AWS cloud architecture consulting
AWS landing-zone advice copied from another provider misses Organizations SCPs, Transit Gateway route tables and Cost and Usage Report allocation. This engagement stays on AWS primitives.
Who this engagement is for
Teams whose production control plane is AWS and who need landing-zone, networking, IAM or cost-allocation decisions written against AWS documentation.
Information required to begin
- Organization structure and whether Control Tower is in use
- IAM Identity Center or IAM federation model
- VPC and Transit Gateway diagrams
- Regions that hold production data
Engineering process
- Consultation scoped to AWS accounts and regions
- Review against current AWS documentation for the services you run
- Written ADRs and a risk register in AWS terminology
Deliverables
- Current-state assessment in AWS terms
- Target architecture and ADRs
- Risk register
Provider-specific scope
- AWS Organizations, Control Tower, IAM, IAM Identity Center
- VPC, Transit Gateway, PrivateLink, NAT Gateway, Route 53
- Cost Explorer, Cost and Usage Report, Savings Plans and Reserved Instances as documented
Limitations
- We do not replace AWS Support.
- Recommendations cite AWS docs current as of the review date. Service names change.
What is not included
- Azure, Google Cloud or Alibaba Cloud design except as a documented dependency
Author
Written by Ankit Mehta. Methods used in this engagement are documented in the related guides below.