What is created in the account
A project network is a VPC, subnets, and security groups for that project. Tasks that need to pull an image or reach the internet use a public IP on the task. There is not a separate NAT product in front of them.
The database security group allows the project service security group on the database port. It is written when the database is created and again when a server or worker is deployed.
The cache has no password. Clients in the project use TLS (
rediss://). The endpoint is reachable from the project services, not published as a public website.
What Springwinter reads, and does not copy
Opening Logs reads CloudWatch Logs for that resource. Opening Metrics reads CloudWatch for CPU, memory, requests, and errors. Opening Cost reads cost for the account. Those responses are shown to people in the organization. They are not indexed into a Springwinter search store, and they are not kept as a second copy of your logs. A workflow run does keep the identifiers and the inputs of that deploy, as described on Credentials.Environment and images
Container environment lives on the task definition in your account. See Credentials. A build from GitHub runs in CodeBuild in your account and pushes the image to ECR in your account. A service created from a public image does not create a CodeBuild project. Fargate pulls that image in the account. Registry passwords are not accepted.Reaching a private service
SQL, a cache, and a web server task can be reached with SSM port forwarding. An authenticated person opens a gateway in the project. Springwinter starts a Session Manager session in your account and returns asession-manager-plugin command. The gateway is a Fargate service in the project security group. Closing it scales that service to zero. The session is not a key Springwinter keeps.