Skip to content

The one rule to remember

Every infra-versus-app argument is really the same argument, dressed up. Here is the line that settles it, and a picture to point at when someone forgets.

Boundary

Infrastructure owns the server and everywhere it runs - the host, the network, everything inside the cloud. What runs inside it belongs to the teams that write it.

The container is Infrastructure's; the contents are the developers'.

AWS · Cloud · Network · Platform Infrastructure

everything inside the cloud account

VPC / subnetssecurity groupsload balancer DNSCDNobject storage (the container) DB enginesecret & parameter wiringpipelines monitoringlog delivery & storage
Server · Host · OS still infra
Application Developers
business logicAPI / resolversrows in the database files inside the bucketwhat to logsecret & parameter values feature behaviour

So, the two-line version:

  • Infrastructure owns the container, the pipeline, and the guardrails.
  • Development owns the content, the logic, and the data inside.

The database engine is infra; the rows are the app's. The bucket is infra; the files in it are the app's. The secret store is infra; the secret's value is the app's. When in doubt, ask which side of that line a thing sits on - it almost always answers the question.