About this talk
This talk explores the concept of a landing zone in the cloud, comparing it to the operations of an airport. The speaker explains that a landing zone is a structured area on cloud platforms where resources are deployed, ensuring compliance and operational efficiency 24/7. Key components of a successful landing zone include multi-account segregation, architecture patterns, baseline governance, and automation. The speaker highlights the importance of establishing a solid governance framework to prevent chaos when multiple teams are managing their resources. Additionally, he discusses best practices for managing networks, security, and user identity while ensuring continuous monitoring and audit capabilities. Throughout the session, he emphasizes that creating a landing zone is a complex process that requires careful planning and the use of proper patterns to support scalability and disaster recovery.
Full transcript
[Music] ladies and Gentlemen please welcome our next speaker Rafael aaro follow presenting the topic the automation of a landing Zone a landing Zone and before starting I would like to ask you if you can raise your have I have a small audience but how many of you are aware of what is a Zone cool awesome so what is a landing Zone I I like to uh use
the Amazonian way of explaining this concept so first of all it's what is the the problem that we're trying to solve and I like to make the example of running an airport so if you if you think about it let's say that you are the manager of an airport and you are in charge of taking care of everything so when you when you manage an airport first
of all you need to be sure that the airport it's it's operating 365 days a year 24/7 because you can get passenger and and flights every time of the day and then you have to manage few activities of the airport so one of them is you have to manage the traffic flow so you have airplane leaving airplane coming you have delays and you need to ensure that
you know the the traffic of this airplane is always move then you have passport control and when you deal with passport control you have to deal with regulation so in reality every country has different regulation and your airport need to be aware of all the immigration law because you have people coming from all over then you have to deal with the scheduling because the passenger walk across
your airport and they need to be aware at any point in time of what is going on in the air airport where is my gate where is my airplane is it my airplane delay when I can drop my baggage then you have to manage the passenger so passenger need to stay in the airport they need to find food they need bathrooms they need to find a place
where they can sit and wait for the airplane you have to manage baggage claim which is quite complex because you will have all the baggage coming it's automated you have different Gates where you can deliver the baggage to to the passer passenger and then you have the security control so in the security control you need to check the passenger and not carry over anything that is dangerous
or harmful now you may say okay what's what's the point of this of managing an airport with a landing Zone then if we look at what is a landing Zone in reality it's like an airport so the landing Zone at is an area on the cloud where you want to deploy your re resources and that you want to be compliant that has to run 365 days a
year 24/7 and you need to manage certain activities so it is not an airport it's an IT product so the activities are different but for example you have multiac account segregation which is in my opinion a fundamental concept of cloud so multi account account if you are on AWS if for example you are on on ASO you would call a multi subscription segregation you have to create
architecture patterns and especially if you are in the area of devops you don't want that every team comes in and reinvent the vehicle so if you have a like virtual machine with a load balancer you want to ensure that that partn is carry over every time a team want to migrate into the cloud so you need to create upfront all those architecture patterns and you want to
distribute them across the company you will have share service when I talk about share service for example we can talk about authentication so in in in an authentication share service maybe you use already in your company a product called OCTA or active directory or any other and all those share service need to be configured in a way that when a team or a company approach your Landing
Zone they know already how to consume the share service what is going to be the implication of it how much is going to cost and similar aspects then you want to have a baseline for governance so the Baseline is actually if you think about the Ws when you when you come in as a as a devops engineer or a developer you will go into aws.com create an
account give the credit card and you get one single account but when you are a company it it's bit more complex so you go in and then we give you a cap of 3,000 account so your devops team can actually spin AWS account as much as they want but you want to create a baseline because what you want to be sure is that every account comply to
the same rule for example what virtual machine can I create what is the size of the virtual machine which region can I use which region I cannot use and so on because you want to control you want to put guard rail to ensure that that your Landing Zone doesn't become full Anarchy so you need a Baseline and and the Baseline is also something that you want to
keep up to date and that you want to push also to existing account because maybe the policy in your company change or you realize that you're spending too much so you want to reduce the amount of service or Hardware that you want to allow to be used in the company then you want to be automation driven which is overall the concept of this conference right we don't
want to click any thing we want the the development team deploy their code and it's all fully automated it is compliant it is reliable uh but the issue is that automating a landing Zone it it's a different story it's it's way more complex but that's the key actually to accelerate and then you want to be repeatable and reliable so um a landing Zone it's deploy let's say
in a region but there's no guarantee that staying uh alive the region you may have a disaster recovery situation so at that point maybe you have in your company an SLA of four hours and within four hours you need to ensure that the entire Landing zone so all those um I think I have a pointer so all those aspect that we talk about like uh the multi
account the patterns the share service the Baseline and and governance it's repeatable in another Landing Zone because you want to be Disaster Recovery compliant and all of that has to be automated so going back to the beginning this is our airport and now we are in charge of building the landing Zone and now I I don't know your your specific job road but as an AWS solution
architect I see two kind of um devops engineer let me put it this way uh one is I work for a consulting company I'm engaged with a big customer and with my company we build a landing zone for this customer or I work in a financial company which is the customer that I have and we have an internal team and we decide to move to AWS so
we want to build the landing zone so these are two different way of approaching the Zone internally if you a company internally you decided to build it for sure you need support from somebody outside because for you it's the first time so a lot of mistake can be made if I am a consulting company I only be landing zone so that's my job I know how to
do it but the difficult is to go to the customer and explain that their vision of the landing zone is not in reality what it's supposed to be so then at this point I want to show you a bit what is the the the workflow that that I see at customers uh so how you are supposed to approach a landing zone now for this speech I will
start from zero let's assume that you have a very big company you are on premise so you don't have a landing Zone and we start the conversation of building the landing zone so this is overall the approach that we we use in Amazon so normally when I get in contact with a customer we always start with the question what problem are you trying to solve because if
you don't have a problem I'm not going to generate a problem for you so that my solution can be can be sold right so what is the problem and and and this is starting from here so the business need now uh I had this conversation few times what what's the reason of company moving to Cloud primary reason is cost Saving right there is no other reason a
company that is not an IT company will not move to Cloud because they want to go serverless because they want to use jni because they want to use uh no SQL database or you name it or micros service micr frontend they don't care this they want to move to Cloud because they have been told that they can save money so that's the that's the business need uh
now without the business need you don't have a sponsor so I think you hear me yeah so without the sponsor the problem is that here you don't have the beautiful money that you internal it or consulting company you need in order to move through this workflow so it's extremely important that you first tailor the business need you don't have to spend months in waterful uh requirement analysis
of what do we need but what is important when you approach the creation of a landing zone is that you have a solid sponsor in the company or at the customer The Envision with you the creation of this because this is a very painful Journey it's not easy and you will fail through the creation of a landing Zone because it's it's not simple and it's important that
you have someone strong on the business side that keep supporting you financially but also emotionally because you're going to you're going to be criticized for this when you have the business need let's say that we are successful in this part then there are five different steps that we envision in the creation of the landing Zone but when you're here we we we are not any more waterfall
we are a GI so we reiterate so the first part is the account the first decision that you have to make when uh you create a landing zone is how many accounts how do we use the account what we do do we create one account multiple environment do we create an account per environment do we create an account per company business unit and inside there a bunch
of VPC how we do that there is no a right solution in in my personal opinion it depends it depends on the company it depends on the budget it depends on the policy and regulation that you have in the company and and that's the first part and this part it's it's like what we call in Amazon a oneway door decision there is a book that is called
working backward which explain you how Jeff basos created Amazon and Jeff Bezos has two kind of decision one is called one oneway door decision so I open the door I made my decision I closed the door it's over I cannot open that door anymore there is no way because if I change that decision I'm going to have a s cost so all the money that I invest
to make the decision it's gone and then you have other decision that is called two-way door decision so it's a door that I can open I made the decision I made a mistake then I can step back and say Hey you know let's try different way so when you create a landing Zone you need to think about a large organization I have organization that have like four
or 5,000 accounts each account it's one or more applications so when you set the Baseline of the landing Zone you cannot say later hey you know what we think that maybe we remove internet access from the subnet because maybe you have three 400 application that they're using it so there are certain decision on the landing Zone and I think the account is the fundamental one where you
really need to sit down with the with the IT team of the company and try to understand how you want to structure the account because if you design it wrong you can change it but it's going to be painful and longer you wait more painful it is then we have the networking part so when you approach the network is not just about the VPC and the the
the amount of Ip that you want to have in a VPC that that's the easy part but you have some core service for example what firewall do you want to use do you have a firewall for each VPC do you allow traffic between VPC do you want to inspect the packages between VPC is it required by your company do you allow connection then you have direct connect
so the VPN because you move to Cloud but you have already something right maybe a different cloud provider maybe on Prem is not a a green field company that you so how do you connect to your existing instance you you want to connect with direct connect you want to have a VPN you go straight to public internet connection you expose all your database or your server I
saw that not a very good decision domains DNS how do you manage that today do you have a DNS server do you have a domain provider that also issue your TLS certificate what you want to do there you want to keep it you want to do it on your own do you have a team that is skilled about it that know how to do it and then
that would be the network then we jump into security so the first aspect of security is like more than configuring it it's it's tailoring security around guard rail so image I'm talking about hardening so if you think about Docker if you think about virtual machine you pull down an operating system but that operating system you pull it down from the marketplace so we are just giving you
the latest version of uh Alpine we don't check what's in there because it's not our job we you ask me for a product I give you the product but then are you sure that that version of Alpine is compliant with the security regulation of your company how do you manage that that Alpine version as always the latest patches if it doesn't what happen in the company because
maybe you have a bunch of Docker now outside running in production but that version of the operating system now is not compliant anymore so how do you enforce in the landing Zone that when because the dev team I'm I'm also developer so I'm not you know talking bad about developers but the developer itself it will never worry about um let me create a new Docker for the
microservice but let me ensure that I pull the Alpine version that is compliant because risk and compliance created a Confluence page with those version of of Alpine and I need to be diligent they don't do that they do mpm install and whatever come from internet they just install it because it works so you need to configure that part config so AWS config allow you to ensure that
nobody change anything let's say in the company we use terraform so inside terraform I allow you to choose only certain size of of the ec2 of the virtual machine but I have a devops engineer that somehow got a role where he's allowed to go into the account and change the ec2 how do I see that happening can can I block that because I don't want that happening
so you need to configure config in a way that is going to be your policeman so you want to have a policeman on the landing Zone that keep checking everything to ensure that we don't have you know someone smarter than us that they go there there and and move away so drift away from the configuration that we want to enforce and then logging this it in the
cloud of course it you have to be careful because Cloud watch is very powerful but very expensive but you need it because it's not your on Prem server the only way that you have to understand what is going on on on any cloud provider is through the log if you don't have the log it's game over it's too late when you real realiz that something happen and
the business come to you devops engineer or system integrator shouting say hey this thing is in production it's not working what is going on and you open the log and the log is empty because you say you know let me be wise let me put a log on error so if there is no error I don't trace anything and then it's game over because if we don't
have a time machine you cannot go back and say hey can you generate the log of yesterday because I had some Incident That's about security then identity so this is the most painful part so identity means who can do what we have access we have identities and we Federation there is no one company that approach Cloud that doesn't have all of them already in place now are
we going to a company and say Hey you have 50,000 employee but they are on is your active directory now you're moving to a w sorry you have to recreate all the identity you have to resettled the password you have to do something no you don't do that right so you need to find a way to Federate your existing identity management and you want to make it
in a way that the employee they use the cloud service doesn't even see it happening for them nothing change you have to manage the identity and the access so you want to create Persona who are you I am a devops engineer I am an employee I'm a data scientist and based on that you want to authenticate the person and Grant certain Privileges and you want that had
happen on Prem on AWS on aure on Google cloud and has to be smooth right they don't have to go through the pain on entering a password they don't have to go through the pain of saying well I can query a database on AIA on AWS I cannot because the person are different so this is what you want to design when you create a landing Zone and
then user so user here is who is the user I am a devops engineer who is my user my user is a developer of the company the SP a service is an application team that deployed the application is another devops engineer but not the one that working the core team like me so not the one that build the landing Zone but the one that is coming in
and you need to create certain service for that application so those are my users and my user are consumer so now I became a service provider because I provide a landing Zone with service in it so you want to create a service catalog you want to have Automation and you want to have end user iteration because in in interaction sorry because what you don't want is to
have your slack teams whatever chat tool you use keep popping because they will bother you right hey how I do this hey how it works this how can I create a VM I create a VM doesn't work the terraform module that you made is buggy you don't want that so you need to create you have to become within the company a service provider then you finish you're
done you lose your job because the landing zone is ready no what happen is at this point in time you need to migrate and good luck because this is the difficult part because now you create a perfect Landing Zone but you need to migrate a company that is using Windows 2000 and windows 2000 doesn't exist on cloud anymore but they use it it works and they're telling
you hey look on Prem it works doesn't bother me I don't want upgrade I don't want to pay license I don't want to change my code oh they have a version version of Linux that AWS doesn't even have the marketplace but they use it it works so this part then you have to iterate because you realize that your Perfect Design when you start to have 50,000 users
and th000 application and 2,000 AWS account and 3,000 VPC it's completely unmanageable so what you do you start from the beginning and you reiterate all this design so you need to be sure that this design it was open from change from day one because you will have to go back a certain point in time and rethink what you have done and maybe need to adjust it and
then you have to operate and you have to optimize because after a year you receive your $2 million bill the CFO come to you and say hey RF now your kpi is reduce of 10% Cloud consumption you're say how come I have to migrate more apps I have to reduce 10% but you have to do it actually the workflow and let me check the time so now
I will touch each point of the workflow I think I touch it already but just to give give you a better overview so let's start with the account here it's a bit like say what is better Java or net and not going to go there so what kind of strategy do do you want to use uh I mean there are many I will not tell you what
it's better because I have this L on the T-shirt so I have to be careful when I speak I tell you what I think so rough what he think based on his experience and I saw that the most successful customer is the one that is more granular so you need to be aware of a beautiful problem called blast radius it's real it happens so if you create
for every application an account for every environment what happen is the blast radius will never be larger than one application one environment on term of cost it will not cost you more because AWS doesn't charge you for the amount of AWS account that you create as far as the account is empty you pay nothing but the management of it the complexity it's bigger but that's the way
I see it now how can you ensure that the account is properly structured these things here this one doesn't have time machine so be verbos create the tags tag everything C Center application owner application name application ID if you have an application catalog in the company environment name you name it when you have tagging done properly you can create really beautiful reports that really drill down because
when you have three 4,000 application running and you get a bill of 2 million the CFO say okay can you tell me which one overspending and if you don't break down every single service with the tagging there is no other way that you can find out that believe me there is no way so tagging fundamental AWS organization if you are familiar with organization it's something that you
need to use right except you have three AWS account you need an organization and what it does the organization allow you to orchestrate many accounts you can create organizational unit you can push down policy and security controls so that you can have a sort of cascading governance and your WS organization is also beautiful because you can grab a bunch of AWS account from one organizational unit you
can enforce new security controls you put all of them in the new organizational unit and you enforce a new Baseline account strategy we I talk extensively it's important you will debate be ready have backbone that's what we say in Amazon so show that you are an expert on Landing Zone you have the backbone to prove that you're right because this is something that you will debate very
heavily isolation blast radius they these two work together careful because it happened not because you did something wrong but because you gave an AWS account to a junior developer that when he realized that there was Internet it's been uneasy to and start to use Facebook on the ec2 machine because it was not allowed on the laptop I saw these things happening right I saw it so careful
here centralized logging you need it it's the only way to understand what is going on x-ray and log if you don't have that you have nothing else to understand what happening and billing visibility so billing without tagging you just get one total 2 million now good luck if you have t you can say well uh we have a company distribute across east of Europe so I saw
that 700k it's Lithuania 300K is ltia and a thousand uh sorry a million is actually our PO office and now I can break down further I can tell you that in Poland 300K is HR and 400k is another office so now in this way you give a tool to the CFO to cross charge Cloud consumption and you can can do that with tagging and visibility next one
is an example so uh I need to accelerate a bit uh so this is actually when you create with control tower a beginning Landing Zone and the idea overall is you want to have an account where you do management so nobody has access except the mega powerful devops engineer they manage what is called the core team and then you want to create sandboxes or you where you
provision the account to the application team and they can only stay here and then you want to have an audit account where you have your Baseline your security notification all the config and then you want to have a log archive account where you probably want to dump inside a glacier S3 bucket all the logs for audit reason and things similar like that so like this is just
an example right very basic then next we go to the network uh I mean here I would try to be a bit faster so we talked before about it what I think it's very important here is Access Control list and security control and Security Group sorry they are firewall so let's be the if AWS give you an ec2 that by default you cannot access because there is
no traffic open is not because we are lazy it's because there is a reason behind so putting like 00000000 Star this kind of pattern because you don't want to think it's it's not a good way so when you design a landing Zone what what's your role Your Role is to create pattern that by default up team have zero access and then they need to challenge themselves and
try to understand okay what kind of access I need for example by default having Port 0 open or RDP protocol open or SSH open is not a good practice because you don't know how it's going to be used uh loging G monitor we talk about VPN Direct Connect I mean here we can spend hours about it my question is how much money you want to spend let's
let's go down to the bottom of it right do you want 10 gigabyte direct connect to your own Prem can you afford that financially because that's that's the only thing this one here it's where you will cry so here is get it this wrong and game over because if you work on AWS you know when you create a VPC you cannot extend and the cidr right it's
written in stone it's like mosa you get it that's it you can create a new one on top of it you have to connect them you can create another VPC in the account you can do VPC peing but you have erass you're going to pay for it subnet no overlapping IP these two go together and you know if you do the a associate and say Pro certification
on AWS we bombard you with this because there is a reason behind right so this is very important and this is where you actually want to give reasoning don't be uh what I call like I cannot use any non-inclusive words so let me think about something polite uh you know don't don't be a dictator uh give the space to the team to choose so in your terraform
if you use terraform give options like a small VPC a medium VPC a large VPC so that the team can choose between 12 40 100 IP range but give the the opportunity I saw company providing VPC with 8 IP and I'm like I mean what is going to happen there 2vm game over so try to think about it when you when you provide the the network configuration
so a bit of flexibility but not too much and always zero thrust so then here an example what is going to be a network design on a landing Zone it could be I have my own Prem then I have a customer Gateway so you have already some sort of uh VPN provider then you're going to have a direct connect and then the direct connect on a WS
is going to go through for example this is one way a Transit gway and then each VPC can you know contain the blast radius but through the Gateway they can go back forward to the VPN because in reality remember your your EMP employee is going to have the laptop running here and if you create an application here by default we assume that this is visible internally right
so this is kind of the design that you need to foresee that you have to document so that when someone approach your Landing Zone you say hey look this is how how it works right and then in this case it's it's you have maybe another organization because you also run VMware and maybe you don't even run it on a w as you run it somewhere else right
so you need to kind of think then next one is uh security and uh security I mean uh here you know the the conversation can go through authentication authorization Federation there are different aspect right uh what I think it's important is first of all a bit of marketing so guard Duty For Thread detection you have different version of it if one it's free I mean when something
it's free I'm Italian right just take it it it's free you don't pay for it just use it right there is no point it's there it's a bit like when you go to the opero if they give us some food is on the table I eat it even if I'm not hungry because it's I mean it's been given to me as a gift right I'm not unpolite
so guard D it use it Cloud watch alarm Cloud watch alarm have action so I give you an example I had a customer that had a budget limit of 1,000 and they put the alarm and the alarm was saying hey when it's 800 go nuke because I cannot spend more and they got a bill with a zero more than 1,000 and then they you know they were
blaming and I say can you show me your alarm and the alarm had the action table if you are familiar with it it was empty so I say look it's like you put um an um an alarm in your house a thief came in break the glass the alarm activated but you forgot to plug the the the Bell right the siren so the alarm did nothing so
the the alarm itself it's it's useless if what the action so if something happen if I have something happening based on a rule on cloudwatch but then what do I kill the VM do I kill the service do I send an email do I create a service now ticket uh do I send an SMS to the C of the company whatever like do something here uh Cloud
trade lock I think I I mentioned that this is your tool VPC flow lock you want to have it right because you're going to have this beautiful call where somebody that doesn't really have your skills will spin something and say hey you know what your Landing zone is crap because I spin this service and now from my MacBook I can't see it and maybe they without maybe
they probably did something wrong and then you need the VPC flow log and and you need also additional uh x-ray log to understand the traffic how it's going and tell them where the traffic is block Ami Factory for Harden OS so this is very specific to financial companies so it's my sector or to Pharma or to other company they are highly regulated so what you need to
do is you have to create a repository of os image so that when someone create a new virtual machine a new ec2 they pull an image that at that point in time is compliant not that was patched three months ago and as soon as they spin they have to do uh an update on Linux or run Windows update on Windows that's just useless it's pointless there is
no reason to do that so you have to keep this up to date constantly and then you need to figure out but how I'm going to push this to things that I have in production for a year because that OS now is in production and it's it's it's it's not okay it's not patch and the team doesn't want to patch because they never have time so you
need to find way to push that uh for example with patching window so you don't give them an option to negotiate it's like the third weekend of the month we do patching window we take down everything patch it and turn it on and then AWS config rules for compliance so I explained you this before it's like you know in my company I don't want to use a
red hat because we don't want to pay the license I don't want to use spin RDS Oracle because we don't have a commercial deal with Oracle and you put me in trouble if you do that so all these kind of rules that you want to be sure that are match not that someone override it and and create troubles for company uh then let's look for a moment
on identity I keep looking here because I have the the timer running uh so just just a second I get like it tell me that I'm 35 minutes is that correct or I I have more eight only okay all right so uh identity here so what happened is this is actually a student res it's a university and they have already all this in on Prem so when
they approach a WS and they want to migrate logically I'm not going to propose them to use identity Center on AWS migrate all the all the students accounts they want to leverage all of this and they want to Federate their Persona their roles into AWS right so this is what you have to figure out when you're going to touch the identity part and then the consumption model
so you reach a point now where all these things that we talk about you become a service provider so how you're going to enable a consumption model and the consumption model is actually the application team come com they want to create to Apache server a load balancer they want to go public internet with that application and they want to do it within an hour so with the
service catalog you can generate terraform and cloud formation patterns that they can just pull push the button deploy and you have hardened patterns that you can give to application team to easily deploy your application this require a lot of investment in terms of time but believe me is an extreme accelerator I have customer now that they have massive migration so they immigrate thousands of platforms and when
they have this done it took them a year to build it properly but then every day they push out one out because it's always the same story right take the package create the servers push it go live so this is a very good uh investment in AWS service catalog and then this is going to be an example of service catalog so you see now you became a
service provider with in AWS so in AWS you're going to create your catalog of pattern infrastructure patterns and then you're going to deliver them through cicd in this case I use cloud formation you can use terraform or anything else and then the catalog will provide different pattern for example you want to go server L you want to go micros service B containers you want to go end
tier standard and then those are the way that you can for example structure your service catalog and they can pull things out of it and spin it and then you know they always spin it in the way that you're comfortable so that would be the final picture you've been successful you created a landing zone so you have a bunch of account that you use to control and
to track information for audit and then you segregate the account of an application for example by environment So Pro Dev and uat challenge so design decision you will do a lot of them don't be scared you will make mistake I make mistakes just take it don't take it personal you are human you will make mistake you will build experience you build experience by making mistake so accept
it document everything that makes sense ISO company with 30,000 pages of Confluence with copy paste of terraform module nobody will ever read that things ever and you spend a year so wasted time Cloud role Persona so aam role policy create Persona so look at your company what do you have in a company you have an employee you have a developer a devops engineer a data scientist so
create those Persona and assign permission on the Persona and when the company evolve what you do you simply evolve the Persona that you have with the permission that are required it's a lot easier to manage because then you point the finger say heyy you are a data scientist why you want to be able to raise ticket on a WS console that's not your role that's a devops
engineer yeah and then creation of a baseline so the Baseline it's it's fundamental because with the Baseline you are saying when I create an account I have certain firewall rules I have certain rules on the VPC and many other service when you have a baseline it's a bit like you know the the the main branch that you have when you write code so the Baseline is date
and you want to find a way there are multiple way to do that you want to find a way to push the Baseline on all the existing things that you have in production because you want to be sure that at any point in time you get a noed and your Landing zone is fully compliant and then I say of course automation so we talk about it there
is a product called control Tower which I think most of you if you work on a WS if you know Landing Zone you know this but control tower it's Mega powerful is really good but I work with cloud formation so I'm a telepone dude how can I do that so I wrote a blog post about it on AWS you can see it through my LinkedIn profile in
reality company today use control tower account Factory for terraform it's really beautiful if you know terraform if you work with Landing Zone suggest you to have a look it's a very nice prod and what you can do you can actually fully automate a landing Zone and this is the real Dr so here you are Disaster Recovery compliant you can spin in 10 minutes a new Landing Zone
and you would make the the risk team of the company very happy uh give it a look I mean is a nice product I don't get any money from terraform I just think it's a very valid solution and then I think I have time for questions I test test thank you for your talk let's go directly to couple of slider questions that we have and then I'll
ask the people here around if there are any questions more so what mistakes companies do most when designing or using a landing Zone all right so I think that the the mistakes that they do most is they take for granted so again as I say at the beginning you are a devops engineer but that doesn't imply that you know what the customer wants so use the Amazonian
way it's like what problem are you trying to solve so most of the company the mistake that they make is they invent service that nobody need I see company spending months on service like beanock and realize later that nobody want to use Bean stalk so why you spend time on it so use the approach the other way around so that's the the mistake that I always see
is that they invent patterns on the landing Zone that nobody ask for that's very common okay and the second question when you are creating the landing zone for a company does the company later take over and manage it or AWS manages it we don't create it so I am a solution arched so what happen is when you are a customer I am a free resource I will
never send you an invoice so I come with your team and I try to help you by sharing knowledge normally there are two patterns one is the company create the landing Zone themselves or the company leverage a consulting company uh I cannot mention any name you know guys right uh so normally yes what happened is you have the first year the consulting company create the landing Zone
and then you see the transition where the company internally acquired the knowledge and take over uh it depends there are million way to do it uh you need people right if you want to take it over not to devops engineer for sure thank you do we have questions in hall I know it's early no okay you still have a opportunity to catch rough outside and ask him
more questions and this is my email so I always answer so feel free to write me an email if you have question Okay so Round of Applause for our speaker thank you
More from this event
See all 58 talks →
Halil Ibrahim Kalkan: Building a Kubernetes Integrated Local Development Environment
45:20
Paco Orozco: Growing at the Edge: Doubling Traffic While Changing the API Gateway
45:03
Viktor Vedmich: Ideal Blueprint Versus Reality for CI/CD Pipelines
46:03
Koray Oksay: Continuous Deployment: The GitOps, The Pipelines, and The Ugly
43:03