Security Architecture Diagram Generator
Quick Start: Define trust boundaries → Place identity/encryption/firewall icons → Connect with access flows → Group into security zones → Wrap in ```plantuml fence.
⚠️ IMPORTANT: Always use ```plantuml or ```puml code fence. NEVER use ```text — it will NOT render as a diagram.
Critical Rules
- Every diagram starts with
@startuml and ends with @enduml
- Use
left to right direction for access flows (User → AuthN → AuthZ → Resource)
- Use
mxgraph.aws4.* stencil syntax for security service icons
- Default colors are applied automatically — you do NOT need to specify
fillColor or strokeColor
- Use
rectangle "Trust Boundary" { ... } for security zones
- Directed flows use
-->, audit/async flows use ..> (dashed)
Full stencil reference: See stencils/README.md for 9500+ available icons.
Mxgraph Stencil Syntax
mxgraph.aws4.<icon> "Label" as <alias>
Identity & Access Stencils
| Category |
Stencils |
Purpose |
| IAM |
identity_and_access_management, identity_access_management_iam_roles_anywhere |
Identity policies & roles |
| SSO/Directory |
cognito, ad_connector, directory_service, cloud_directory |
User authentication & federation |
| STS |
sts, sts_alternate |
Temporary security credentials |
| Organizations |
organizations, organizations_account, organizations_organizational_unit |
Multi-account governance |
Encryption & Secrets Stencils
| Category |
Stencils |
Purpose |
| KMS |
key_management_service, key_management_service_external_key_store |
Key management & encryption |
| Secrets |
secrets_manager |
Secrets rotation & storage |
| Certificates |
certificate_manager, private_certificate_authority |
TLS certificate lifecycle |
| HSM |
cloudhsm |
Hardware security module |
| Encryption |
encrypted_data |
Encrypted data at rest |
Network Security Stencils
| Category |
Stencils |
Purpose |
| Firewall |
network_firewall, network_firewall_endpoints, firewall_manager |
Network traffic filtering |
| WAF |
generic_firewall |
Web application firewall |
| Shield |
shield, shield_shield_advanced, shield2 |
DDoS protection |
| Security Group |
security_group, group_security_group |
Instance-level firewall |
Threat Detection & Compliance Stencils
| Category |
Stencils |
Purpose |
| Detection |
guardduty, detective, inspector |
Threat detection & investigation |
| Data Protection |
macie |
Sensitive data discovery |
| Compliance |
security_hub, security_hub_finding, audit_manager, config |
Compliance posture & audit |
| Logging |
cloudtrail, cloudtrail_cloudtrail_lake, security_lake |
Audit trail & log aggregation |
| Governance |
control_tower, organizations |
Multi-account governance |
| Incident |
security_incident_response |
Incident management |
Connection Types
| Syntax |
Meaning |
Use Case |
A --> B |
Solid arrow |
Auth flow / access request |
A ..> B |
Dashed arrow |
Audit event / async detection |
A -- B |
Solid line |
Trust relationship |
A --> B : "label" |
Labeled connection |
Describe protocol or credential |
Quick Example
@startuml
left to right direction
mxgraph.aws4.users "Users" as users
mxgraph.aws4.cognito "Cognito" as auth
mxgraph.aws4.identity_and_access_management "IAM" as iam
rectangle "Protected Resources" {
mxgraph.aws4.s3 "Data (S3)" as s3
mxgraph.aws4.encrypted_data "Encrypted" as enc
}
users --> auth : "login"
auth --> iam : "token"
iam --> s3
s3 --> enc
@enduml
Security Architecture Types
| Type |
Purpose |
Key Stencils |
Example |
| IAM & AuthN |
Identity and authentication |
cognito, identity_and_access_management, sts |
iam-authn.md |
| Encryption Pipeline |
Data encryption at rest/in-transit |
key_management_service, certificate_manager, secrets_manager |
encryption-pipeline.md |
| Network Security |
Perimeter defense & firewalls |
network_firewall, shield, security_group |
network-security.md |
| Threat Detection |
Automated threat response |
guardduty, detective, security_hub |
threat-detection.md |
| Compliance Audit |
Governance & audit trail |
config, audit_manager, cloudtrail, security_lake |
compliance-audit.md |
| Zero Trust |
Zero-trust access model |
cognito, identity_and_access_management, network_firewall |
zero-trust.md |
| Data Protection |
Sensitive data classification |
macie, encrypted_data, key_management_service |
data-protection.md |
| Multi-account Gov |
Organization-wide security |
organizations, control_tower, security_hub |
multi-account-governance.md |
1---2name: security-23description: Create security architecture diagrams using PlantUML syntax with identity, encryption, firewall, and compliance stencil icons. Best for IAM flows, zero-trust models, encryption pipelines, and threat detection architectures.4---5
6# Security Architecture Diagram Generator
7
8**Quick Start:** Define trust boundaries → Place identity/encryption/firewall icons → Connect with access flows → Group into security zones → Wrap in ` ```plantuml ` fence.
9
10> ⚠️ **IMPORTANT:** Always use ` ```plantuml ` or ` ```puml ` code fence. NEVER use ` ```text ` — it will NOT render as a diagram.
11
12## Critical Rules
13
14- Every diagram starts with `@startuml` and ends with `@enduml`
15- Use `left to right direction` for access flows (User → AuthN → AuthZ → Resource)
16- Use `mxgraph.aws4.*` stencil syntax for security service icons
17- Default colors are applied automatically — you do NOT need to specify `fillColor` or `strokeColor`
18- Use `rectangle "Trust Boundary" { ... }` for security zones
19- Directed flows use `-->`, audit/async flows use `..>` (dashed)
20
21**Full stencil reference:** See [stencils/README.md](../uml/stencils/README.md) for 9500+ available icons.
22
23## Mxgraph Stencil Syntax
24
25```
26mxgraph.aws4.<icon> "Label" as <alias>
27```
28
29### Identity & Access Stencils
30
31| Category | Stencils | Purpose |
32|----------|----------|---------|
33| IAM | `identity_and_access_management`, `identity_access_management_iam_roles_anywhere` | Identity policies & roles |
34| SSO/Directory | `cognito`, `ad_connector`, `directory_service`, `cloud_directory` | User authentication & federation |
35| STS | `sts`, `sts_alternate` | Temporary security credentials |
36| Organizations | `organizations`, `organizations_account`, `organizations_organizational_unit` | Multi-account governance |
37
38### Encryption & Secrets Stencils
39
40| Category | Stencils | Purpose |
41|----------|----------|---------|
42| KMS | `key_management_service`, `key_management_service_external_key_store` | Key management & encryption |
43| Secrets | `secrets_manager` | Secrets rotation & storage |
44| Certificates | `certificate_manager`, `private_certificate_authority` | TLS certificate lifecycle |
45| HSM | `cloudhsm` | Hardware security module |
46| Encryption | `encrypted_data` | Encrypted data at rest |
47
48### Network Security Stencils
49
50| Category | Stencils | Purpose |
51|----------|----------|---------|
52| Firewall | `network_firewall`, `network_firewall_endpoints`, `firewall_manager` | Network traffic filtering |
53| WAF | `generic_firewall` | Web application firewall |
54| Shield | `shield`, `shield_shield_advanced`, `shield2` | DDoS protection |
55| Security Group | `security_group`, `group_security_group` | Instance-level firewall |
56
57### Threat Detection & Compliance Stencils
58
59| Category | Stencils | Purpose |
60|----------|----------|---------|
61| Detection | `guardduty`, `detective`, `inspector` | Threat detection & investigation |
62| Data Protection | `macie` | Sensitive data discovery |
63| Compliance | `security_hub`, `security_hub_finding`, `audit_manager`, `config` | Compliance posture & audit |
64| Logging | `cloudtrail`, `cloudtrail_cloudtrail_lake`, `security_lake` | Audit trail & log aggregation |
65| Governance | `control_tower`, `organizations` | Multi-account governance |
66| Incident | `security_incident_response` | Incident management |
67
68### Connection Types
69
70| Syntax | Meaning | Use Case |
71|--------|---------|----------|
72| `A --> B` | Solid arrow | Auth flow / access request |
73| `A ..> B` | Dashed arrow | Audit event / async detection |
74| `A -- B` | Solid line | Trust relationship |
75| `A --> B : "label"` | Labeled connection | Describe protocol or credential |
76
77### Quick Example
78
79```plantuml
80@startuml
81left to right direction
82mxgraph.aws4.users "Users" as users
83mxgraph.aws4.cognito "Cognito" as auth
84mxgraph.aws4.identity_and_access_management "IAM" as iam
85
86rectangle "Protected Resources" {
87 mxgraph.aws4.s3 "Data (S3)" as s3
88 mxgraph.aws4.encrypted_data "Encrypted" as enc
89}
90
91users --> auth : "login"
92auth --> iam : "token"
93iam --> s3
94s3 --> enc
95@enduml
96```
97
98## Security Architecture Types
99
100| Type | Purpose | Key Stencils | Example |
101|------|---------|--------------|---------|
102| IAM & AuthN | Identity and authentication | `cognito`, `identity_and_access_management`, `sts` | [iam-authn.md](examples/iam-authn.md) |
103| Encryption Pipeline | Data encryption at rest/in-transit | `key_management_service`, `certificate_manager`, `secrets_manager` | [encryption-pipeline.md](examples/encryption-pipeline.md) |
104| Network Security | Perimeter defense & firewalls | `network_firewall`, `shield`, `security_group` | [network-security.md](examples/network-security.md) |
105| Threat Detection | Automated threat response | `guardduty`, `detective`, `security_hub` | [threat-detection.md](examples/threat-detection.md) |
106| Compliance Audit | Governance & audit trail | `config`, `audit_manager`, `cloudtrail`, `security_lake` | [compliance-audit.md](examples/compliance-audit.md) |
107| Zero Trust | Zero-trust access model | `cognito`, `identity_and_access_management`, `network_firewall` | [zero-trust.md](examples/zero-trust.md) |
108| Data Protection | Sensitive data classification | `macie`, `encrypted_data`, `key_management_service` | [data-protection.md](examples/data-protection.md) |
109| Multi-account Gov | Organization-wide security | `organizations`, `control_tower`, `security_hub` | [multi-account-governance.md](examples/multi-account-governance.md) |