| name | aws-well-architected-review |
| description | Perform an AWS Well-Architected Framework review of the current workload IaC and architecture, generating findings and GitHub issues for improvements. |
AWS Well-Architected Review
This workflow performs a structured AWS Well-Architected Framework (WAF) review against your workload's IaC files and deployed infrastructure. It identifies risks across all 6 WAF pillars and creates GitHub issues to track remediation.
Prerequisites
- AWS CLI configured and authenticated
- IaC files present in the repository (Terraform, CloudFormation, CDK, or SAM)
- GitHub MCP server configured and authenticated
Workflow Steps
Step 1: Load Well-Architected Framework Reference
Fetch current AWS WAF best practices:
https://docs.aws.amazon.com/wellarchitected/latest/framework/welcome.html
- Pillar-specific lenses relevant to the workload type (Serverless, SaaS, etc.)
Step 2: Discover IaC & Architecture
Scan the repository for IaC files:
- Terraform:
**/*.tf
- CloudFormation/SAM:
**/*.yaml, **/*.json (CFn templates)
- CDK:
lib/**/*.ts, bin/**/*.ts, cdk.json
Identify key AWS services in use (compute, data, networking, security, observability) and generate a Mermaid architecture diagram.
Step 3: Pillar-by-Pillar Review
Pillar 1: Operational Excellence
Pillar 2: Security
Pillar 3: Reliability
Pillar 4: Performance Efficiency
Pillar 5: Cost Optimization
Pillar 6: Sustainability
Step 4: Risk Classification
For each finding, classify:
- High Risk: Security vulnerability, single point of failure, no backup/recovery
- Medium Risk: Suboptimal reliability, cost inefficiency, performance concern
- Low Risk: Best practice deviation, minor optimization opportunity
Step 5: User Confirmation
๐๏ธ AWS Well-Architected Review Summary
๐ Review Results:
โข IaC Files Analyzed: X
โข AWS Services Identified: Y
โข Total Findings: Z
โข High Risk: A (immediate action required)
โข Medium Risk: B (should address soon)
โข Low Risk: C (nice to have)
๐ด Top High Risk Findings:
1. [Pillar]: [Finding] โ [Why it matters]
2. [Pillar]: [Finding] โ [Why it matters]
๐ก This will create Z individual GitHub issues + 1 EPIC issue.
โ Proceed with creating GitHub issues? (y/n)
Step 6: Create Individual Finding Issues
Label with "well-architected" and the pillar name (e.g., "security", "reliability").
Title: [WAF-<PILLAR>] [Brief Finding] โ [Risk Level]
Body:
## ๐๏ธ Well-Architected Finding: [Brief Title]
**Pillar**: [Name] | **Risk Level**: [High/Medium/Low] | **Effort**: [Low/Medium/High]
### ๐ Description
[Clear explanation of the finding and why it matters]
### ๐ง Remediation
**IaC Fix** (preferred):
```hcl
# Terraform example
resource "aws_s3_bucket_server_side_encryption_configuration" "example" {
bucket = aws_s3_bucket.example.id
rule {
apply_server_side_encryption_by_default {
sse_algorithm = "aws:kms"
}
}
}
```
**AWS CLI fallback**:
```bash
aws s3api put-bucket-encryption --bucket <name> \
--server-side-encryption-configuration '{"Rules":[{"ApplyServerSideEncryptionByDefault":{"SSEAlgorithm":"aws:kms"}}]}'
```
### ๐ AWS Reference
- [WAF Best Practice Link]
- [AWS Documentation Link]
### โ
Validation
- [ ] Change implemented in IaC and deployed
- [ ] AWS Config rule passes (if applicable)
- [ ] Security Hub finding resolved (if applicable)
**Well-Architected Question**: [WAF question this maps to]
Step 7: Create EPIC Tracking Issue
Label with "well-architected" and "epic".
Title: [EPIC] AWS Well-Architected Review โ X findings across 6 pillars
Body: Executive summary with pillar breakdown table (finding counts by pillar and risk level), Mermaid architecture diagram, prioritized checklist linking all individual issues (High โ Medium โ Low), and success criteria:
- All High-risk findings resolved
- Medium findings have accepted mitigation plans
- No regression in existing CloudWatch alarms or Config rules
Error Handling
- No IaC Files Found: Limit review to live resource discovery via AWS CLI and note the gap
- Insufficient AWS Permissions: List required read-only permissions for the review
- GitHub Creation Failure: Output all findings as formatted markdown to console
Success Criteria
- โ
All 6 WAF pillars reviewed against IaC and live infrastructure
- โ
All findings classified by risk level and pillar
- โ
Actionable remediation steps with IaC examples for each finding
- โ
GitHub issues created for team tracking
- โ
Architecture diagram generated for EPIC context
- โ
AWS documentation references included