NORMA eResearch @NCI Library

Automation of Secure and Compliant Infrastructure Orchestration Utilizing Terraform on AWS

Singamaneni, Anusha, Bhaskaran, Ranjith, Muntean, Cristina Hava and Gupta, Shaguna (2026) Automation of Secure and Compliant Infrastructure Orchestration Utilizing Terraform on AWS. In: Proceedings of the 16th International Conference on Cloud Computing and Services Science. SciTePress, Benidorm, Spain, pp. 269-276. ISBN 978-989758829-7

[thumbnail of 148730.pdf]
Preview
PDF
Download (391kB) | Preview
Official URL: https://doi.org/10.5220/0014873000004039

Abstract

Secure, compliant cloud provisioning is difficult with manual configuration, where misconfigurations, inconsistent security, and limited auditability often arise. Infrastructure-as-Code (IaC) solves this by defining infrastructure declaratively and enabling repeatable, version-controlled deployments. This paper presents an AWS-focused Terraform approach embedding security-by-design controls into automated provisioning, including least-privilege IAM, network segmentation with public and private VPC subnets, bastion-based administrative access, controlled outbound connectivity via a NAT gateway, and centralized logging and encryption baselines. The implementation is evaluated through a comparative study against manual provisioning using the AWS Management Console. Results show Terraform reduces provisioning time by over 75% across complex networking and access-control scenarios, while improving reliability by increasing success rates from 74% to 96%. Connectivity validation confirms th at public resources route traffic through the Internet Gateway, private instances access outbound connectivity only via the NAT gateway, and administrative access to private resources is restricted to the bastion host. Security validation confirms consistent enforcement of baseline controls such as IAM least privilege, subnet isolation, restricted Secure Shell (SSH) ingress, centralized logging, and encryption at rest. These findings demonstrate that Terraform-based Infrastructure-as-Code can simultaneously improve operational efficiency and strengthen security and compliance consistency, offering a practical foundation for repeatable and audit-ready cloud infrastructure deployments, particularly for environments with limited operational overhead.

Item Type: Book Section
Additional Information: CC BY-NC-ND 4.0: https://creativecommons.org/licenses/by-nc-nd/4.0/
Uncontrolled Keywords: Amazon Web Services; Automation; Cloud Security; Compliance-as-Code; Identity and Access Management; Infrastructure-as-Code; Terraform; Virtual Private Cloud
Subjects: Q Science > QA Mathematics > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Electronic computers. Computer science
T Technology > T Technology (General) > Information Technology > Cloud computing
Q Science > QA Mathematics > Computer software > Computer Security
T Technology > T Technology (General) > Information Technology > Computer software > Computer Security
Divisions: School of Computing > Staff Research and Publications
Depositing User: Tamara Malone
Date Deposited: 05 Aug 2026 11:02
Last Modified: 05 Aug 2026 11:02
URI: https://norma.ncirl.ie/id/eprint/9489

Actions (login required)

View Item View Item