AWS cloud architecture consulting

AWS landing-zone advice copied from another provider misses Organizations SCPs, Transit Gateway route tables and Cost and Usage Report allocation. This engagement stays on AWS primitives.

Who this engagement is for

Teams whose production control plane is AWS and who need landing-zone, networking, IAM or cost-allocation decisions written against AWS documentation.

Information required to begin

  • Organization structure and whether Control Tower is in use
  • IAM Identity Center or IAM federation model
  • VPC and Transit Gateway diagrams
  • Regions that hold production data

Engineering process

  1. Consultation scoped to AWS accounts and regions
  2. Review against current AWS documentation for the services you run
  3. Written ADRs and a risk register in AWS terminology

Deliverables

  • Current-state assessment in AWS terms
  • Target architecture and ADRs
  • Risk register

Provider-specific scope

  • AWS Organizations, Control Tower, IAM, IAM Identity Center
  • VPC, Transit Gateway, PrivateLink, NAT Gateway, Route 53
  • Cost Explorer, Cost and Usage Report, Savings Plans and Reserved Instances as documented

Limitations

  • We do not replace AWS Support.
  • Recommendations cite AWS docs current as of the review date. Service names change.

What is not included

  • Azure, Google Cloud or Alibaba Cloud design except as a documented dependency

Author

Written by Ankit Mehta. Methods used in this engagement are documented in the related guides below.

Related technical guides

Official sources