CloudFix — Core Architecture

How CloudFix connects to your AWS environment, what it reads, and how approved fixes are executed — without any third-party ITSM integration.

CloudFix Platform AWS us-east-1 CloudFix App & API REST API · HTTPS/TLS 1.2+ AWS Cognito User auth CloudFront CDN / HTTPS Analysis Engine 75+ cost finders · recommendations DB Athena / Glue CUR query engine Lambda Events & automation CloudFix Dashboard Approve/reject recommendations Customer AWS Account(s) Deployed via CloudFormation StackSet · all changes audited in CloudTrail CloudFormation StackSet Deploys IAM roles · fully auditable IaC cloudfix-finder-role Read: CUR · CloudWatch · resource metadata Tagging (cloudfix: prefix) · CloudWatch Logs CUR + S3 Cost & Usage Reports bucket CloudWatch Usage metrics for finders CloudTrail All CloudFix API calls logged annotated with CloudFix role ── Customer approval required before any changes execute ── AWS Systems Manager Change Manager + Automation Orchestrates approved runbooks cloudfix-ssm-assumed-role Executes approved fixes Cannot be assumed by CloudFix directly Customer AWS Resources EC2 · RDS · EBS · ECS · EKS ElastiCache · EFS · Lambda Redshift · OpenSearch · S3 Modified only after explicit approval via SSM No app data accessed Browser Deploy Metadata Change request Execute

Figure 1 — CloudFix core architecture. Data flows left (CloudFix platform) ↔ right (customer AWS account). No application data is accessed; only infrastructure metadata.

CloudFix Platform (AWS us-east-1)
Customer AWS Account
Approval boundary — customer must approve before fixes execute

CloudFix + ITSM Integration

How CloudFix integrates with service desk and ITSM platforms via webhooks and the CloudFix REST API.

Service Desk Jira · ServiceDesk · etc. Inbound Integration Receives webhook events Change / Incident Ticket Created automatically resource ID · savings · status Approval Workflow Human review & approval Outbound API Call HTTPS POST → CloudFix API Data received Resource IDs · savings status · account name No app/business data CloudFix Platform AWS us-east-1 CloudFix API Bearer token auth · HTTPS/TLS 1.2+ Webhook Engine Sends HTTPS POST on events Cognito User auth CloudFront CDN / HTTPS Analysis Engine 75+ finders · recommendations DB Dashboard Approve / review (web UI) API authentication Bearer token (API key) scoped to account generated in dashboard Customer AWS Account(s) All activity audited in CloudTrail CloudFormation StackSet Deploys IAM roles cloudfix-finder-role Read CUR · CloudWatch Tagging · CloudWatch Logs CUR + S3 Usage reports CloudWatch Metrics CloudTrail Independent audit log ── Approval required (ITSM or Dashboard) before changes execute ── AWS Systems Manager Change Manager + Automation Orchestrates runbooks cloudfix-ssm-assumed-role Executes approved fixes Not directly assumable by CloudFix Customer AWS Resources EC2 · RDS · EBS · ECS ElastiCache · S3 · Lambda… Modified only after approved changes No app data accessed Webhook HTTPS POST Approval signal Deploy Metadata Change request Execute

Figure 2 — CloudFix + ITSM integration. CloudFix raises a webhook to your service desk when a recommendation is ready. The service desk routes approval through its own workflow, then calls the CloudFix API to signal approval. CloudFix then triggers execution via AWS Systems Manager.

Service desk / ITSM platform
CloudFix Platform (AWS us-east-1)
Customer AWS Account
Approval boundary
No customer AWS data passes through the service desk platform. Webhook payloads contain only CloudFix recommendation metadata: AWS resource IDs, estimated savings amounts, service type, and approval status. No S3 contents, database records, application data, or credentials are ever included.

Need the diagrams in another format?

Request a Visio, draw.io, or high-resolution PNG version for your security review pack.