⌂ Home

D&I Platform Operations

Infrastructure, deployments and operations

How D&I infrastructure is provisioned, deployed, and operated day to day — starting with the AWS accounts and environment tiers managed by di-terraform, with more operational areas landing here over time.

AWS Accounts & Tiers
The dev / trex / prod promotion model, the AWS accounts it maps to, and how state is backed for each.
Open section →
AWS Quadrants
Okta's legacy account-naming convention used by bi-regional/bi-wms, and how it maps onto the accounts above.
Open section →
Coming soon
Deployments
CI/CD flow for Terraform plan/apply, module release tagging, and environment promotion.
Coming soon
Snowflake Operations
Account topology, warehouse/role operations, and on-call runbooks for the Snowflake estate.
Coming soon
GCP & dbt Cloud
GCP project/BigQuery footprint and dbt Cloud job/environment operations.

AWS Accounts & Tiers

AWS environments managed directly by di-terraform follow a three-tier promotion model. Source: ai-docs/environments/aws-environments.md and data/aws-accounts.yml.

Environment tiers

TierSuffixPurpose
DevelopmentdevActive development and testing
StagingtrexPre-production validation
ProductionprodLive production workloads

Account inventory

Environment dirAccount IDAWS profileTierRegion
aws/aws-bi382359729765aws-bilegacyus-west-2
aws/okta-bt-data-eng-dev720384017859data-eng-devdevus-west-2
aws/okta-bt-data-eng-trex749130651226data-eng-trextrexus-west-2
aws/okta-bt-data-eng-prod057759945086data-eng-prodprodus-west-2
aws/okta-bt-data-lake-devTBDdata-lake-devdevus-west-2
aws/okta-bt-data-lake-trexTBDdata-lake-trextrexus-west-2
aws/okta-bt-data-lake-prodTBDdata-lake-prodprodus-west-2

aws-bi is legacy BI infrastructure (quadrant auw2w), being migrated off in favor of the okta-bt-data-eng-* accounts. Data-lake account IDs are not yet populated in the source data file.

Each environment directory under environments/aws/ is a standalone Terraform root that carries its own S3 + DynamoDB state backend. See initialize-tfstate.md for how a new environment's backend is bootstrapped.

AWS Quadrants

A quadrant is Okta's naming convention for identifying an AWS account, predating this repo. It's used heavily by BI applications (bi-wms, bi-regional) and their "cellside" dependencies. Source: aws-environments.md — Quadrants.

Format

a<region><letter> — a is a constant "Amazon" prefix, <region> is a compressed AWS region code, and <letter> is an account/role designator assigned per region. Example: auw2w = amazon, uw2 (us-west-2), w (the BI account in that region).

Confirmed letter designators

LetterMeaningConfidence
wBI account (bi-regional prod, and formerly bi-wms prod pre-migration)Confirmed
nbi-wms dev (migration source account, pre-okta-bt-data-eng-dev)Confirmed
tbi-wms trex (migration source account, pre-okta-bt-data-eng-trex)Confirmed
pCellside production accountConfirmed
sCellside secondary — exact semantics unconfirmedUnconfirmed
m, eObserved on individual cellside accounts — semantics unconfirmedUnconfirmed

Some cellside accounts have no single-letter designator at all — they use <region>-<cell> instead (e.g. aue2-ok10).

Who owns what

  • BI quadrants (w suffix, plus the n/t migration-source accounts) are owned by Data & Insights and managed in this repo.
  • Cellside quadrants (p, s, and unlettered <region>-<cell> accounts) are owned by the external ORD (cellside platform) team — consumed by bi-regional but not managed by di-terraform.
  • Government/federal quadrants (augw1, auge1, augw1t) serve government cells and live in a FedRAMP High environment — treat with elevated compliance care.
Full quadrant → region → account ID → consumer mapping, with per-entry confidence flags, lives in data/aws-quadrants.yml.

Deployments

Coming soon
Will cover the CI/CD pipeline for Terraform plan/apply across environments, module version tagging on merge, and the promotion path from dev → trex → prod.

Snowflake Operations

Coming soon
Will cover Snowflake account topology, service-user/role operations, warehouse management, and on-call runbooks across the sfc/* environments.

GCP & dbt Cloud

Coming soon
Will cover the GCP project/BigQuery footprint and dbt Cloud job, environment, and connection operations managed under environments/gcp/ and environments/dbt/.