AWS Well-Architected Framework... for Less Effort?

Let’s start with some context…

What is the AWS Well-Architected Framework?

The AWS Well-Architected Framework helps you understand the pros and cons of decisions you make while building systems on AWS. Using the Framework helps you learn architectural best practices for designing and operating secure, reliable, efficient, cost-effective, and sustainable workloads in the AWS Cloud. It provides a way for you to consistently measure your architectures against best practices and identify areas for improvement. The process for reviewing an architecture is a constructive conversation about architectural decisions, and is not an audit mechanism. We believe that having well-architected systems greatly increases the likelihood of business success.

Source: AWS Documentation - Well-Architected Framework

TLDR version; It’s a framework by AWS that guides you to make good architectural decisions for your workload or infrastructure, or at least have a conscious idea of why you choose a different path. It is focused around the 6 pillars, “Operational excellence”, “Security”, “Reliability”, “Performance efficiency”, Cost optimization” and “Sustainability”.

The introductionary question for the framework is often: Are you Well-Architected?

Challenges with the framework

While the framework itself is very powerful if used correctly by the right people, it has some challenges. Here are some notable ones:

Introducing Waffle: Well-Architected Framework for Less Effort!

Waffle

Waffle is a CLI utility designed to tackle some of these challenges. The tool uses Amazon Bedrock direct invocations to analyze your Terraform infrastructure code and the Well-Architected Framework questions in the same context to check the boxes and write a summary for each question directly to the Well-Architected tool in AWS.

This may well be the head start that your workload needs for an efficient Well-Architected Framework review. Instead of starting from scratch for each question, you will have valuable context from your actual infrastructure code as a basis for further in-room discussion for the question.

Furthermore, being a CLI tool, the developers (or their CI-pipelines) can execute Waffle at any time to validate their direction, ensuring that no big surprises come up during the actual review.

Waffle was born from a hackathon project at the AWS Oslo GenAI Hackathon 2025, and we (Meraj and me) recently published it as an open source project for anyone to contribute to.

Take a look for yourself, and don’t be shy with creating issues or Pull Requests if you see potential for improvements! https://github.com/partly-notes/waffle

Architecture

High level architecture diagram of the Waffle CLI tool


In use

Using the utility is easy. After installing, there are a few commands available to you. The two most central ones are waffle init and waffle review

waffle init validates that you have AWS credentials configured in your terminal session, have access to Bedrock models and the Well-Architected tool in AWS.

waffle init

waffle review performs the actual analysis of your Terraform infrastructure, either by reading only the .tf files of the working directory + modules (default behaviour), or can alternatively also analyze a terraform state/plan file in json format for greater context. Note that using terraform state/plan file may expose sensitive values in your Terraform state!

You can scope your review to a specific Well-Architected Framework pillar with --scope pillar and for example --pillar security if you only want to evaluate the questions in the Security pillar. You can also scope the review to a specific question only with --question-id.

waffle review

Once posted, the answered questions can be viewed in the Well-Architected Framework tool in AWS for the workload you specified with --workload-id WAF Tool