helixordevelopers

AWS Well-Architected alignment

This page maps a Decision Runtime deployment on AWS to the six pillars of the AWS Well-Architected Framework. For each pillar it shows what the runtime provides, what you configure on AWS, and where a gap remains or a feature is Planned.

Helixor does not certify your workload

Well-Architected reviews assess a workload, not a component. You perform the review, or an AWS partner performs it with you, against your whole workload. This page helps you answer the questions that touch the Decision Runtime. It is not an attestation. Question areas below are described in our own words; use the current AWS Well-Architected Tool for the authoritative wording.

At a glance#

AWS pillarHelixor pageMain things you configure
Operational excellenceOperational excellenceCI with golden tests, CloudWatch Logs and EMF metrics, runbooks, deployment circuit breaker
SecuritySecuritySecrets Manager, KMS, IAM roles, security groups, VPC endpoints, S3 Object Lock
ReliabilityReliabilityExec health checks, multi-AZ tasks, versioned license and pack pairs, expiry alarms
Performance efficiencyPerformance efficiencyPlacement choice, one vCPU per process, measured sizing, arm64 benchmarks
Cost optimizationCost optimizationCost allocation tags, right-sized tasks and functions, rule-based escalation
SustainabilitySustainabilityLocal decisions instead of model inference, scale to zero, efficient instance types

Operational excellence#

AWS focus areas: organizing ownership, preparing workloads to be operated, operating with visibility into health, and evolving through learning.

Runtime providesYou configure on AWSGap or Planned
Declarative playbooks compiled into versioned packs. A CLI for compile, one-shot run and license inspection, suitable for CI. action, triggered rule IDs, receipt_hash and latency_us on every result. A pipeline (for example CodePipeline and CodeBuild) that compiles each pack and runs its golden tests. ECR and S3 as the artifact stores. CloudWatch Logs for one structured line per decision. EMF metrics and CloudWatch alarms. The ECS deployment circuit breaker with rollback. Runbooks in Systems Manager documents or your own wiki. No built-in metrics endpoint or tracing Planned. The runtime does not enforce pack version ordering, so your pipeline must.

Security#

AWS focus areas: security foundations and governance, identity and access management, detection, infrastructure protection, data protection, incident response and application security.

Runtime providesYou configure on AWSGap or Planned
Ed25519 license verification before any pack is unsealed. AES-256-GCM encrypted packs bound to a pack ID and a license, with an integrity check. In-memory unsealing. No network calls during evaluation. Remedies that replace sensitive values. License in Secrets Manager, encrypted with a customer managed KMS key, and readable only by the roles that start decision workloads. Sidecar bound to loopback, or a shared service behind ALB mutual TLS, VPC Lattice IAM auth or a private API Gateway. Security groups without open egress, VPC endpoints, optionally Network Firewall. Logs without payloads or matched_items. Audit export to S3 Object Lock in compliance mode. VPC Flow Logs, CloudTrail and GuardDuty for detection. The decision service's authentication is a single shared bearer token over plain HTTP; TLS and per-caller credentials come from the front door. The license carries the pack key, so it must be protected as a secret. No host binding or revocation Planned. Receipts are unkeyed; signed and chained receipts are Planned. No KMS key wrapping in the runtime Planned.

Reliability#

AWS focus areas: foundations such as quotas and network topology, workload architecture, change management and failure management.

Runtime providesYou configure on AWSGap or Planned
Fail-closed loading: a missing, tampered, expired or unentitled license or pack stops start-up with a typed error. No external dependencies once a pack is loaded. Stateless evaluation that scales horizontally. Tasks spread across at least two Availability Zones. Exec container health checks that run a real evaluation. Application dependency on the sidecar being healthy. Callers that treat errors and timeouts as blocks. License and pack deployed as one versioned pair, with rollback to the previous pair. A daily EventBridge Scheduler check of license expiry, with an alarm 30 days out. GET /v1/health shows liveness and the loaded pack, not license state; a readiness endpoint that reports license state is Planned. A running engine stops evaluating a compiled pack once the license's grace period ends, with no earlier warning than license_status in results.

Performance efficiency#

AWS focus areas: architecture selection, compute and hardware, data management, networking, and a culture of measuring and experimenting.

Runtime providesYou configure on AWSGap or Planned
In-process evaluation measured in microseconds by bench_engine_time.py (see Reproduce). latency_us per result, covering evaluation only. Pure Python on x86_64 and arm64. The closest placement that fits: in-process, then sidecar, then shared service. Tasks and functions sized from your own benchmark, at about one vCPU per process. Graviton and x86 compared on your workload. Provisioned concurrency for Lambda if cold starts matter. Caller-side latency metrics. Evaluation is single-threaded per process. A compiled native runtime is Planned. No published memory footprint, so measure it.

Cost optimization#

AWS focus areas: cloud financial management, expenditure and usage awareness, cost-effective resources, matching supply to demand, and optimizing over time.

Runtime providesYou configure on AWSGap or Planned
No model tokens and no data transfer per local decision (tokens_spent and egress_bytes are always 0). A small CPU-only footprint. Cost allocation tags (Application, Environment, CostCenter) with ECS tag propagation. Right-sized Fargate tasks and Lambda memory. Autoscaling on CPU. VPC endpoints instead of NAT for isolated workloads. Rule-based escalation to hosted reasoning, counted as a metric. Log retention matched to need. Per-decision cost figures depend on your hardware and must be measured. License terms are set in your agreement.

Sustainability#

AWS focus areas: Region selection, aligning capacity to demand, efficient software and architecture, data management, efficient hardware and services, and a culture of improvement.

Runtime providesYou configure on AWSGap or Planned
Decisions on CPU without model inference or accelerators. Runs on arm64. Local decisions first, with escalation only by rule. Lambda or autoscaled services that scale down with demand. Graviton where benchmarks favor it. No duplicate evaluation across hops. Compact logs with lifecycle rules. The AWS customer carbon footprint tool for reporting. The runtime reports no energy or carbon figures.

Preparing for a Well-Architected review#

Facts to have ready#

  • Placement: which pattern you use: in-process, ECS sidecar, EKS sidecar, Lambda or shared service. Also which accounts, Regions and Availability Zones it runs in.
  • Packs: the pack IDs and versions in each environment, their SHA-256 digests, the source commit, the golden test results and who approved them.
  • License handling: where each environment's license is stored, the KMS key that protects it, which roles can read it, its expiry date and the renewal procedure.
  • Network: how the decision service is reached (loopback or front door and its authentication), security group rules, VPC endpoints and the egress policy.
  • Data flows: what enters each decision, what leaves (only clean_text and receipts), what is logged, and what, if anything, is escalated to hosted reasoning.
  • Audit: where receipts are stored, the Object Lock retention, and any signing you add.
  • Operations: health checks, alarms, dashboards, runbooks, the rollback procedure and the last time it was exercised.
  • Sizing: your benchmark results, task and function sizes, scaling policies and cost allocation tags.

Where to find the answers#

Review areaWhat reviewers look forSee
Identity and accessLeast-privilege roles for reading the license and packs; no long-lived credentials; authenticated access to the decision serviceAWS, Security
Data protectionEncryption at rest and in transit; handling of sensitive values in results and logsSecurity, AWS
Detective controlsLogs, audit trail, tamper evidence and alertingOperational excellence, AWS
Infrastructure protectionNetwork isolation, egress control, hardened containersDeployment patterns, AWS
Change managementHow rule changes are reviewed, tested, promoted and rolled back; license rotationOperational excellence, Reliability
Failure managementFail-closed behavior, health checks, recovery, expiry monitoringReliability
Workload architectureComponent boundaries, dependencies on the decision path, concurrency modelComponents, Reliability
Selection (compute, architecture)Why this placement and instance type; how it was measuredPerformance efficiency
Cost-aware architectureTagging, right-sizing, scaling with demand, escalation costCost optimization
SustainabilityAvoiding unnecessary inference and idle capacity; measuring efficiencySustainability

Items to record as accepted risks or planned improvements#

Some reviews will flag items that depend on runtime features not yet shipped. Record them with the compensating control you use:

ItemCompensating control today
Service authentication is one shared token without TLSLoopback bind, or an authenticating front door that terminates TLS plus a security group that admits only the front door
Unkeyed receiptsS3 Object Lock in compliance mode; optional KMS signing of records
License carries the pack key; no revocation or host bindingSecrets Manager with a customer managed key; narrowly scoped IAM; separate licenses per environment
Zero egress is not enforced by the runtimeSecurity groups, VPC endpoints, optionally Network Firewall; Flow Logs alerts
No runtime metrics or readiness endpointEMF metrics from your application; exec health checks