How D&I infrastructure is provisioned, deployed, and operated day to day — starting with the AWS accounts and environment tiers managed by di-terraform, with more operational areas landing here over time.
bi-regional/bi-wms, and how it maps onto the accounts above.AWS Accounts & Tiers
AWS environments managed directly by di-terraform follow a three-tier promotion model. Source: ai-docs/environments/aws-environments.md and data/aws-accounts.yml.
Environment tiers
| Tier | Suffix | Purpose |
|---|---|---|
| Development | dev | Active development and testing |
| Staging | trex | Pre-production validation |
| Production | prod | Live production workloads |
Account inventory
| Environment dir | Account ID | AWS profile | Tier | Region |
|---|---|---|---|---|
| aws/aws-bi | 382359729765 | aws-bi | legacy | us-west-2 |
| aws/okta-bt-data-eng-dev | 720384017859 | data-eng-dev | dev | us-west-2 |
| aws/okta-bt-data-eng-trex | 749130651226 | data-eng-trex | trex | us-west-2 |
| aws/okta-bt-data-eng-prod | 057759945086 | data-eng-prod | prod | us-west-2 |
| aws/okta-bt-data-lake-dev | TBD | data-lake-dev | dev | us-west-2 |
| aws/okta-bt-data-lake-trex | TBD | data-lake-trex | trex | us-west-2 |
| aws/okta-bt-data-lake-prod | TBD | data-lake-prod | prod | us-west-2 |
aws-bi is legacy BI infrastructure (quadrant auw2w), being migrated off in favor of the okta-bt-data-eng-* accounts. Data-lake account IDs are not yet populated in the source data file.
environments/aws/ is a standalone Terraform root that carries its own S3 + DynamoDB state backend. See initialize-tfstate.md for how a new environment's backend is bootstrapped.
AWS Quadrants
A quadrant is Okta's naming convention for identifying an AWS account, predating this repo. It's used heavily by BI applications (bi-wms, bi-regional) and their "cellside" dependencies. Source: aws-environments.md — Quadrants.
Format
a<region><letter> — a is a constant "Amazon" prefix, <region> is a compressed AWS region code, and <letter> is an account/role designator assigned per region. Example: auw2w = amazon, uw2 (us-west-2), w (the BI account in that region).
Confirmed letter designators
| Letter | Meaning | Confidence |
|---|---|---|
| w | BI account (bi-regional prod, and formerly bi-wms prod pre-migration) | Confirmed |
| n | bi-wms dev (migration source account, pre-okta-bt-data-eng-dev) | Confirmed |
| t | bi-wms trex (migration source account, pre-okta-bt-data-eng-trex) | Confirmed |
| p | Cellside production account | Confirmed |
| s | Cellside secondary — exact semantics unconfirmed | Unconfirmed |
| m, e | Observed on individual cellside accounts — semantics unconfirmed | Unconfirmed |
Some cellside accounts have no single-letter designator at all — they use <region>-<cell> instead (e.g. aue2-ok10).
Who owns what
- BI quadrants (
wsuffix, plus then/tmigration-source accounts) are owned by Data & Insights and managed in this repo. - Cellside quadrants (
p,s, and unlettered<region>-<cell>accounts) are owned by the external ORD (cellside platform) team — consumed bybi-regionalbut not managed bydi-terraform. - Government/federal quadrants (
augw1,auge1,augw1t) serve government cells and live in a FedRAMP High environment — treat with elevated compliance care.
Deployments
Snowflake Operations
sfc/* environments.GCP & dbt Cloud
environments/gcp/ and environments/dbt/.