Skip to content Skip to footer

What New AWS Certificate and Terraform Controls Mean for Enterprise AI Systems

What Happened

  • Enterprise AI: On October 6, 2026, Atlassian and OpenAI announced an expanded partnership to connect AI models with enterprise knowledge and help teams plan, build, and deliver work. The announcement does not specify a new API or model version. [1]
  • Certificate issuance: On October 6, AWS Certificate Manager (ACM) added AWS PrivateLink support for issuing and renewing public TLS certificates through ACME. With a managed ACME endpoint and VPC interface endpoint configured, existing ACMEv2 clients can use the same directory URL while private DNS routes traffic through the endpoint. The feature is available in all commercial AWS Regions. [2]
  • Infrastructure changes: On October 5, AWS Control Tower Account Factory for Terraform (AFT) added plan-only customization runs. Administrators can preview global and account customization changes without applying them. The capability is documented in the AFT 1.22.0 release notes and supports open-source Terraform, Terraform Cloud, and Terraform Enterprise wherever AFT is supported. [3]

Why It Matters to Businesses

The AWS changes offer two practical controls: a private network path for ACME certificate operations and a review step before AFT customizations change accounts. Both are relevant to teams operating AI applications across multiple AWS accounts. The Atlassian–OpenAI announcement signals a direction for connecting AI to work context, but businesses should wait for product-level details before assuming a particular integration or capability is available. [1][2][3]

Kimbodo Engineering Perspective

These are different decisions, not one upgrade program. PrivateLink is most useful where certificate automation already runs in VPCs and reducing exposure to public network paths is a requirement; its endpoint charges need to be justified. Plan-only runs improve change review, but a successful plan is not a guarantee that a later apply will produce the same result. For enterprise knowledge integrations, the decisive question is whether retrieval and actions respect the user’s existing permissions. [1][2][3]

How We Would Implement It

  • ACME: Create the managed ACME and VPC interface endpoints, configure private DNS, then test issuance and renewal with an existing ACMEv2 client. Verify the workflow and inspect ACM, CloudTrail, and CloudWatch records. [2]
  • AFT: Add plan-only runs to the customization CI/CD workflow. Require review of proposed changes for global and account customizations before an authorized apply, then check the applied result for unexpected drift. [3]
  • Enterprise AI: Assess the Atlassian–OpenAI integration against specific workflows only when implementation details are available. Test permission boundaries and action approvals before enabling it for sensitive work. [1]

Risks, Costs and Security

AWS PrivateLink interface endpoint charges apply, and endpoint deployment adds networking configuration to operate. Certificate workflows still need appropriate access controls and monitoring. AFT plans may become stale between review and apply, so deployment pipelines should retain approval and post-apply checks. Connecting AI to enterprise knowledge increases the importance of access enforcement, auditability, and controls on actions taken on a user’s behalf. [1][2][3]

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Application Development practice, or Estimate My AI Application.

Sources

  1. [1] Atlassian and OpenAI expand partnership to turn enterprise knowledge into action
  2. [2] AWS Certificate Manager now supports ACME issuance through AWS PrivateLink
  3. [3] AWS Control Tower AFT now supports plan-only customization runs

Leave a comment

0.0/5