AWS Well-Architected Tool: Complete Review Guide
Learn how to use the AWS Well-Architected Tool to conduct comprehensive workload reviews and track improvements over time.
The AWS Well-Architected Tool is a free service that helps you review the state of your workloads against AWS architectural best practices. This guide covers how to effectively use the tool for comprehensive workload assessments.
Understanding the Well-Architected Tool
What It Does
The Well-Architected Tool provides:
- Structured workload reviews across all six pillars
- Consistent methodology for evaluating architectures
- Improvement tracking and milestone management
- Custom lenses for specific use cases
- Integration with AWS services
Key Concepts
Understanding these concepts is essential:
- Workload: The collection of resources and code that deliver business value
- Lens: A set of questions tailored to specific technologies or domains
- Milestone: A snapshot of your workload state at a point in time
- Improvement Plan: Prioritized actions to address identified risks
Defining Your Workloads
Workload Identification
Before starting a review, clearly define your workload:
{
"WorkloadName": "E-Commerce Platform",
"Description": "Customer-facing shopping platform with payment processing",
"Environment": "Production",
"AwsRegions": ["us-east-1", "us-west-2"],
"ReviewOwner": "platform-team@company.com",
"Industry": "Retail",
"Lenses": [
"wellarchitected",
"serverless",
"saas"
]
}
Workload Properties
Configure essential properties:
- Account IDs: Associated AWS accounts
- Review Cadence: Quarterly, bi-annually, or annually
- Tags: For organization and filtering
- Architectural Tier: Internal, external, or infrastructure
Conducting Reviews
Pillar-by-Pillar Approach
Review each pillar systematically:
1. Operational Excellence
Key questions address:
- Runbook and playbook documentation
- Telemetry and monitoring implementation
- Deployment automation practices
- Incident response procedures
2. Security
Focus areas include:
- Identity and access management
- Encryption and data protection
- Network security controls
- Incident detection and response
3. Reliability
Evaluate:
- Fault tolerance mechanisms
- Recovery procedures
- Change management processes
- Monitoring and alerting
4. Performance Efficiency
Assess:
- Compute optimization
- Storage selection
- Database performance
- Global content delivery
5. Cost Optimization
Review:
- Cost allocation and tagging
- Resource right-sizing
- Pricing model optimization
- Usage monitoring
6. Sustainability
Consider:
- Resource utilization efficiency
- Data lifecycle management
- Hardware optimization
- Geographic placement
Using Custom Lenses
Available Lenses
AWS provides specialized lenses:
- Serverless Applications Lens: For serverless architectures
- SaaS Lens: For multi-tenant SaaS applications
- Data Analytics Lens: For analytics workloads
- Machine Learning Lens: For ML/AI workloads
- Financial Services Lens: For regulated industries
Creating Custom Lenses
Build organization-specific lenses:
{
"schemaVersion": "2021-11-01",
"name": "Custom Organization Lens",
"pillars": [
{
"id": "custom_security",
"name": "Organization Security Standards",
"questions": [
{
"id": "custom_sec_01",
"title": "Data Classification",
"description": "How do you classify data?",
"choices": [
{
"id": "choice1",
"title": "Automated classification",
"helpfulResource": {
"displayText": "Data classification guide"
},
"improvementPlan": {
"displayText": "Implement Macie"
}
}
]
}
]
}
]
}
Managing Milestones
Creating Milestones
Document progress with milestones:
aws wellarchitected create-milestone \
--workload-id wa-123456789 \
--milestone-name "Q1-2025-Review"
Tracking Improvements
Monitor improvement over time:
- Compare high-risk item counts between milestones
- Track resolution of specific risks
- Measure time to remediation
- Calculate improvement velocity
Improvement Planning
Risk Prioritization
Prioritize improvements by:
- High Risk Items (HRI): Address immediately
- Medium Risk Items (MRI): Plan for near-term
- Low Risk Items: Include in roadmap
- No Issues: Continue monitoring
Creating Action Items
ImprovementPlan:
HighPriority:
- Risk: "No MFA on root account"
Owner: "security-team"
DueDate: "2025-01-15"
Status: "In Progress"
- Risk: "Unencrypted S3 buckets"
Owner: "platform-team"
DueDate: "2025-01-30"
Status: "Planned"
Automation and Integration
API Integration
Automate reviews with the API:
import boto3
client = boto3.client('wellarchitected')
# List workloads
workloads = client.list_workloads()
# Get workload details
workload = client.get_workload(
WorkloadId='wa-123456789'
)
# List improvement items
improvements = client.list_lens_review_improvements(
WorkloadId='wa-123456789',
LensAlias='wellarchitected',
PillarId='security'
)
Notifications and Reporting
Configure automated notifications:
- EventBridge rules for workload changes
- SNS topics for review reminders
- Custom reports with Athena queries
Working with Warqline
We are a cloud engineering consultancy and an official AWS and Google Cloud partner. If you are running this in production and want a second pair of eyes, we scope work in a free 45-minute technical call: you describe what you are running and what worries you, and we tell you what we would look at first.
Best Practices
Review Cadence
Establish regular review schedules:
- Quarterly: For critical production workloads
- Bi-annually: For stable internal systems
- After major changes: For any significant updates
- Continuously: With Warqline automation
Team Involvement
Include diverse perspectives:
- Architecture team
- Operations team
- Security team
- Development team
- Business stakeholders
Conclusion
The AWS Well-Architected Tool provides a structured approach to evaluating cloud workloads. Combined with automated tools like Warqline, organizations can maintain continuous visibility into their architecture's alignment with best practices.