Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

ChatGPT can help plan AWS infrastructure and draft CloudFormation templates or AWS CDK code, but an ordinary chat does not create AWS resources. Provisioning requires an AWS deployment tool such as CloudFormation, plus an explicitly configured, permissioned connection if ChatGPT is expected to initiate the deployment.

Choose how you want to define AWS infrastructure

CloudFormation and the AWS Cloud Development Kit (CDK) can both provision infrastructure through CloudFormation. The main difference is how you describe the desired resources and how much abstraction you want.

Option How you define infrastructure How provisioning works Useful when Important consideration
CloudFormation A declarative template describes the resources and their configuration. CloudFormation creates and manages a stack, including dependencies between its resources. The AWS CLI can submit the template and create a change set. You want to work directly with the rendered infrastructure definition or keep the deployment relatively straightforward. A template can include IAM resources. Supply the appropriate capability acknowledgement when deploying such a template.
AWS CDK Infrastructure is defined in a supported programming language using reusable constructs. The CDK CLI synthesizes CloudFormation templates and deployment artifacts, then submits them to CloudFormation to provision resources. You want to use code, reuse components, or create higher-level abstractions across stacks. Deployment may require bootstrapping the target account and Region before the stack can be deployed.

The current CDK guide lists TypeScript, JavaScript, Python, Java, C#, and Go as supported languages. CDK does not bypass CloudFormation: it generates CloudFormation templates for the provisioning stage.

Decide what ChatGPT is allowed to do

There are three distinct ways to use ChatGPT in an AWS workflow. They differ in whether ChatGPT can merely prepare material or can call a tool that may change infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Approach Execution authority What must be configured Approval and availability
Drafting assistance ChatGPT produces explanations, templates, code, or troubleshooting suggestions. A person runs AWS commands in a controlled environment. No AWS execution connection is needed for drafting. The operator separately configures AWS credentials and tools. The human controls when a command is run; ChatGPT’s generated code still needs review and validation.
Custom GPT action A configured action can call an external API whose operations and parameters are defined by an OpenAPI schema. The action needs an API server, authentication, and a narrowly defined schema. It must connect to an approved API or deployment service; it is not a built-in direct AWS connection. Workspace policy may restrict actions. A GPT can use apps or actions, but not both at once.
Custom MCP app An app may expose tools that read or modify external systems, depending on its configuration and permissions. An administrator or owner may need to enable developer mode and publish a vetted app in an eligible workspace. Availability depends on plan and workspace settings. Write actions may require confirmation, and some risky actions may be blocked. Check current workspace controls.

If you connect a tool that can deploy, design its API surface and AWS role to permit only the actions and environments it needs. Test the integration outside production first, and retain an explicit human approval point for production changes. A connected app or server also creates a trust boundary: use only integrations your organization has vetted.

Prepare credentials and the target environment

Use short-term access

For local human access, AWS recommends configuring credentials with the AWS CLI and using IAM Identity Center when applicable. For automation, use an IAM role and short-term credentials rather than embedding long-lived IAM user keys. Never paste AWS secret access keys into a ChatGPT prompt.

Confirm the account and Region

Identify the AWS account and Region for each stack before generating or deploying infrastructure. Make sure the credentials in use can access that target and have only the permissions required for the planned resources.

Bootstrap CDK environments when required

CDK deployment may require bootstrap resources in the target environment. Bootstrap each account-and-Region combination that needs it; bootstrapping one Region does not prepare another. Those resources may incur AWS charges. Review the bootstrap trust list and execution policies carefully: trusted accounts and execution roles can receive broad read or write authority.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Generate, review, and deploy in controlled steps

  1. Describe the intended change. Tell ChatGPT which account and Region are in scope, what the resources are for, the expected lifecycle, and any security or availability constraints. Ask it to explain IAM permissions, public exposure, data retention, and likely cost drivers along with the draft.
  2. Generate a draft. Ask for a CloudFormation template or CDK implementation. Treat the result as untested code; a plausible-looking response is not proof that the template is valid, secure, or suitable for your environment.
  3. Run your normal local checks. For CDK, synthesize the app to inspect the CloudFormation output; use the validation and review checks established by your team. For either approach, check that the generated resources and settings match the requested design.
  4. Inspect the proposed changes before execution. Review creates, updates, replacements, and deletions, with particular attention to IAM changes, network exposure, storage retention, and logging. Do not approve a change set just because ChatGPT generated or explained it.
  5. Deploy to a non-production environment first when practical. This gives you a chance to test the deployment and application behavior before allowing a production change.
  6. Verify the result. Check the stack status and outputs in AWS tooling, test the application-level behavior, and monitor the resulting resources and costs.

Stage a CloudFormation change set with the AWS CLI

The AWS CLI cloudformation deploy command creates and executes a change set by default. To create a review point instead, use --no-execute-changeset:

aws cloudformation deploy --template-file template.yaml --stack-name my-stack --no-execute-changeset

Inspect the resulting change set in your AWS tooling. Execute it only after review, using the change set’s actual name:

aws cloudformation execute-change-set --stack-name my-stack --change-set-name CHANGE_SET_NAME

Replace CHANGE_SET_NAME with the name shown for the change set; it is an instruction placeholder, not a literal value. If the template creates IAM resources, provide the capability acknowledgement appropriate to those resources when running the deploy command. The option to stage a change set is useful whether ChatGPT drafted the template or a developer wrote it independently.

Use CDK through synthesis and CloudFormation

A typical CDK sequence is to configure valid credentials for the target, bootstrap the target account and Region if the stack requires it, synthesize the app, and review the generated CloudFormation before deploying. Use your team’s established deployment controls and environment-specific checks; avoid giving a generated CDK app unattended production authority.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect the deployment beyond the prompt

  • Keep permissions narrow. Limit the AWS role, connected API operations, and trusted accounts to the resources and environments required. Bootstrap trust and execution policies deserve particular scrutiny because they can grant powerful account-level access.
  • Enforce compliance outside generated code when necessary. A CDK app alone may not guarantee compliance. AWS notes that controls such as CloudFormation Hooks or separate pipeline validation may be needed to enforce requirements.
  • Account for variable costs. CDK bootstrap resources may incur charges, while application cost depends on the services, configuration, usage, account, and Region. Estimate from the actual proposed design rather than assuming a universal deployment price.
  • Keep a human review path. Tool confirmation behavior and workspace controls depend on the integration and settings. Treat production writes as a change-management decision, not as a natural consequence of asking ChatGPT a question.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.