12.90 | 2 | $6.45 |
| July 2 - July 3 | $200 plan | 100% | $181 | 2 | $90.5 |
I stopped posting here. I'm using a $200 plan about every 2 days now. I think I've spent another $200. Up to $1000 for the mont and it's July 10th. Still not done.
If you want to support of follow this research consider becoming a paid subscriber on my substack technology and security research blog. Paid subscribers can add comments and see the archives. Founding members can ask questions (i.e. consulting or training). You can also just sign up for free - no worries! All are welcome and appreciated. π©΅
https://teriradichel.substack.com
Build a script to deploy, delete, and test an AWS environment to securely run AI agents. Specifically I want to segregate my security testing, development, production, and management environments. The framework also sets up my organization with monitoring including budgets and security services used by delegated administrators (Guard Duty, etc.)
The whole point of this is to be able to quickly spin up and tear down environments for projects. As for agents I want to be able to quickly deploy new ideas. That is in part achieved by my job framework which is the follow-on project to this one, but I need first and foremost to have the secure base infrastructure in which to deploy my agent framework and agent resources.
I also spin up separate environments for each penetration test so one test cannot affect another. If I am running AI agents in an environment and they mess it up, I can tear down the whole environment and rebuild it easily. In addition, it ensures that my agents cannot affect production resources with proper security boundaries. When something is deployed incorrectly or I have a billing issue I cannot fix, I can tear down the environment to stop the building and build a new one.
A full series on what I am developing in this project can be found here:
https://teriradichel.substack.com/p/toc-aws-organizations-and-ai-agent
More granular updates on X @teriradichel and the AWS Builder Center.
https://builder.aws.com/profile?tab=articles
I'm primarily using Kiro CLI and anthropic models, though I do use Google aimode to ask questions at times and may branch out to test other models and technologies after this infrastructure is up and running.
https://github.com/2ndSightLab/ai-tracker/blob/main/issues.md
https://github.com/2ndSightLab/ai-tracker/blob/main/fixed.md
https://github.com/2ndSightLab/ai-tracker/blob/main/awswishlist.md
I started this project around March 7th. I had to take a break for about three weeks in May. I haven't really worked on anything else besides this and blog posts because I keep thinking it is "almost done." I've also been working kind of long hours to do it and figure things out.
My initial post on this project tracks the start project and initial progress in 2.5 weeks
https://teriradichel.substack.com/p/what-ive-vibe-coded-in-25-weeks
The time it takes is demonstrated by feature completion and the timestamps in this GitHub repo, though my time may be taken away for other things periodically.
Sometimes I am blocked by the system being slow or copmletely unsuable. It's hard to tell if it's the model or Kiro so I tried to measure gaps. This is a work in progress. I have limited information to work with, which I think needs to improve. We need more transparency for all metrics.
https://github.com/2ndSightLab/ai-tracker/blob/main/response-time.md
Date Range: Mar 7, 2026 - Jul 2, 2026
| Service / Resource | Total | Mar 2026 | Apr 2026 | May 2026 | Jun 2026 | Jul 2026* |
|---|---|---|---|---|---|---|
| Total costs | $2,151.92 | $359.07 | $387.55 | $621.52 | $755.02 | $28.76 |
| Kiro | $1,079.02 | $193.55 | $129.07 | $285.79 | $457.71 | $12.90 |
| Virtual Private Cloud | $411.17 | $50.07 | $118.34 | $137.58 | $104.22 | $0.97 |
| Elastic Compute Cloud - Compute | $283.88 | $39.45 | $44.28 | $100.12 | $96.80 | $3.23 |
Costs broken down by service and other details here:
https://github.com/2ndSightLab/ai-tracker/blob/main/cost.md
I was tracking all this manually but now I ahve the tracker diagram above to track deployments. But notice I haven't spent much time on actually security testing or code review. I review the code as it's being writtne a lot. I have crucial pieces of code that I move to other projects and lock down and some of that has been reviewed a bit more.
Role, policy and permission boundary deployed in root management account in AWS CloudShell.
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Role | π’ | π’ | π’ | π’ | π’ | π’ |
| Policy | π’ | π’ | π’ | π’ | π’ | π’ |
| Permission Boundary | π’ | π’ | π’ | π’ | π’ | π΄ |
| Trust policy with MFA and IP condition | π’ | π’ | π’ | π’ | π’ | π’ |
Separate reusable project that handles configuring role profiles and role assumption with MFA.
I used some previously written code as a starting point in which the role trust policies contain MFA and IPAddress conditions to assume the role and the user associated with the keys cannot do anything except asusme a role with MFA. I found at some point the CLI Auth code in my AI repos was modified to cache creds. I thought I removed that in the original repo. Do your own code review.
| Feature | Tested | Code Review | Security Review |
|---|---|---|---|
| Configure Role Profile | π’ | π’ | π’ |
| Assume Role With MFA | π’ | π‘ | π‘ |
A generic XML parser project that can be used by any bash project to move error prone and vulnerability prone code to a spearate locked down project.
| Feature | Tested | Code Review | Security Review |
|---|---|---|---|
| XML read by path | π’ | π΄ | π΄ |
| XML write by path | π’ | π΄ | π΄ |
| XML load by path | π’ | π΄ | π΄ |
| XML read by single value | π’ | π΄ | π΄ |
| XML write by single value | π’ | π΄ | π΄ |
| XML load by single value | π’ | π΄ | π΄ |
Separate reusable project provides simple and xml driven menus for consistency and easy updates
| Feature | Tested | Code Review | Security Review |
|---|---|---|---|
| Reusaable Numbered Menu with Filter by letters | π’ | π΄ | π΄ |
| Reusable y/n/e prompt | π’ | π΄ | π΄ |
| XML data driven Menu | π’ | π΄ | π΄ |
| Multi-select menu | π’ | π΄ | π΄ |
| /c to return to previous menu | π’ | π΄ | π΄ |
| common banner with lines above and below and text between | π’ | π΄ | π΄ |
| Feature | Tested | Code Review | Security Review |
|---|---|---|---|
| Run AWS Command | π’ | π΄ | π΄ |
| Track Deployed Resources | π’ | π΄ | π΄ |
| Switch Role (org/acount) | π’ | π΄ | π΄ |
| Feature | Tested | Code Review | Security Review |
|---|---|---|---|
| Analysis Report | π’ | π΄ | π΄ |
| Report time (logs per day) | π’ | π΄ | π΄ |
| Report mistake (logs per day) | π’ | π΄ | π΄ |
| Bug Report | π’ | π΄ | π΄ |
| Run all tests (all projects) | π’ | π΄ | π΄ |
| Feature | Done |
|---|---|
| Cross-Project Requiremetns and Logging | π’ |
| Feature | Done |
|---|---|
| Run test for all projects | π’ |
A project to manaage te handoff from org to environnet project so neither depends on the other. Reduces context and scope of the org and environment projects.
| Feature | Tested | Code Review | Security Review |
|---|---|---|---|
| Configure Org Types (Menu Action) | π’ | π΄ | π΄ |
| Configure Org (Menu Action) | π’ | π΄ | π΄ |
| Deploy Resources (Menu Action) | π’ | π΄ | π΄ |
| Manage Drift (Menu Action) | π’ | π΄ | π΄ |
Configure organization to deploy; define environemnt types (allowed resources)
- Environment Types Define accounts and resources that can be deployed to an environment.
- Accounts define resources that can be deployed to account on top of environmen resources.
- The resource master list maps a reosurce to a script that deploys it (to create a menu of resources to deploy)
| Feature | List | Add | Delete | Rename | Edit | Menus | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|---|---|---|
| Resource Types | π’ | π’ | π’ | π’ | n/a | π’ | π’ | π΄ | π΄ |
| Account Types | π’ | π’ | π’ | n/a | π’ | π’ | π’ | π΄ | π΄ |
| Account Resource Types | π’ | π’ | π’ | π’ | n/a | π’ | π’ | π΄ | π΄ |
| Environment Types | π’ | π’ | π’ | π’ | n/a | π’ | π’ | π΄ | π΄ |
| Environment Type Account Types | π’ | π’ | π’ | n/a | π’ | π’ | π’ | π΄ | π΄ |
| Environment Type Resource Types | π’ | π’ | π’ | n/a | π’ | π’ | π’ | π΄ | π΄ |
| Default Org (define mangemnt env) | π’ | n/a | n/a | n/a | π’ | π’ | π’ | π΄ | π΄ |
| Default Org (define backup env) | π’ | n/a | n/a | n/a | π’ | π’ | π’ | π΄ | π΄ |
| Resource type Dependencies | π’ | π’ | π’ | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Bootstrap / Account Role Resource Confit | π’ | π’ | π’ | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Tested | Code Review | Security Review |
|---|---|---|---|
| Management Environment - Type ID | π’ | π΄ | π΄ |
| Backup Environment - Type ID | π’ | π΄ | π΄ |
| View Settings XML | π’ | π΄ | π΄ |
| Organization Diagram - All | π’ | π΄ | π΄ |
| Organization Diagram - Enviroments | π’ | π΄ | π΄ |
| Organization Diagram - Accounts | π’ | π΄ | π΄ |
| Organization Diagram - Per org/env resources | π’ | π΄ | π΄ |
| Organization Diagram - Type descriptions | π’ | π΄ | π΄ |
| Actions File (menus) | π’ | π΄ | π΄ |
- Multiple enviroments of a single type can be created (Web-Dev, Web-Prod, etc.)
- Multiple accounts of the same type can be created (Pentest1, Pentest2, etc.)
- The resource list is pullled from the type configuration, not altered here.
| Feature | List | Add | Delete | Rename | Menus | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|---|---|
| Organization | π’ | π’ | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Evironments | π’ | π’ | π’ | n/a | π’ | π’ | π΄ | π΄ |
| Environment Accounts | π’ | π’ | π’ | n/a | π’ | π’ | π΄ | π΄ |
| Feature | Run | Tested | Code Review | Security Review |
|---|---|---|---|---|
| Create CLI Profiles | π‘ | π‘ | π΄ | π΄ |
| Select CLI Profiles | π’ | π’ | π΄ | π΄ |
| Test CLI Porfile | π’ | π’ | π΄ | π΄ |
| Look up Org, Root, Acount ID | π’ | π’ | π΄ | π΄ |
| Organization Seettings | π’ | π’ | π΄ | π΄ |
| Environment Settings | π‘ | π‘ | π΄ | π΄ |
| List Available Account Resources | π’ | π’ | π΄ | π΄ |
| Organization Diagram - All | π’ | π’ | π΄ | π΄ |
| Organization Diagram - Enviroments | π’ | π’ | π΄ | π΄ |
| Organization Diagram - Accounts | π’ | π’ | π΄ | π΄ |
| Organization Diagram - Per org/env resources | π’ | π’ | π΄ | π΄ |
| Organization Diagram - Type descriptions | π’ | π’ | π΄ | π΄ |
| Actions File (menus) | π’ | π’ | π΄ | π΄ |
| Feature | Menus | Run | Tested | Code Review | Security Review |
|---|---|---|---|---|---|
| Select Organization | π’ | π’ | π’ | π΄ | π΄ |
| Deploy Org Resources | π’ | π’ | π’ | π΄ | π΄ |
| Select Env | π’ | π’ | π’ | π΄ | π΄ |
| Deploy Env Resources | π’ | π’ | π’ | π΄ | π΄ |
| Select Account | π’ | π’ | π’ | π΄ | π΄ |
| Deploy Account Resources | π’ | π’ | π’ | π΄ | π΄ |
| Deployed Resources Tracking | π’ | π’ | π’ | π΄ | π΄ |
| Deployed Resources Diagram | π’ | π’ | π’ | π΄ | π΄ |
| Deploy With Confirm | π’ | π’ | π’ | π΄ | π΄ |
| Deploy No Prompt | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Run | Tested | Code Review | Security Review |
|---|---|---|---|---|
| Drift Report | π‘ | π΄ | π΄ | π΄ |
| Drift Delete Unauthorized Resources | π΄ | π΄ | π΄ | π΄ |
| Drift Deploy Missing Resources | π΄ | π΄ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Organization | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Enable All Features | π’ | π’ | π’ | π’ | π΄ | π΄ |
| SCP: env-allowed-regions [env] | π’ | π’ | π’ | π’ | π΄ | π΄ |
| SCP: IMDSV1 [env] | π’ | π’ | π’ | π’ | π΄ | π΄ |
| SCP: always-denied-actions [root] | π’ | π’ | π’ | π’ | π΄ | π΄ |
| SCP: always-default-org-root [root] | π’ | π’ | π’ | π’ | π΄ | π΄ |
| SCP: deploy-scp-require-imdsv2.sh [root] | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| OU | π’ | π’ | π’ | π’ | π΄ | π΄ |
| SCP: deny-external-access | π’ | π’ | π’ | π’ | π΄ | π΄ |
| SCP: account specific OU only allowing resources deployed | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
| SCP: for different regions than org regions (more restrictive) | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
| Rename OU | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Accounts | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Move account to OU | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Account alias | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Admin roles | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Admin role policy | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delete Default VPC | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Rename account, alias, email, name | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| OU | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Deny All SCP | π’ | π’ | π’ | π’ | π΄ | π΄ |
Environment where people log into EC2 instances.
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| OU | π’ | π’ | π’ | π’ | π΄ | π΄ |
| SCP | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Accounts | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Budgets | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Delete Default VPCs | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Admin roles | π’ | π’ | π’ | π’ | π΄ | π΄ |
| log to security account | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
IAM users in work environment
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| IAM User | π’ | π’ | π’ | π’ | π΄ | π΄ |
KMS keys used in enviroment
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| KMS keys | π’ | π’ | π’ | π’ | π΄ | π΄ |
| KMS policies | π’ | π’ | π’ | π’ | π΄ | π΄ |
| KMS key aliases | π’ | π’ | π’ | π’ | π΄ | π΄ |
Network resources shared to environmeng via RAM
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| VPC Flow Logs Role | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Jobs VPC | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Jobs Subnet | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Jobs NACL | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Route Table + Routes | π’ | π’ | π’ | π’ | π΄ | π΄ |
| VPC Endpoints | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Vpc Endoint Security Groups | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Jobs VCP Flow Logs | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Jobs Ram Share | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Work VPC | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Work Subnet | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Work NACL | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Work Route Table + Routes | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Work IGW | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Work Ram Share | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Work VCP Flow Logs | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Jobs Auth VPC | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Jobs Auth Subnet | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Jobs Auth NACL | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Jobs Auth Route Auth Table + Routes | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Jobs AUth IGW | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Jobs Auth VCP Flow Logs | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Jobs Auth Ram Share | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Remote Access Prefix List | π’ | π’ | π’ | π’ | π΄ | π΄ |
| AWS Services Prefix Lists | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| SSH Security Group | π’ | π’ | π’ | π’ | π΄ | π΄ |
| RDP Security Group | π’ | π’ | π’ | π’ | π΄ | π΄ |
| HTTP/HTTPS Security Group | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Account: log to security account | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
Account where people log into EC2 instances.
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Base Ubuntu AMI | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Base Amazon Linux AMI | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
| Burp AMI | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Collab AMI | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
| Kiro Dev AMI | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
| Claude Code Ami | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
| Codex Ami | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
Account where people log into EC2 instances.
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Code Commit Repo | π’ | π’ | π’ | π’ | π΄ | π΄ |
| ECR | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
Account where people log into EC2 instances.
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| IPAM pool | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| IPAM EIP allocation | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| S3 buckets (with KMS) | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Bucket policies | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Kiro Dev ENI | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Kiro Instance Role | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Kiro Instance | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Burp ENI | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Burp Instance Role | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Burp Instance | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Collab ENI | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Collab Instance Role | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
| Collab Instance | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
| Claude Code Dev ENI | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Claude Code Instance Role | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Claude Code Instance | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Codex Dev ENI | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Codex Instance Role | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Codex Instance | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | |
| Webs | π‘ | π‘ | π΄ | π΄ | π΄ | π΄ |
| log to security account | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
If I use CloudFront have to allow us-east-1 for ACM Cert. Lock down when not acively making chanages.
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Job Auth Lambdas | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Auth Lambda VPC Config | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| ACM Certificate | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| API Gateway | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| API Gateway CNAME | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| DynamoDB | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| S3 buckets | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Job Instance Role | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Job ENI | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Job EC2 Instance | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Job AMI | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Job Run (other resources, lambdas, micro VMs? TBD) | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
The management environment contains accounts where my organization deletegated administrators exist.
IAM users in management environment
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Account | π’ | π’ | π’ | π’ | π΄ | π΄ |
| IAM User | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Org resource policy | π’ | π’ | π’ | π’ | π΄ | π΄ |
IAM users in work environment
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Acoount resources | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Identity Center (requires interaction) | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Kiro (requires interaction) | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Account | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate IPAM admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Firewall Manager admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Network Manager admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate VPC Reachability Analyzer admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| IPAM | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Account | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Security Hub admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate GuardDuty admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate CloudTrail admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate AWS Config admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Macie admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Inspector admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate IAM Access Analyzer admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Audit Manager admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Health admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Detective admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| S3 Logs buckets (one per env) | π’ | π’ | π’ | π’ | π΄ | π΄ |
| S3 Logs bucket - with encryption | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Configure GuardDuty | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Configure Security Hub | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Configure CloudTrail | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Configure AWS Config | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Configure Macie | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Configure Inspector | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Configure IAM Access Analyzer | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Configure Security Alerts | π‘ | π΄ | π΄ | π΄ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Account, Move to OU, Alias | π’ | π’ | π’ | π’ | π΄ | π΄ |
| KMS Log Key | π’ | π’ | π’ | π’ | π΄ | π΄ |
| KMS Log Key Alias | π’ | π’ | π’ | π’ | π΄ | π΄ |
| KMS Log Key Policy | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Account, Move to OU, Alias | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Cost Optimization Hub admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Delegate Compute Optimizer admin | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Account, Move to OU, Alias | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Org Policy (org delegated admin) | π’ | π’ | π’ | π’ | π΄ | π΄ |
| Feature | Run | Tested | Code Review | Security Review |
|---|---|---|---|---|
| Deploy Web Site | π΄ | π΄ | π΄ | π΄ |
| IAM Acccess Analyzer Report | π΄ | π΄ | π΄ | π΄ |
| Prowler Report | π΄ | π΄ | π΄ | π΄ |
| Enable AWS default Org Role | π΄ | π΄ | π΄ | π΄ |
| Disable AWS default Org Role | π΄ | π΄ | π΄ | π΄ |
| Move website | π΄ | π΄ | π΄ | π΄ |
| Lock Environment (apply deny-all SCP) | π΄ | π΄ | π΄ | π΄ |
| Unlock Environment (remove deny-all SCP) | π΄ | π΄ | π΄ | π΄ |
| Lock Account (apply deny-all SCP) | π΄ | π΄ | π΄ | π΄ |
| Unlock Account (remove deny-all SCP) | π΄ | π΄ | π΄ | π΄ |
| Transfer GitHub repo to Code Commit | π΄ | π΄ | π΄ | π΄ |
| Transfer one Code Commit repo to Another | π΄ | π΄ | π΄ | π΄ |
| Troubleshoot Job | π΄ | π΄ | π΄ | π΄ |
| Analyze Network Traffic | π΄ | π΄ | π΄ | π΄ |
| Analyze System Logs | π΄ | π΄ | π΄ | π΄ |
| Move Domain | π΄ | π΄ | π΄ | π΄ |
| Move Hosted Zone | π΄ | π΄ | π΄ | π΄ |
| Register domain | π΄ | π΄ | π΄ | π΄ |
| Update Parent Hosted Zone (specific steps TBD) | π΄ | π΄ | π΄ | π΄ |
| Share all amis to all acounts in ou | π΄ | π΄ | π΄ | π΄ |
| Share AMI To External | π΄ | π΄ | π΄ | π΄ |
| Archive Acount | π΄ | π΄ | π΄ | π΄ |
Back up infrastructure segregated from other infrastructure
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Backup OU | π’ | π’ | π’ | π’ | π΄ | π΄ |
| budgets | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| delete default vpcs | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| admin roles | π’ | π’ | π’ | π’ | π΄ | π΄ |
| log to security account | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Delegate Backup admin | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Delegate Backup admin | π‘ | π‘ | π‘ | π‘ | π΄ | π΄ |
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Backup Account Per Environment | π΄ | π΄ | π΄ | π΄ | π΄ | π΄ |
Deploy environment to single account (account in a different organization or standalone)
| Feature | Deploy | Delete | Verify | Tested | Code Review | Security Review |
|---|---|---|---|---|---|---|
| Network | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| User | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Role | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |
| Jobs Instance | π‘ | π‘ | π‘ | π΄ | π΄ | π΄ |