Urgent.News

What's breaking now, across thousands of outlets.

Tech

A No-Nonsense Cloud Landing Zone Checklist (Azure, AWS, Google Cloud)

If you've ever been handed a brand-new Azure subscription, AWS account or Google Cloud project and told to "just get something running," you already know the real problem isn't the workload. It's everything around it: who's allowed to log in, how the network is wired, what stops someone from spinning up a public storage bucket at 2am, and where the audit logs actually end up. That governed…

The cloud landing zone concept refers to the foundation necessary for securely launching workloads in cloud environments like Azure, AWS, and Google Cloud. This foundational platform, encompassing identity, network, guardrails, and logging, is distinct from the workloads themselves.

Key components of a cloud landing zone include groups for everything, subscriptions or projects for workloads, identity managed by Microsoft Entra ID, AWS IAM Identity Center, or Google Cloud Identity, and policies like Azure Policy, AWS Service Control Policies, or Google Cloud Organization Policies to enforce security rules.

Azure, AWS, and Google Cloud each present their landing zones differently. Azure's management groups, AWS Organizational Units, and Google Cloud folders serve as grouping entities. Subscriptions, AWS accounts, and Google Cloud projects denote workload boundaries. Centralized logging, network hubs, and shared virtual private clouds create a cohesive architecture.

Before deploying any resources, define the identity provider, enforce multi-factor authentication, and assign roles at the highest applicable scope. Avoid placing workloads within the management account as it bypasses governance controls. Establish non-overlapping IP ranges for each environment before creating the first spoke network.

Guardrails serve as preventative measures against misconfigurations that could result in incidents. Azure Policy, AWS Service Control Policies, and Google Cloud Organization Policies all aim to restrict permissions and enforce security standards. Begin with basic guardrails such as restricting regions, blocking public storage, enforcing encryption, and limiting access to the logging account. Test these rules in a controlled environment before organization-wide deployment.

Logging and cost tagging are equally crucial. Aggregated logs should be centralized for visibility but secured from deletion. A standard tagging scheme must be established upfront to track cost and ownership effectively. Adopting a codified approach for landing zones is integral to their success. Utilize managed identities and service accounts for workload identities, and employ tools like Azure Verified Modules, AWS Account Factory, or Terraform-based blueprints to maintain infrastructure as code.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Thursday 1 October →