← Cloud projects

Cloud · Architecture Concept

Enterprise Landing Zone Principles

Design a cloud foundation that separates shared platform responsibilities from workload ownership while standardizing identity, networking, policy, logging, security, and cost controls.

PlatformCloud
DomainGovernance
LevelIntermediate
Last reviewed2026-09-19
Use whenCreate a repeatable foundation where application teams can deploy workloads without rebuilding governance and connectivity each time.
Key decisionPlatform and workloads have different lifecycles
Key conceptsOrganization hierarchy · Identity · Shared networking
Cost focusShared firewall/NAT services
On this page

Building blocks

Organization hierarchyIdentityShared networkingSecurity loggingPolicyFinOps

Design goal

Let workload teams deploy repeatedly without rebuilding governance and connectivity, while preserving enough autonomy for application teams to operate independently.

Success criteria

  • Separate platform and workload responsibilities
  • Centralize guardrails and logging
  • Standardize identity and connectivity
  • Enable controlled workload autonomy

Architecture

Establish platform-level shared services and governance, then place application environments into governed workload boundaries.

Architecture flow

  • Define organization/account/subscription hierarchy
  • Establish identity and privileged access
  • Deploy shared connectivity and DNS
  • Enable centralized security and logging
  • Apply policy and cost controls
  • Onboard workload environments
IdentityGovernanceConnectivitySecurity / LogsWorkload Zones
Identity
Governance
Connectivity
Security / Logs
Workload Zones

Architecture decisions

Decision

Platform and workloads have different lifecycles

Why

Shared identity, networking, policy, and logging should not be coupled to an individual application deployment.

Trade-off

Decoupling platform services from applications improves scale and ownership, but introduces formal interfaces, governance, and dependency management between teams.

Decision

Guardrails should enable teams

Why

A landing zone is most effective when policy prevents unsafe states while preserving delegated ownership for application teams.

Trade-off

Preventive controls reduce unsafe states, but overly restrictive policy can slow delivery unless exceptions and delegated ownership are designed deliberately.

Security

Protect the control and data paths deliberately. Centralize audit, identity guardrails, policy, and security monitoring while keeping workload teams accountable for application controls.

Cost drivers

  • Shared firewall/NAT services
  • Central log ingestion and retention
  • Connectivity
  • Security services
  • Non-production environment footprint

Design assumptions

  • Multiple workloads or teams will share the cloud platform
  • A central platform/governance function exists or is planned

Implementation plan

  1. Define the organization/account/subscription hierarchy around ownership, policy inheritance, environment boundaries, and lifecycle.
  2. Establish workforce identity, workload identity, privileged access, and break-glass procedures before delegating environments.
  3. Design shared connectivity, DNS, egress, and inspection as platform capabilities with clear interfaces to workload networks.
  4. Centralize audit, security, and operational telemetry where workload teams cannot silently remove required evidence.
  5. Apply guardrails, cost allocation, and environment provisioning consistently, then validate the model by onboarding a representative workload.

Validate the design

  • Confirm a new workload environment inherits the required policy, logging, identity, and cost-allocation controls without manual reconstruction.
  • Verify identity and privileged-access boundaries are documented and technically enforced.
  • Trace representative network and DNS paths and confirm they are deterministic and owned by the expected platform team.
  • Confirm central cost allocation can identify the workload owner and that shared-cost treatment is documented.

Architecture basis

Continue a learning path