I'm sorry but whereever I've seen aws at work there was a sprawling terraform codebase to manage it. This no different than puppet or ansible on bare metal complexoty-wise, you just pat extra for the shiny tools