Skip to content

gcasanova/aws-landing-zone-blueprint

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

AWS Landing Zone Blueprint

Docs-first reference architecture and operating model for AWS foundations (Control Tower, Identity Center/SSO, org logging, guardrails, and baseline networking). Opinionated, designed to scale across many accounts and teams.

Scope

This repo describes target state, decisions, and operational workflows. It is not a full Terraform implementation of every component.

Contents

  • Multi-account model (OUs, account archetypes, ownership)
  • IAM Identity Center (SSO) model (groups, permission sets, break-glass)
  • Centralized logging & audit baseline (org CloudTrail, retention, integrity checks)
  • Guardrails baseline (SCP intent + rollout strategy)
  • Networking reference (segmentation intent, TGW by default / Cloud WAN when required)
  • Operating model (change workflows, exception process, health checks)
  • Delivery phases (sequenced plan from discovery → handover)

Start here

Reference architecture

Landing Zone Overview

Templates

ADRs (key decisions)

See docs/adr for decision records (multi-account, Identity Center, TGW vs Cloud WAN).

Assumptions

  • AWS Organizations is used (single org unless explicitly required otherwise)
  • Identity Center is the default for interactive access
  • Foundations changes are PR-reviewed and applied via IaC/pipelines (ClickOps only for bootstrap/emergencies)

License

See LICENSE.

About

Docs-first AWS landing zone blueprint: Control Tower, Identity Center (SSO), logging/audit, guardrails (SCP), networking and day-2 ops.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors