Build your entire infrastructure in
days, not months
Stand up a scalable, secure, and compliant multi-account AWS architecture.  Fully managed by OpenTofu/Terraform.
Trusted by DevOps Teams at
Skip the DIY and get it done right, faster
All companies share the same fundamental infrastructure needs. So why waste time building it all from scratch? Gruntwork gives you all the pieces you need.
AWS Landing Zone
Best-practice DevOps standards and baselines for a well-architected AWS landing zone.
Amazon Web Services logo
Proven Modules
300+ infrastructure as code modules to set up AWS foundations, run apps, and store data.
Image
IaC Management Platform
The tools you need to deploy, manage, update, and tear down infrastructure seamlessly.
Image
Accelerate your path to well-architected infrastructure on AWS
Networking, compute, pipelines, automation, and more — Gruntwork delivers a complete, fully integrated DevOps foundation built on proven patterns that just works.
Step
1
IaC tooling and best practices
Gruntwork works with you to:
Image
Set up OpenTofu and Terragrunt
Image
Organize your code in a proven folder structure and pattern
Image
Set up tagging and naming patterns for AWS resources
Image
Define global variables and overwrites as you descend down your folder structure
Image
Define a default set of OpenTofu/Terraform module input values used by all module instances to keep your code DRY
Image
Step
2
Infrastructure architecture and repo structure
Gruntwork provides:
Image
A git repo for your infrastructure configured following best practices for multi-account multi-region
Image
A flexible multi-environment pattern with Terragrunt stacks that is proven to scale
Image
A baseline branch protection configuration
Image
Delegated per team repository structure
Step
3
Accounts and environment structures
Gruntwork works with you to set up:
Image
Gruntwork Account Factory
 — create new AWS accounts with best-practice baselines
Image
AWS multi-account structure
 — AWS Organizations, OUs, cross-account IAM roles
Image
AWS Control Tower and recommended configuration
Image
Guardrails
 — SCPs, AWS Config, GuardDuty, CloudTrail, etc
Image
Auth
 — AWS IAM Identity Center (SSO) for all accounts, IAM roles, OIDC, etc
Image
Network architecture
 — VPCs, subnets, route tables, VPN, Transit Gateway, etc
Image
AWS Well-Architected Framework
Step
4
Infrastructure deployment and compliance
Gruntwork works with you to set up:
Image
Gruntwork Pipelines
 — an IaC pipeline that consolidates privileged access, enforces least-privilege, includes auditing, locking, drift detection etc
Image
GitHub Actions / GitLab CI integration to deploy all your Terragrunt, OpenTofu, and Terraform code directly using Gruntwork Pipelines
Image
CIS compliant modules
 — all IaC are versioned OpenTofu/Terraform modules that are continuously maintained and updated
Image
Guardrails
 — SCPs, AWS Config, GuardDuty, CloudTrail, etc
Image
Modules follow CIS AWS Framework Benchmark and AWS Well-Architected Framework
Image
Terragrunt Stacks deployment for common use cases: ECS, RDS, EKS
Step
5
Monitoring and Maintenance
Gruntwork works with you to set up:
Image
Gruntwork Patcher
 — identifies and automates IaC updates
Image
Gruntwork Drift Detection
 — detect and resolve infrastructure drift
Image
Monitoring
 — service catalog modules come with built in monitoring
Step
6
Application architecture
You the customer to deploy your application
Image
Get the fast track to …
Image
AWS
Foundations
Image
Gruntwork
IaC Foundations
Image
GitHub/GitLab
CI/CD Pipelines