Urgent.News

What's breaking now, across thousands of outlets.

Tech

[pt-BR] AWS Landing Zones na prática - Parte 1

Quando uma organização começa a utilizar AWS, é relativamente comum que tudo nasça dentro de uma única conta. No começo, isso parece razoável. Uma conta contém algumas VPCs, aplicações, bancos de dados, buckets e usuários. Com o crescimento do ambiente, porém, começam a surgir perguntas mais difíceis: Produção e desenvolvimento deveriam estar na mesma conta?, Onde devem ficar os logs de…

Original Portuguese Read in English

AWS Landing Zones represent a framework for establishing a foundational multi-account architecture within the Amazon Web Services (AWS) environment. The concept aims to provide a baseline for various aspects such as multi-account architecture, Identity and Access Management (IAM), governance, data security, network architecture, logging, account structure, billing, and customization mechanisms.

Landing Zones are not merely VPCs prepared for application deployment, nor are they synonymous with AWS Control Tower or AWS Organizations.

The primary goal of a Landing Zone is to create a structured environment where organization workloads can be built upon. Before migrating or creating applications, it is essential to establish the rules of the road through this foundational framework. A typical multi-account structure might include separate accounts for security, logging, and shared services, each with their own organizational units (OUs) to maintain clear boundaries and responsibilities.

One key principle is to use AWS accounts as the primary boundaries of isolation. Instead of a single account structure like:

AWS Account ├── VPC Development ├── VPC Staging ├── VPC Production ├── Security ├── Logs └── Shared Services

A more isolated approach would be:

AWS Organization │ ├── Security OU │ ├── Log Archive Account │ └── Audit Account │ ├── Infrastructure OU │ ├── Network Account │ └── Shared Services Account │ ├── Workloads OU │ ├── Development Account │ ├── Staging Account │ └── Production Account │ └── Sandbox OU

This separation ensures that failures or misconfigurations in a development account, for instance, cannot compromise production resources. AWS advises against running production workloads in the management account of a managed organization via Control Tower.

A well-designed Landing Zone should address several critical components, as outlined by AWS Prescriptive Guidance. Initial configuration should focus on account structure, identity management, governance, security, networking, logging, billing, and customization mechanisms. This includes defining how AWS accounts will be organized and utilized, setting up networking standards, establishing IAM policies, configuring logging and auditing mechanisms, and defining governance policies to regulate resource access and usage.

While AWS Control Tower offers a managed implementation of a Landing Zone, it is not the concept itself. Control Tower automates many aspects of multi-account creation and governance, integrating various AWS services such as AWS Organizations, IAM, AWS Service Catalog, CloudTrail, and Config. A typical Control Tower setup includes a management account, security and log archive accounts, and multiple workload accounts, all governed through controls that enforce governance policies and detect deviations from configured rules.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Wednesday 19 August →