diff --git a/docs/user/aws/images/install_nodes_elbs.png b/docs/user/aws/images/install_nodes_elbs.png
deleted file mode 100644
index 350aa785990..00000000000
Binary files a/docs/user/aws/images/install_nodes_elbs.png and /dev/null differ
diff --git a/docs/user/aws/images/install_upi.dia b/docs/user/aws/images/install_upi.dia
index 5d2067660b0..1119d6e9e4b 100644
Binary files a/docs/user/aws/images/install_upi.dia and b/docs/user/aws/images/install_upi.dia differ
diff --git a/docs/user/aws/images/install_upi.svg b/docs/user/aws/images/install_upi.svg
index f8f5a22a831..2d8e14b13e3 100644
--- a/docs/user/aws/images/install_upi.svg
+++ b/docs/user/aws/images/install_upi.svg
@@ -1,5 +1,5 @@
- AWS-General_AWS-Cloud_light-bgAmazon-Route-53Amazon-VPCAmazon-VPC_Internet-Gateway_light-bgAmazon-VPC_Endpoints_light-bgAmazon-VPC_Router_light-bgAmazon-VPC_NAT-Gateway_light-bgAWS-Identity-and-Access-Management_IAMSecurity-group_light-bgAmazon-EC2_M4-Instance_light-bgElastic-Load-Balancing-ELB_light-bgAmazon-Simple-Storage-Service-S3_Bucket_light-bg
+ AWS-General_AWS-Cloud_light-bgAmazon-Route-53Amazon-VPCAmazon-VPC_Internet-Gateway_light-bgAmazon-VPC_Endpoints_light-bgAmazon-VPC_Router_light-bgAmazon-VPC_NAT-Gateway_light-bgAWS-Identity-and-Access-Management_IAMSecurity-group_light-bgAmazon-EC2_M4-Instance_light-bgElastic-Load-Balancing-ELBElastic-Load-Balancing-ELB_light-bgAmazon-Simple-Storage-Service-S3_Bucket_light-bg
@@ -80,7 +80,7 @@
-
+
@@ -92,8 +92,8 @@
-
- NAT Gateway
+
+ NAT Gateway
@@ -103,7 +103,7 @@
-
+
@@ -115,14 +115,14 @@
-
- NAT Gateway
+
+ NAT Gateway
-
+
@@ -134,45 +134,45 @@
-
- NAT Gateway
+
+ NAT Gateway
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
@@ -201,25 +201,25 @@
Master IAM
-
- Worker IAM
+
+ Worker IAM
-
-
-
-
-
-
-
+
+
+
+
+
+
+
cloud credential operator IAM
-
+
Registry S3 Bucket
-
+
@@ -238,49 +238,49 @@
Router
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
image-registry IAM
-
- ingress IAM
+
+ ingress IAM
cluster API IAM
-
-
-
+
+
+
@@ -288,43 +288,43 @@
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
\ No newline at end of file
diff --git a/docs/user/aws/images/install_upi_vpc.svg b/docs/user/aws/images/install_upi_vpc.svg
index 614eefa2341..2bf5caedc72 100644
--- a/docs/user/aws/images/install_upi_vpc.svg
+++ b/docs/user/aws/images/install_upi_vpc.svg
@@ -73,7 +73,7 @@
-
+
@@ -85,8 +85,8 @@
-
- NAT Gateway
+
+ NAT Gateway
@@ -96,7 +96,7 @@
-
+
@@ -108,14 +108,14 @@
-
- NAT Gateway
+
+ NAT Gateway
-
+
@@ -127,45 +127,45 @@
-
- NAT Gateway
+
+ NAT Gateway
-
-
-
-
+
+
+
+
-
-
-
+
+
+
-
-
-
+
+
+
-
+
-
+
-
-
-
+
+
+
diff --git a/docs/user/aws/install.md b/docs/user/aws/install.md
index 43617213f6e..df8a504cc66 100644
--- a/docs/user/aws/install.md
+++ b/docs/user/aws/install.md
@@ -56,9 +56,9 @@ The encryption uses the default EBS key for your target account and region
(`aws kms describe-key --key-id alias/aws/ebs`).
The encrypted AMI is deregistered by `destroy cluster`.
-The relationship of the EC2 instances, elastic load balancers (ELBs) and Route53 hosted zones is as depicted:
+An architecture diagram for the AWS elements created by the full installation is as depicted:
-
+
The nodes within the VPC utilize the internal DNS and use the Router and Internal API load balancers. External/Internet
access to the cluster use the Router and External API load balancers. Nodes are spread equally across 3 availability