Hi,
Unfortunately at this time, there are not any reference architectures on how to configure the Identity broker service that works as the pathway between the identity store, AltaVault, and Amazon STS. I'll check to see if I can gather any additional information on the topic, but at this point I don't know if there will be anything published any time soon.
Regards,
Christopher