Implementation and diagnosis
Built features, ran tests, investigated CloudFormation replacement constraints, IAM failures, Cognito sessions, Bedrock access, and production behavior.
CloudLens turns live AWS accounts into searchable architecture, dependency, change-risk, security, cost, and operational intelligence. This page documents the shipped system, the coding-agent connection to AWS, and the boundaries of each public claim.
The public judge experience exposes the full CloudLens workflow with synthetic infrastructure data, so reviewers can explore the product without receiving customer credentials or access to a private AWS account. The authenticated product uses real tenant-scoped AWS discovery.
CloudFront delivers the web application from a private S3 origin. Cognito authenticates tenants. API Gateway and Lambda enforce authorization and orchestrate discovery, analysis, billing, reports, and chat. DynamoDB stores tenant-scoped state. EventBridge schedules collection. Bedrock generates grounded explanations. STS assumes customer-owned read-only roles with a unique External ID.
Customer accounts remain under customer control. CloudLens receives short-lived STS credentials and performs read-only collection. Users never paste long-lived AWS access keys into the product.
The coding agent participated in the real AWS delivery loop—not only local code generation. It synthesized CDK, prepared and pushed changes, monitored GitHub Actions, inspected deployment failures, helped diagnose IAM and CloudFormation behavior, verified Cognito and Bedrock, and browser-tested the deployed application.

Built features, ran tests, investigated CloudFormation replacement constraints, IAM failures, Cognito sessions, Bedrock access, and production behavior.
GitHub Actions requested temporary AWS credentials through OIDC; no long-lived AWS access key is published or required.
The workflow assumed the dedicated CloudLens deployment role, synthesized CDK, and updated the CloudFormation stack.
The workflow ran smoke checks and production browser tests against the public custom-domain application.
This table distinguishes shipped capability from proof and explicitly records important limits. It is intended to help reviewers audit the project without relying on promotional claims.
| Claim | What supports it | Limits |
|---|---|---|
| Live AWS application | Public custom domain, CloudFront delivery, deployment smoke checks, and production Playwright tests. | Availability can change after a dated observation; reviewers should test the live URL. |
| Cross-account discovery | Customer-owned IAM role template, External ID flow, STS validation, and authenticated discovery results. | The public demo does not assume a real customer role and uses synthetic resources. |
| Evidence-grounded AI | Bedrock analysis and copilot consume bounded topology, relationship, telemetry, cost, security, and change context while retaining resource references. | Recommendations are advisory and require human review; CloudLens does not execute remediation. |
| Coding-agent AWS connection | Redacted connection board, public evidence narrative, sanitized GitHub Actions OIDC workflow, CDK records, and live verification steps. | Secrets and tenant identifiers are deliberately excluded. AWS judges decide whether evidence satisfies event requirements. |
| Multi-tenant SaaS controls | Cognito authentication, tenant-scoped records, server-side account grants, role checks, invitations, limits, billing lifecycle, and audit controls. | The product is an early paid-pilot MVP, not a certified compliance platform. |
The React Native Android companion uses the same tenant-scoped CloudLens APIs and authentication lifecycle. It brings live inventory, architecture, costs, alerts, the Bedrock copilot, and commercial plan controls to a phone-sized experience.

These direct AWS Console captures document the deployed CloudLens environment: completed CloudFormation stacks, the live stack's 84 managed resources, and the generated Infrastructure Composer graph. They were captured on September 26, 2026 from the authenticated deployment account.

UPDATE_COMPLETE; the customer read-only access stack and CDK bootstrap stack are also complete.
CloudLens-dev stack reports 84 resources, including encrypted data, knowledge-source, vector-search, API, identity, and automation components.
CloudLens uses Amazon Bedrock for evidence-grounded architecture analysis and its account-aware copilot. These AWS Console captures document the deployed retrieval and safety resources, plus the serverless model selected for cost-conscious inference.

CloudLens_dev_v2 vector-store Knowledge Base has one attached data source and no recorded sync warnings.
CloudLens_dev_evidence data source is backed by Amazon S3, reports Available, and uses fixed-size chunking for bounded retrieval.
Ready and is described in AWS as protecting evidence-grounded analysis from unsafe content and credential disclosure.