AWS Architecture Diagram Skill
Generate AWS architecture diagrams as native
files using official AWS Architecture Icons. Optionally export to PNG, SVG, or PDF with embedded XML (so exported files remain editable in draw.io).
How to create a diagram
- Generate draw.io XML in mxGraphModel format following the rules below
- Write the XML to a file using the Write tool
- If the user requested an export format (png, svg, pdf), export using the draw.io CLI (see Export section)
- Open the result with (macOS), (Linux), or print the path
Layout Rules
- Left-to-right flow for data/request path
- UI/Frontend on the LEFT (users access from left side)
- Data sources / external systems on the RIGHT
- Use horizontal lanes for parallel paths (top lane, bottom lane)
- Minimum 220px horizontal spacing between icons (room for edge labels)
- Minimum 250px vertical spacing between lanes
- Secondary/auxiliary services (monitoring, DLQ) go BELOW main flow with 280px+ gap
- Canvas:
pageWidth="2400" pageHeight="1400"
, viewport
- Always include a title block after the background rectangle:
xml
<mxCell value="<b>Diagram Title</b><br>Author | Date | Version" style="text;html=1;align=left;verticalAlign=top;whiteSpace=wrap;rounded=0;fontSize=14;spacing=8;" vertex="1" parent="1">
<mxGeometry x="40" y="30" width="420" height="60" as="geometry" />
</mxCell>
Icon Style
- Icons are from draw.io's built-in stencil library — the official AWS Architecture Icons (https://aws.amazon.com/architecture/icons/)
- Icon size: 78x78px for main services, 65x65px for secondary
- Use on all icons
- Use on all AWS service icons
- Font size: 12px for labels
- NO colored backgrounds on group boxes — always
Edge Style — CRITICAL FOR CLEAN DIAGRAMS
Base edge style:
edgeStyle=orthogonalEdgeStyle;rounded=1;orthogonalLoop=1;jettySize=auto;html=1;strokeWidth=2;exitX=1;exitY=0.5;exitDx=0;exitDy=0;entryX=0;entryY=0.5;entryDx=0;entryDy=0;
Edge label rules:
- Keep labels SHORT (1-2 words max). Detail goes in icon labels, not edge labels.
- Always add
labelBackgroundColor=#F5F5F5;fontSize=11;
to edges with labels
- For edges WITHOUT labels: omit entirely
- When NOT to label: if the flow is obvious (Lambda → DynamoDB doesn't need "Write")
For edges to services ABOVE or BELOW main flow, use explicit exit/entry points:
- Exit bottom:
exitX=0.5;exitY=1;exitDx=0;exitDy=0;
- Enter top:
entryX=0.5;entryY=0;entryDx=0;entryDy=0;
- This prevents draw.io from routing lines through other icons
Edge types:
- Solid (): primary data flow
- Dashed (): optional/async
- Red dashed (
strokeWidth=2;dashed=1;strokeColor=#DD344C;
): error path
Edge attachment (CRITICAL — fixes "green cross" problem):
- Every edge MUST have both and attributes referencing valid cell IDs
- NEVER create floating/unattached edges — all edges must be bound to shapes at both ends
- Always include and to define exact connection points on the shape perimeter
- Cross-container edges: When source and target are in different containers, set the edge's
PNG Export Background
First element after root cells (lowest z-order):
xml
<mxCell value="" style="rounded=0;whiteSpace=wrap;html=1;fillColor=#F5F5F5;strokeColor=none;" vertex="1" parent="1">
<mxGeometry x="0" y="0" width="2400" height="1400" as="geometry" />
</mxCell>
AWS Icon Patterns (VERIFIED WORKING)
resourceIcon (78x78, colored square frame)
| Service | resIcon | fillColor |
|---|
| Lambda | | |
| API Gateway | | |
| EventBridge | | |
| SNS | | |
| SES | mxgraph.aws4.simple_email_service
| |
| Step Functions | mxgraph.aws4.step_functions
| |
| DynamoDB | | |
| RDS | | |
| S3 | | |
| CloudFront | | |
| Route 53 | | |
| ECS | | |
| EC2 | | |
Style template:
sketch=0;points=[[0,0,0],[0.25,0,0],[0.5,0,0],[0.75,0,0],[1,0,0],[0,1,0],[0.25,1,0],[0.5,1,0],[0.75,1,0],[1,1,0],[0,0.25,0],[0,0.5,0],[0,0.75,0],[1,0.25,0],[1,0.5,0],[1,0.75,0]];outlineConnect=0;fontColor=#232F3E;fillColor=<COLOR>;strokeColor=#ffffff;dashed=0;verticalLabelPosition=bottom;verticalAlign=top;align=center;html=1;fontSize=12;fontStyle=0;aspect=fixed;shape=mxgraph.aws4.resourceIcon;resIcon=mxgraph.aws4.<SERVICE>
productIcon (70x100, taller with service header bar)
Style template:
sketch=0;outlineConnect=0;fontColor=#232F3E;gradientColor=none;strokeColor=#ffffff;fillColor=#232F3E;dashed=0;verticalLabelPosition=bottom;verticalAlign=top;align=center;html=1;whiteSpace=wrap;fontSize=12;fontStyle=0;shape=mxgraph.aws4.productIcon;prIcon=mxgraph.aws4.<SERVICE>
Standalone shapes (no resIcon needed)
| Shape | shape value | fillColor |
|---|
| Client/Browser | | |
| Traditional Server | mxgraph.aws4.traditional_server
| |
| Firewall | mxgraph.aws4.generic_firewall
| |
| ALB | mxgraph.aws4.application_load_balancer
| |
| NLB | mxgraph.aws4.network_load_balancer
| |
| VPC Endpoint | | |
Group boundaries
| Group | grIcon | strokeColor |
|---|
| AWS Cloud | mxgraph.aws4.group_aws_cloud_alt
| |
| Account | mxgraph.aws4.group_account
| |
| On-premise | mxgraph.aws4.group_on_premise
| |
| Corporate DC | mxgraph.aws4.group_corporate_data_center
| |
| VPC | | |
| Subnet (public) | mxgraph.aws4.group_security_group
| |
| Subnet (private) | mxgraph.aws4.group_security_group
| |
Container nesting (CRITICAL for grouping):
- ALL group/boundary shapes MUST include
container=1;dropTarget=1;
in their style
- Child cells inside a boundary MUST set
parent="<boundary-cell-id>"
instead of
- This ensures moving a boundary moves all its children together
- Child geometry coordinates are relative to the parent container, not the canvas
- Cross-container edges: When source and target are in different containers, set the edge's
BROKEN Icons — DO NOT USE
resIcon=mxgraph.aws4.dynamodb_table
— renders as empty colored square
resIcon=mxgraph.aws4.dynamodb_stream
— renders as empty colored square
resIcon=mxgraph.aws4.general_saml_token
— renders as black square
resIcon=mxgraph.aws4.endpoint
— may not render
resIcon=mxgraph.aws4.kinesis_data_streams
— unreliable
Alternatives:
- DynamoDB tables/streams → use
resIcon=mxgraph.aws4.dynamodb
with descriptive labels
- External systems → use
shape=mxgraph.aws4.traditional_server
- Browsers/clients → use
shape=mxgraph.aws4.client
Audience Mode
Before generating, assess the target audience:
- Technical: Use service names, protocol labels (HTTPS, gRPC), CIDR blocks, instance types
- Non-technical: Use action labels ("Store Data", "Send Notification"), hide implementation details, use numbered flow (① ② ③)
If unclear, ask: "Technical audience or executive/non-technical?"
Numbered flow edges (for non-technical mode)
Instead of technical labels, show flow order with circled numbers:
- Flow A: ① → ② → ③ → ④ (white circled numbers)
- Flow B: ❶ → ❷ → ❸ → ❹ (black circled numbers for second flow)
Use edge labels:
with
fontSize=14;fontStyle=1;labelBackgroundColor=#ffffff;
Companion Guide
After generating the .drawio file, also generate a markdown guide:
- Same filename with extension
- Contents: diagram title, flow description (numbered steps), service list with purpose, key design decisions
Two-Step Edit Approach
After generating the initial .drawio file:
- Export to PNG using the draw.io CLI (see Export section)
- Review the PNG visually — check for empty/broken icons, overlapping edges, misaligned labels
- Fix issues in the .drawio XML and re-export
This catches rendering problems (wrong stencil names, broken styles) that are invisible in raw XML.
Icon Name Gotchas — CRITICAL
draw.io stencil names do NOT always match current AWS service names. Services that were renamed keep their legacy stencil names:
| AWS Service Name | draw.io resIcon name | Why |
|---|
| Amazon OpenSearch Service | | Renamed from Elasticsearch in 2021; also works |
| Amazon EventBridge | | Was CloudWatch Events |
| AWS Fargate | | Correct |
| VPC Peering | | Resource-level: shape=mxgraph.aws4.peering;strokeColor=none
— NOT or (those render as blank squares) |
| Amazon MSK | managed_streaming_for_kafka
| NOT (renders as blank square) |
| IAM Identity Center | | NOT (renders as blank square) |
Rule: Always verify icon names from the reference files. If a service icon renders as an empty box, the stencil name is wrong. Check the draw.io source at
src/main/webapp/js/diagramly/sidebar/Sidebar-AWS4.js
for the canonical name.
Fallback for unmapped services: If a service is NOT found in any reference file, use this generic AWS cloud icon with the service name as label:
sketch=0;outlineConnect=0;fontColor=#232F3E;fillColor=#232F3E;strokeColor=#ffffff;dashed=0;verticalLabelPosition=bottom;verticalAlign=top;align=center;html=1;fontSize=12;fontStyle=0;aspect=fixed;shape=mxgraph.aws4.resourceIcon;resIcon=mxgraph.aws4.general_AWScloud
Never render an unknown service as a plain colored rectangle with no label.
Validation Step
After generating XML, verify:
- Every value exists in the reference files
- Service-level icons have
- Resource-level icons have
- No XML comments present
- All cell IDs are unique
- Every edge has
<mxGeometry relative="1" as="geometry" />
- No icon uses a guessed stencil name — all verified against reference files
- Every edge has both and attributes referencing valid cell IDs (no floating edges)
- All group/boundary shapes include
container=1;dropTarget=1;
in their style
- Children inside boundaries use (not )
Export
For PNG/SVG/PDF export using draw.io Desktop CLI:
Multi-page Diagrams
For complex architectures, use multiple pages in one .drawio file:
xml
<mxfile>
<diagram id="overview" name="Overview">...</diagram>
<diagram id="networking" name="Networking Detail">...</diagram>
<diagram id="data-flow" name="Data Flow">...</diagram>
</mxfile>
- Page 1: High-level overview (service-level icons only)
- Page 2+: Detail views (resource-level icons, subnet layouts, etc.)
Legend / Title Block
Place in top-left corner, inside the background rectangle:
xml
<mxCell value="<b>Diagram Title</b><br>Author | Date | Version" style="text;html=1;align=left;verticalAlign=top;whiteSpace=wrap;rounded=0;fontSize=14;spacing=8;" vertex="1" parent="1">
<mxGeometry x="40" y="40" width="300" height="50" as="geometry" />
</mxCell>
PNG Export Background Fix
Place a
rectangle covering the entire diagram as the bottom-most element to prevent black background on export.
Export CLI
| Platform | CLI Path |
|---|
| macOS | /Applications/draw.io.app/Contents/MacOS/draw.io
|
| Linux | (on PATH via snap/apt) |
| Windows | "C:\Program Files\draw.io\draw.io.exe"
|
bash
<CLI> -x -f <format> -e -b 10 -o <output> <input>
Flags:
export,
format (png/svg/pdf),
embed diagram XML,
border
Exported files use double extension:
— signals embedded XML, re-editable in draw.io.
XML Well-formedness (CRITICAL)
- NEVER include XML comments () — they cause parse errors
- Escape special characters:
- Always use unique values for each mxCell
- Every edge MUST have
<mxGeometry relative="1" as="geometry" />
as child
- Root structure requires cells (root) and (default layer, parent="0")
Official Reference