AWS Well-Architected alignment
This page maps a Decision Runtime deployment on AWS to the six pillars of the AWS Well-Architected Framework. For each pillar it shows what the runtime provides, what you configure on AWS, and where a gap remains or a feature is Planned.
Helixor does not certify your workload
Well-Architected reviews assess a workload, not a component. You perform the review, or an AWS partner performs it with you, against your whole workload. This page helps you answer the questions that touch the Decision Runtime. It is not an attestation. Question areas below are described in our own words; use the current AWS Well-Architected Tool for the authoritative wording.
At a glance#
| AWS pillar | Helixor page | Main things you configure |
|---|---|---|
| Operational excellence | Operational excellence | CI with golden tests, CloudWatch Logs and EMF metrics, runbooks, deployment circuit breaker |
| Security | Security | Secrets Manager, KMS, IAM roles, security groups, VPC endpoints, S3 Object Lock |
| Reliability | Reliability | Exec health checks, multi-AZ tasks, versioned license and pack pairs, expiry alarms |
| Performance efficiency | Performance efficiency | Placement choice, one vCPU per process, measured sizing, arm64 benchmarks |
| Cost optimization | Cost optimization | Cost allocation tags, right-sized tasks and functions, rule-based escalation |
| Sustainability | Sustainability | Local decisions instead of model inference, scale to zero, efficient instance types |
Operational excellence#
AWS focus areas: organizing ownership, preparing workloads to be operated, operating with visibility into health, and evolving through learning.
| Runtime provides | You configure on AWS | Gap or Planned |
|---|---|---|
Declarative playbooks compiled into versioned packs. A CLI for compile, one-shot run and license inspection, suitable for CI. action, triggered rule IDs, receipt_hash and latency_us on every result. |
A pipeline (for example CodePipeline and CodeBuild) that compiles each pack and runs its golden tests. ECR and S3 as the artifact stores. CloudWatch Logs for one structured line per decision. EMF metrics and CloudWatch alarms. The ECS deployment circuit breaker with rollback. Runbooks in Systems Manager documents or your own wiki. | No built-in metrics endpoint or tracing Planned. The runtime does not enforce pack version ordering, so your pipeline must. |
Security#
AWS focus areas: security foundations and governance, identity and access management, detection, infrastructure protection, data protection, incident response and application security.
| Runtime provides | You configure on AWS | Gap or Planned |
|---|---|---|
| Ed25519 license verification before any pack is unsealed. AES-256-GCM encrypted packs bound to a pack ID and a license, with an integrity check. In-memory unsealing. No network calls during evaluation. Remedies that replace sensitive values. | License in Secrets Manager, encrypted with a customer managed KMS key, and readable only by the roles that start decision workloads. Sidecar bound to loopback, or a shared service behind ALB mutual TLS, VPC Lattice IAM auth or a private API Gateway. Security groups without open egress, VPC endpoints, optionally Network Firewall. Logs without payloads or matched_items. Audit export to S3 Object Lock in compliance mode. VPC Flow Logs, CloudTrail and GuardDuty for detection. |
The decision service's authentication is a single shared bearer token over plain HTTP; TLS and per-caller credentials come from the front door. The license carries the pack key, so it must be protected as a secret. No host binding or revocation Planned. Receipts are unkeyed; signed and chained receipts are Planned. No KMS key wrapping in the runtime Planned. |
Reliability#
AWS focus areas: foundations such as quotas and network topology, workload architecture, change management and failure management.
| Runtime provides | You configure on AWS | Gap or Planned |
|---|---|---|
| Fail-closed loading: a missing, tampered, expired or unentitled license or pack stops start-up with a typed error. No external dependencies once a pack is loaded. Stateless evaluation that scales horizontally. | Tasks spread across at least two Availability Zones. Exec container health checks that run a real evaluation. Application dependency on the sidecar being healthy. Callers that treat errors and timeouts as blocks. License and pack deployed as one versioned pair, with rollback to the previous pair. A daily EventBridge Scheduler check of license expiry, with an alarm 30 days out. | GET /v1/health shows liveness and the loaded pack, not license state; a readiness endpoint that reports license state is Planned. A running engine stops evaluating a compiled pack once the license's grace period ends, with no earlier warning than license_status in results. |
Performance efficiency#
AWS focus areas: architecture selection, compute and hardware, data management, networking, and a culture of measuring and experimenting.
| Runtime provides | You configure on AWS | Gap or Planned |
|---|---|---|
In-process evaluation measured in microseconds by bench_engine_time.py (see Reproduce). latency_us per result, covering evaluation only. Pure Python on x86_64 and arm64. |
The closest placement that fits: in-process, then sidecar, then shared service. Tasks and functions sized from your own benchmark, at about one vCPU per process. Graviton and x86 compared on your workload. Provisioned concurrency for Lambda if cold starts matter. Caller-side latency metrics. | Evaluation is single-threaded per process. A compiled native runtime is Planned. No published memory footprint, so measure it. |
Cost optimization#
AWS focus areas: cloud financial management, expenditure and usage awareness, cost-effective resources, matching supply to demand, and optimizing over time.
| Runtime provides | You configure on AWS | Gap or Planned |
|---|---|---|
No model tokens and no data transfer per local decision (tokens_spent and egress_bytes are always 0). A small CPU-only footprint. |
Cost allocation tags (Application, Environment, CostCenter) with ECS tag propagation. Right-sized Fargate tasks and Lambda memory. Autoscaling on CPU. VPC endpoints instead of NAT for isolated workloads. Rule-based escalation to hosted reasoning, counted as a metric. Log retention matched to need. |
Per-decision cost figures depend on your hardware and must be measured. License terms are set in your agreement. |
Sustainability#
AWS focus areas: Region selection, aligning capacity to demand, efficient software and architecture, data management, efficient hardware and services, and a culture of improvement.
| Runtime provides | You configure on AWS | Gap or Planned |
|---|---|---|
| Decisions on CPU without model inference or accelerators. Runs on arm64. | Local decisions first, with escalation only by rule. Lambda or autoscaled services that scale down with demand. Graviton where benchmarks favor it. No duplicate evaluation across hops. Compact logs with lifecycle rules. The AWS customer carbon footprint tool for reporting. | The runtime reports no energy or carbon figures. |
Preparing for a Well-Architected review#
Facts to have ready#
- Placement: which pattern you use: in-process, ECS sidecar, EKS sidecar, Lambda or shared service. Also which accounts, Regions and Availability Zones it runs in.
- Packs: the pack IDs and versions in each environment, their SHA-256 digests, the source commit, the golden test results and who approved them.
- License handling: where each environment's license is stored, the KMS key that protects it, which roles can read it, its expiry date and the renewal procedure.
- Network: how the decision service is reached (loopback or front door and its authentication), security group rules, VPC endpoints and the egress policy.
- Data flows: what enters each decision, what leaves (only
clean_textand receipts), what is logged, and what, if anything, is escalated to hosted reasoning. - Audit: where receipts are stored, the Object Lock retention, and any signing you add.
- Operations: health checks, alarms, dashboards, runbooks, the rollback procedure and the last time it was exercised.
- Sizing: your benchmark results, task and function sizes, scaling policies and cost allocation tags.
Where to find the answers#
| Review area | What reviewers look for | See |
|---|---|---|
| Identity and access | Least-privilege roles for reading the license and packs; no long-lived credentials; authenticated access to the decision service | AWS, Security |
| Data protection | Encryption at rest and in transit; handling of sensitive values in results and logs | Security, AWS |
| Detective controls | Logs, audit trail, tamper evidence and alerting | Operational excellence, AWS |
| Infrastructure protection | Network isolation, egress control, hardened containers | Deployment patterns, AWS |
| Change management | How rule changes are reviewed, tested, promoted and rolled back; license rotation | Operational excellence, Reliability |
| Failure management | Fail-closed behavior, health checks, recovery, expiry monitoring | Reliability |
| Workload architecture | Component boundaries, dependencies on the decision path, concurrency model | Components, Reliability |
| Selection (compute, architecture) | Why this placement and instance type; how it was measured | Performance efficiency |
| Cost-aware architecture | Tagging, right-sizing, scaling with demand, escalation cost | Cost optimization |
| Sustainability | Avoiding unnecessary inference and idle capacity; measuring efficiency | Sustainability |
Items to record as accepted risks or planned improvements#
Some reviews will flag items that depend on runtime features not yet shipped. Record them with the compensating control you use:
| Item | Compensating control today |
|---|---|
| Service authentication is one shared token without TLS | Loopback bind, or an authenticating front door that terminates TLS plus a security group that admits only the front door |
| Unkeyed receipts | S3 Object Lock in compliance mode; optional KMS signing of records |
| License carries the pack key; no revocation or host binding | Secrets Manager with a customer managed key; narrowly scoped IAM; separate licenses per environment |
| Zero egress is not enforced by the runtime | Security groups, VPC endpoints, optionally Network Firewall; Flow Logs alerts |
| No runtime metrics or readiness endpoint | EMF metrics from your application; exec health checks |