BLUEPRINT LIBRARY

Create paved roads

Blueprints for creating cloud resources with best practices embedded

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

This blueprint creates a Google Compute Subnetwork with best practices by defaulting to enable private Google access and flow logs, enhancing security and observability. It allows for the configuration of secondary IP ranges and encourages the use of labels for better resource management. The variables are organized into logical groups to assist users, including those who may not be cloud infrastructure experts, in configuring essential settings easily.

This blueprint creates an AWS CloudWatch Log Group with best practices in mind, such as setting a default retention period of 14 days to prevent unlimited storage costs and optionally enabling encryption using a KMS key for enhanced security. It encourages the use of tags for better resource identification and management. The blueprint is organized to assist users, including those who may not be cloud infrastructure experts, in configuring essential settings easily.

This blueprint creates an Azure Public IP with best practices in mind, such as defaulting to a 'Static' allocation method and using the 'Standard' SKU for enhanced security and features. It encourages the use of tags for better resource management and identification. Advanced settings like idle timeout can be customized if needed. The blueprint organizes variables into intuitive groups to assist users—including those who may not be cloud infrastructure experts—in configuring essential and advanced settings easily.

This blueprint creates an AWS RDS DB instance following best practices such as enabling encryption at rest for data security, setting Multi-AZ deployment by default for high availability, and disabling public access to enhance security. It organizes variables into intuitive groups to assist users—especially those not well-versed in cloud infrastructure—in configuring essential and advanced settings easily. The blueprint also encourages tagging for better resource identification and management.

This blueprint creates an AWS IAM User with best practices in mind, such as encouraging the use of tagging for resource identification and management. It provides advanced options like setting a permissions boundary for enhanced security control. The blueprint organizes variables into groups to assist users, including those who may not be cloud infrastructure experts, in configuring essential and advanced settings easily.

This blueprint creates an AWS IAM Role with best practices in mind, such as requiring an assume role policy for security and encouraging the use of tags for resource identification and management. It provides advanced options like setting a permissions boundary for better security control. The blueprint is organized into groups to assist users, including those who may not be cloud infrastructure experts, in configuring essential and advanced settings easily.

This blueprint creates an AWS Security Group adhering to best practices by denying all inbound traffic unless specified, thereby enhancing security. It allows all outbound traffic by default, following AWS's standard behavior, but gives users the flexibility to define specific egress rules if needed. The blueprint encourages the use of descriptive tagging for better resource management and organizes variables into groups to simplify configuration for users who may not be cloud infrastructure experts.

This blueprint creates an AWS S3 bucket with best practices in mind, such as blocking public access by default, enabling server-side encryption and versioning to protect data integrity and security. It provides options for access logging and tagging for better resource management. The blueprint is organized to guide users through essential settings while offering flexibility for advanced configurations.

This blueprint creates an Azure Resource Group with best practices in mind, such as providing a default location of "eastus" while allowing customization, and encouraging the use of tags for better resource identification and management. It organizes variables into intuitive groups to assist users—including those who may not be cloud infrastructure experts—in configuring essential settings easily.

This blueprint creates an Azure SQL Server with best practices such as requiring secure administrator credentials, defaulting to version 12.0, and encouraging the use of managed identities for enhanced security. It promotes the use of tags for better resource identification and management and organizes variables into logical groups to assist users—including those who may not be cloud infrastructure experts—in configuring essential and advanced settings easily.

This blueprint creates an AWS RDS Cluster following best practices such as enabling encryption at rest for data security, setting deletion protection by default to prevent accidental deletion, and configuring sensible defaults for backup retention and preferred backup windows. It encourages the use of tags for resource identification and management. The blueprint is organized into intuitive groups to assist users—including those not well-versed in cloud infrastructure—in configuring essential and advanced settings easily.

This blueprint creates an Azure SQL Database with best practices in mind, such as defaulting to the 'Basic' edition and service objective for cost-effectiveness, setting a standard collation, and encouraging the use of tags for better resource identification and management. It allows customization of advanced settings like collation and maximum size, organizing variables into logical groups to assist users—including those who may not be cloud infrastructure experts—in configuring essential and advanced settings easily.

This blueprint creates an AWS Lambda function following best practices, such as setting a default runtime environment (Python 3.8) and handler, enabling secure configuration by requiring an IAM role, and encouraging the use of tags for resource identification and management. It allows customization of memory size and timeout for performance tuning and supports the inclusion of environment variables to provide flexibility for various use cases.

This blueprint creates an AWS Subnet with best practices in mind, such as disabling public IP assignment by default to enhance security. It allows customization of CIDR blocks and availability zones to suit different network requirements. The blueprint encourages the use of tagging for better resource management and organizes variables into groups to assist users who may not be cloud infrastructure experts.

This blueprint creates an Azure Load Balancer with best practices in mind, such as defaulting to the 'Standard' SKU for enhanced features and security. It provides flexibility to configure either a public or internal Load Balancer by allowing users to specify the appropriate frontend IP configurations. The blueprint promotes the use of tagging for better resource management and organizes variables into logical groups to guide users—including those who may not be cloud infrastructure experts—through the essential and advanced settings.

Your CSPM can't fix cloud infrastructure

Learn how Resourcely can improve your cloud posture in days, not quarters