Multi-Environment Access Architecture for Claude Platform on AWS
A dedicated AI Services account and multi-authentication method have been introduced to provide secure access from different environments for the Claude Platform on AWS.
An architectural guide has been published that consolidates different access requirements from production workloads, developer laptops, and external CI/CD pipelines under a single subscription for Claude Platform integration on AWS.
Architectural Structure and Account Layout
The system is based on a dedicated structure where the subscription is kept in a separate linked account. This three-account structure includes a payer account, an AI Services account, and workload accounts.
Multi-Environment Requirements
Production workloads, local development environments, and continuous integration pipelines on external cloud providers have different authentication requirements.
Workspace Isolation
Workspace-level isolation is established between production and development traffic, making it secure for all environments to share a single common subscription.
SigV4 for AWS Workloads
Workload accounts make inference calls by assuming roles in the AI Services account. For example, an EKS pod can perform secure calls without storing static keys.
API Keys for Developers
Workspace-specific API keys are generated for developers for local work. Privileges are restricted using IAM inline policies to protect the development space.
OIDC Federation for External Systems
OIDC federation is implemented for external workloads. This allows authentication without using permanent secrets and temporary credentials are obtained.