WHAT IS AWS LANDING ZONE?
Are you planning for cloud migrations? Cloud adoption is increasing rapidly across organizations. More and more workloads are being moved to cloud every day. It is essential that you need a good cloud migration strategy in place for successful migrations. Lack of effective strategies can lead to higher costs, longer migration cycles or even failure.
Before you deploy your applications on Amazon Web Services (AWS), you need to design and configure a base environment. Traditional methods of setting up a multi account environment in AWS take significant amount of time and effort. It involves setting up of configurations, security, VPC, logging and enabling a set of other AWS services and settings to reach the baseline requirements.
Landing Zone, a new solution by AWS, which helps customers to easily setup secure, scalable, multiaccount environments based on best practices. It is an orchestration framework for your foundational AWS environment. It provides a baseline to get started with multi-account architecture, identity and access management, governance, data security, network design and logging. This solution saves time by automating the setup of an environment for running secure and scalable workloads, while implementing an initial security baseline through the creation of core accounts and resources.
Key Benefits
BEST PRACTICES IN CREATING LANDING ZONE
Look at how successful businesses operate!
One can always develop custom methods and practices of working and find out which one is the best. But this approach is inefficient, costly, time consuming and failure prone. A far more effective approach would be to look at successful businesses, and find out and use industry’s best practices and standards. AWS recommends various Landing Zone best practices, including multi-account structure, security controls, self-service with guardrails, scalability, and extensibility from the initial landing zone environment, and automation with Infrastructure as Code (IaC).
COMMON MISTAKES
Learn from mistakes and move on.
Some of the common mistakes and errors while using AWS Landing Zone are:
ROLE OF AUTOMATION
Automation aids in achieving efficiency through increased productivity, reliability, scalability, faster time to market, optimal use of resources, better quality, security and best practices. AWS Landing Zone solution automates landing zone deployment and configuration, which otherwise is a cumbersome task.
AWS has three options for creating your landing zone:
Recommended by LinkedIn
SIGNIFICANCE OF DRIFT WATCH
Monitor and control changes to stay compliant.
When a landing zone is created, it is compliant with the governance rules enforced by the chosen guardrails. As the landing zone is used by members of the organization, it may change the compliance status, creating a drift. These changes could be accidental or intentionally made to respond to some urgent operational requirements, but needs to be identified and resolved.
Drift Detection
Drift detection identifies resources that need changes or configuration updates to resolve the drift. AWS Control Tower automatically detects drifts and generates notifications in the audit trails. Member account administrators and master account administrators can receive such notifications and take necessary steps to resolve it.
Drift Resolution
Drift resolution needs to be done manually through the console or settings page. Some drifts can be repaired through settings page, others by can be resolved manually by administrators. If your landing zone is in a state of drift, the Enroll account feature in AWS Control Tower will not work. In such cases, you must provision new accounts through AWS Service Catalog. Examples of some of the Governance Drift are given below,
Resolving drift helps to ensure your compliance with governance regulations.
SUMMARY
AWS Landing Zone helps you start your cloud migration quickly and easily, following necessary best practices and security requirements out there in the industry. Recommend to choose and use the right automation tools for your AWS Landing Zone setup and management. Setting up is not enough, monitor, identify drifts and resolve it to be compliant always.
About The Author
Founder | Vice President | CTO | Architect | Consultant | Mentor | Advisor | Faculty
CONTACT US:
CLOUDCONTROL helps organizations to migrate their legacy and on premise applications to private/public cloud environments. We have migrated more than 800 enterprise apps to cloud.
We are passionate about #oneclick deployments, faster time to market, maximizing security and controls using our platform. Visit us to learn more… ecloudcontrol.com
For more information : ✉ info@ecloudcontrol.com