The one rule to remember¶
Every infra-versus-app argument is really the same argument, dressed up. Here is the line that settles it, and a picture to point at when someone forgets.
Boundary
Infrastructure owns the server and everywhere it runs - the host, the network, everything inside the cloud. What runs inside it belongs to the teams that write it.
The container is Infrastructure's; the contents are the developers'.
AWS · Cloud · Network · Platform
Infrastructure
everything inside the cloud account
VPC / subnetssecurity groupsload balancer
DNSCDNobject storage (the container)
DB enginesecret & parameter wiringpipelines
monitoringlog delivery & storage
Server · Host · OS
still infra
Application
Developers
business logicAPI / resolversrows in the database
files inside the bucketwhat to logsecret & parameter values
feature behaviour
So, the two-line version:
- Infrastructure owns the container, the pipeline, and the guardrails.
- Development owns the content, the logic, and the data inside.
The database engine is infra; the rows are the app's. The bucket is infra; the files in it are the app's. The secret store is infra; the secret's value is the app's. When in doubt, ask which side of that line a thing sits on - it almost always answers the question.