Skip to main content

ADR 01 - Integration of web applications with data in AP

SPIKE investigation ticket

Decision

Register webapps with AP and use the vended IAM role to integrate webapps with data in AP. Database permissions are configured through a separate configuration file maintained by Data Engineering.

Architecture

AP-webapp integration architecture

Rationale

Advantages:

  • No data duplication
  • Data kept in AP
  • Low maintenance cost

Neutral:

  • Medium implementation effort

Disadvantages:

  • Potential reliance on support from AP
  • Less flexibility, including no support for serverless, as the trust policy for the cross-account IAM role is for kubernetes service accounts and EC2

Risks

  • Risk: AP are busy building out the AI Gateway product, therefore their ability to provide support may be limited.
  • Mitigation: The integration should be relatively simple, relying on one primary component, the cross-account IAM role, therefore any issues with the integration should be easier to troubleshoot.
This page was last reviewed on 17 September 2026. It needs to be reviewed again on 17 December 2026 by the page owner #coat-notifications .