Building blocks
Design goal
Let workload teams deploy repeatedly without rebuilding governance and connectivity, while preserving enough autonomy for application teams to operate independently.
Success criteria
- Separate platform and workload responsibilities
- Centralize guardrails and logging
- Standardize identity and connectivity
- Enable controlled workload autonomy
Architecture
Establish platform-level shared services and governance, then place application environments into governed workload boundaries.
Architecture flow
- Define organization/account/subscription hierarchy
- Establish identity and privileged access
- Deploy shared connectivity and DNS
- Enable centralized security and logging
- Apply policy and cost controls
- Onboard workload environments
Architecture decisions
Platform and workloads have different lifecycles
WhyShared identity, networking, policy, and logging should not be coupled to an individual application deployment.
Trade-offDecoupling platform services from applications improves scale and ownership, but introduces formal interfaces, governance, and dependency management between teams.
Guardrails should enable teams
WhyA landing zone is most effective when policy prevents unsafe states while preserving delegated ownership for application teams.
Trade-offPreventive controls reduce unsafe states, but overly restrictive policy can slow delivery unless exceptions and delegated ownership are designed deliberately.
Security
Protect the control and data paths deliberately. Centralize audit, identity guardrails, policy, and security monitoring while keeping workload teams accountable for application controls.
Cost drivers
- Shared firewall/NAT services
- Central log ingestion and retention
- Connectivity
- Security services
- Non-production environment footprint
Design assumptions
- Multiple workloads or teams will share the cloud platform
- A central platform/governance function exists or is planned
Implementation plan
- Define the organization/account/subscription hierarchy around ownership, policy inheritance, environment boundaries, and lifecycle.
- Establish workforce identity, workload identity, privileged access, and break-glass procedures before delegating environments.
- Design shared connectivity, DNS, egress, and inspection as platform capabilities with clear interfaces to workload networks.
- Centralize audit, security, and operational telemetry where workload teams cannot silently remove required evidence.
- Apply guardrails, cost allocation, and environment provisioning consistently, then validate the model by onboarding a representative workload.
Validate the design
- Confirm a new workload environment inherits the required policy, logging, identity, and cost-allocation controls without manual reconstruction.
- Verify identity and privileged-access boundaries are documented and technically enforced.
- Trace representative network and DNS paths and confirm they are deterministic and owned by the expected platform team.
- Confirm central cost allocation can identify the workload owner and that shared-cost treatment is documented.