# Templates

The Golden Path ships a set of reusable Terraform templates (packages) that you add to an environment with `ok pkg add <name>` and install with `ok pkg install`. This page lists every template, grouped by area, with a link to its reference documentation.

<!-- The tables below are generated from /templates.yml by cog. -->
<!-- Regenerate (also done by .github/workflows/update_template_docs.yml): -->
<!--   uv run --locked --only-group docs-gen cog -r zensical.toml docs/templates/index.md -->
<!-- [[[cog
import yaml, cog
with open("templates.yml") as _f:
    _TEMPLATES = yaml.safe_load(_f)
_areas = []
for _t in _TEMPLATES:
    if _t["area"] not in _areas:
        _areas.append(_t["area"])
for _area in _areas:
    # Pad cells to the widest in each column, the way Prettier formats tables.
    # markdownlint's MD060 requires the pipes to line up.
    _rows = [
        (f'[`{_t["name"]}`](../{_t["dir"]}/templates/{_t["name"]}.md)', _t["blurb"])
        for _t in _TEMPLATES
        if _t["area"] == _area
    ]
    _w1 = max(len("Template"), *(len(r[0]) for r in _rows))
    _w2 = max(len("Description"), *(len(r[1]) for r in _rows))
    cog.outl(f"\n## {_area}\n")
    cog.outl(f'| {"Template".ljust(_w1)} | {"Description".ljust(_w2)} |')
    cog.outl(f'| {"-" * _w1} | {"-" * _w2} |')
    for _name, _blurb in _rows:
        cog.outl(f"| {_name.ljust(_w1)} | {_blurb.ljust(_w2)} |")
cog.outl("")  # Prettier wants a blank line before the closing cog marker
]]] -->

## Terraform

| Template                                                 | Description                                                       |
| -------------------------------------------------------- | ----------------------------------------------------------------- |
| [`remote-state`](../terraform/templates/remote-state.md) | S3 bucket and DynamoDB table for storing Terraform state remotely |

## Networking

| Template                                                                        | Description                                                   |
| ------------------------------------------------------------------------------- | ------------------------------------------------------------- |
| [`certificates`](../networking/templates/certificates.md)                       | ACM TLS certificates for your environment's domains           |
| [`dns`](../networking/templates/dns.md)                                         | Route 53 hosted zone and DNS for the environment subdomain    |
| [`load-balancing-alb`](../networking/templates/load-balancing-alb.md)           | Public Application Load Balancer for routing internet traffic |
| [`load-balancing-alb-data`](../networking/templates/load-balancing-alb-data.md) | Supporting data resources for the ALB stack                   |
| [`networking`](../networking/templates/networking.md)                           | VPC and core network shared by the environment                |
| [`networking-data`](../networking/templates/networking-data.md)                 | Supporting data resources for the networking stack            |

## Database

| Template                                              | Description                                                |
| ----------------------------------------------------- | ---------------------------------------------------------- |
| [`databases`](../database/templates/databases.md)     | Shared PostgreSQL (Aurora) database cluster                |
| [`rds-bastion`](../database/templates/rds-bastion.md) | Bastion for connecting to RDS databases from your computer |

## Application

| Template                                                                                       | Description                                                             |
| ---------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------- |
| [`app`](../application/templates/app.md)                                                       | ECS service for a containerized application                             |
| [`app-common`](../application/templates/app-common.md)                                         | Shared application infrastructure (ECS cluster, ECR pull-through cache) |
| [`app-data`](../application/templates/app-data.md)                                             | Data resources for an application stack                                 |
| [`cloudfront-static-website`](../application/templates/cloudfront-static-website.md)           | S3 + CloudFront static website with TLS and a custom domain             |
| [`cloudfront-static-website-data`](../application/templates/cloudfront-static-website-data.md) | Data resources (S3 buckets) for a CloudFront static website             |

## Terraform automation

| Template                                          | Description                     |
| ------------------------------------------------- | ------------------------------- |
| [`iam`](../terraform-automation/templates/iam.md) | GitHub OIDC IAM roles for CI/CD |

## Backup

| Template                                  | Description                 |
| ----------------------------------------- | --------------------------- |
| [`backup`](../backup/templates/backup.md) | AWS Backup plans and vaults |

## Observability

| Template                                                         | Description                                    |
| ---------------------------------------------------------------- | ---------------------------------------------- |
| [`datadog-common`](../observability/templates/datadog-common.md) | Shared Datadog integration for the environment |

<!-- [[[end]]] -->
