CloudFix — Core Architecture

How CloudFix connects to your AWS environment, what it reads, and how approved fixes are executed — without any third-party ITSM integration.

CloudFix Platform AWS us-east-1 CloudFix App & API REST API · HTTPS/TLS 1.2+ AWS Cognito User auth CloudFront CDN / HTTPS Analysis Engine 75+ cost finders · recommendations DB Athena / Glue CUR query engine Lambda Events & automation CloudFix Dashboard Approve/reject recommendations Customer AWS Account(s) Deployed via CloudFormation StackSet · all changes audited in CloudTrail CloudFormation StackSet Deploys IAM roles · fully auditable IaC cloudfix-finder-role Read: CUR · CloudWatch · resource metadata Tagging (cloudfix: prefix) · CloudWatch Logs CUR + S3 Cost & Usage Reports bucket CloudWatch Usage metrics for finders CloudTrail All CloudFix API calls logged annotated with CloudFix role ── Customer approval required before any changes execute ── AWS Systems Manager Change Manager + Automation Orchestrates approved runbooks cloudfix-ssm-assumed-role Executes approved fixes Cannot be assumed by CloudFix directly Customer AWS Resources EC2 · RDS · EBS · ECS · EKS ElastiCache · EFS · Lambda Redshift · OpenSearch · S3 Modified only after explicit approval via SSM No app data accessed Browser Deploy Metadata Change request Execute

Figure 1 — CloudFix core architecture. Data flows left (CloudFix platform) ↔ right (customer AWS account). No application data is accessed; only infrastructure metadata.

CloudFix Platform (AWS us-east-1)
Customer AWS Account
Approval boundary — customer must approve before fixes execute

CloudFix + ITSM Integration

How CloudFix integrates with service desk platforms (ServiceNow, Jira Service Management, and similar tools) via webhooks and the CloudFix REST API.

Service Desk ServiceNow · Jira · etc. Inbound Integration Receives webhook events Change / Incident Ticket Created automatically resource ID · savings · status Approval Workflow Human review & approval Outbound API Call HTTPS POST → CloudFix API Data received Resource IDs · savings status · account name No app/business data CloudFix Platform AWS us-east-1 CloudFix API Bearer token auth · HTTPS/TLS 1.2+ Webhook Engine Sends HTTPS POST on events Cognito User auth CloudFront CDN / HTTPS Analysis Engine 75+ finders · recommendations DB Dashboard Approve / review (web UI) API authentication Bearer token (API key) scoped to account generated in dashboard Customer AWS Account(s) All activity audited in CloudTrail CloudFormation StackSet Deploys IAM roles cloudfix-finder-role Read CUR · CloudWatch Tagging · CloudWatch Logs CUR + S3 Usage reports CloudWatch Metrics CloudTrail Independent audit log ── Approval required (ITSM or Dashboard) before changes execute ── AWS Systems Manager Change Manager + Automation Orchestrates runbooks cloudfix-ssm-assumed-role Executes approved fixes Not directly assumable by CloudFix Customer AWS Resources EC2 · RDS · EBS · ECS ElastiCache · S3 · Lambda… Modified only after approved changes No app data accessed Webhook HTTPS POST Approval signal Deploy Metadata Change request Execute

Figure 2 — CloudFix + ITSM integration. CloudFix raises a webhook to your service desk when a recommendation is ready. The service desk routes approval through its own workflow, then calls the CloudFix API to signal approval. CloudFix then triggers execution via AWS Systems Manager.

Service desk platform (ServiceNow, Jira, etc.)
CloudFix Platform (AWS us-east-1)
Customer AWS Account
Approval boundary
No customer AWS data passes through the service desk platform. Webhook payloads contain only CloudFix recommendation metadata: AWS resource IDs, estimated savings amounts, service type, and approval status. No S3 contents, database records, application data, or credentials are ever included.

Need the diagrams in another format?

Request a Visio, draw.io, or high-resolution PNG version for your security review pack.