Implementation case study
Aegis Cloud
Turn a supported diagram into an explicit cloud model, derived controls and reviewable infrastructure files.

Implemented pipeline
- Supported draw.io input
- Finite typed AWS architecture model
- Derived IAM, network and key requirements
- Control states visible in the Studio
- Local Terraform and Terragrunt emission
Decision: expose unresolved controls
Modeling a finite set of resources makes derivation inspectable. The Studio shows controls that remain open rather than treating emitted infrastructure as proof of compliance. The tradeoff is limited coverage: a modeled relationship cannot capture every AWS service or real account condition.
Bounded walkthrough
A bundled diagram produced 26 model nodes, 137 Terraform lines and 26 Terragrunt files through the actual CLI. The WASM Studio exercised a fictional bucket and derived policy, VPC endpoint and key requirements. These are concrete local artifacts, not provisioned cloud resources.
Bug and lesson
An input-only invocation previously fell through to a built-in reference example. Unknown or missing input options now fail explicitly. A polished reference diagram cannot stand in for parsing the user’s input.
Proof and limits
98 Rust tests passed. No AWS account was queried and no infrastructure was applied. Generated files need review against the intended account and service semantics; this is neither cloud deployment evidence nor a compliance certification.