water park

Design docs

These are the documents the lessons send you to. The decisions ledger is the why, written down. The house rules and the prescriptions are the pattern the IAM course builds, made checkable. The estate is what the repo manages, which is water park’s own AWS. The threat model is the failure-mode story. The AWS desk is the agent app the courses build. The notes under design/ carry the depth behind single lessons.

Some of these docs were written when water park was an IAM access-repo kit rather than a course, and a few still read that way. Where they name a toolchain, decision 31 is what the course actually runs on. Project planning and archived analysis live outside the site, in project/ .

  1. Appendix: lessons not yet scheduled
  2. Decisions
  3. Live session guide
  4. Prescriptions
  5. Principles (IAM scenario)
  6. The AWS desk
  7. The estate
  8. Threat and credential model

Design notes

  1. Design: break-glass guarantees
  2. Design: delegated role creation (decision 20)
  3. Design: guardrail rollout (the upgrade story)
  4. Design: multi-account AWS
  5. Design: personas
  6. Design: the agentic layer
  7. Design: workload identity and federation trust (SPIFFE seam)