When your architecture has passed simulation and cost review, deploy it directly to AWS from the pinpole canvas. A secure, four-step guided workflow - no long-lived credentials stored, every action logged.
Every deployment follows the same guided flow. Review before anything is provisioned. Approve only when you're ready. The deployment history captures a full architecture snapshot at every step.
IAM Role assumption via STS. pinpole generates a CloudFormation stack that creates a least-privilege role in your account. No long-lived credentials are stored - only temporary session credentials are used for the duration of the deployment. Select your target deploy region at this step.
STS AssumeRole credential workflow. Monitor provisioning progress live in the deploy panel. No secrets leave your browser session.
Terraform HCL or AWS CDK from any canvas state - before or after simulation. The export reflects the exact canvas configuration at the moment of export, including any changes applied from recommendations.
AWS STS AssumeRole for cross-account access. No IAM access keys are stored. No long-lived credentials are transmitted or persisted anywhere. The IAM role configuration is documented in full in the deployment guide.
Deployments are a security-sensitive operation. pinpole's security model is designed so that no long-lived credentials enter or leave the platform at any point.
AWS STS AssumeRole for all deployments. A CloudFormation stack creates a least-privilege IAM role in your account. pinpole assumes that role for the duration of the deployment - no secrets leave your account.
Multi-environment configuration is set once per workspace. pinpole enforces a deployment path that protects production - validate in lower environments before promoting.
If your organisation deploys through Terraform or CDK pipelines, export the architecture definition at any canvas state and integrate it into your existing workflow.
The IaC export reflects the exact canvas configuration at the moment of export, including any configuration changes applied from recommendations. Use it as an additional review layer, or as your primary deployment path.
Export provides an architecture definition compatible with Terraform and CDK. Full Terraform HCL code generation is planned for Phase 1 of the product roadmap (Q2–Q3 2026).
IaC export documentation →Execution history captures a full architecture snapshot at every simulation run and deployment. Compare any two states side by side, roll back to a prior canvas configuration, or trace a live deployment back to the exact simulation run that cleared it.
Execution history docs →The four steps are a framework, not a formality. These practices make the difference between a smooth promotion and a production incident.
ST (System Test) or UAT before targeting Production. This validates that the architecture behaves in a real AWS account before it handles production traffic. Simulation is not a substitute for a real environment run.
The full workflow - canvas design, traffic simulation at up to 100M RPS, live cost estimation, and direct deployment to AWS - in one product. Start free, deploy when you're ready.