Homepage » Amazon Web Services Solutions » Cloud Foundations
Cloud Foundations
Front page » Amazon Web Services Solutions » Cloud Foundations
Cloud Foundations
What does this solution do?
Amazon Web Services‘s Cloud Foundations whitepaper defines thirty capabilities required for a company's cloud environment. It covers six categories such as governance, risk management and compliance, operations, security, business continuity, finance, and infrastructure. It is a comprehensive improvement over the cloud adoption strategy of a company after the Landing Zone. The Cloud Foundations Quick Start Pack is a deployment tool for the infrastructures of the cloud environment built exactly as defined in the whitepaper. It aims to quickly deploy a cloud-ready environment including a basic landing zone, security baselines, and DevOps functions within two weeks, using cloud-native technologies and automation services. It will effectively assist you to deploy, operate and govern workloads on the cloud efficiently, and make them available for business production fast. You can continue building based on it and constantly enhance the capabilities of your cloud environment.
The Cloud Foundations Quick Start Pack provides two editions at present
Standard Edition | Lite Edition | |
Delivery mode | Amazon Web Services | Amazon Web Services and our partners |
Basic landing zone | Yes | Yes |
Security baselines | Yes | Yes |
Networking connectivity | Yes | Yes |
Backup configurations | Yes | Yes |
DevOps functions | Yes | Not available |
Advanced functions | Yes | Not available |
Solution Advantages
Fast delivery
Enhanced security
Simplified work
Solution Overview
Below presented are the architecture and the web portal of Service Workbench.
About the architecture diagram
- Management Account: It includes an Amazon Organizations organization or a virtual organization and necessary Amazon Identity and Access Management (Amazon IAM) functional roles.
- Infrastructure Account: It centrally manages Amazon Systems Manager parameter store, Amazon Simple Notification Service (Amazon SNS) topics, Amazon CodePipeline pipelines, Amazon CodeBuild projects and Amazon CodeCommit repositories. It includes Amazon Step Functions deploy and destroy state machines, the Amazon Service Catalog Account Factory, Pipeline Factory and Repository Factory products, to implement infrastructure-as-code automation.
- Security Account: It centrally manages Amazon Key Management Service (Amazon KMS) customer keys. It includes alternative solutions to Service Control Policies and Tag Policies for Amazon Web Service China Regions. It provides the security enhancements based on Amazon GuardDuty and Amazon Security Hub. It integrates the latest KeyCloak to provide user federation based on Amazon Fargate. It provides user interface backend based on Amazon AppSync.
- Logs Account: It centrally manages Amazon Simple Storage Service (Amazon S3) buckets for logs from Amazon CloudTrail, Amazon Config, Amazon GuardDuty, Amazon Virtual Private Cloud (Amazon VPC) flow and elastic load balancing logs. It includes an Amazon OpenSearch Services domain to search and show logs. It includes an Amazon CloudFront distribution for user interface frontend.
- Network Account: It centrally manages Amazon VPCs and their related resources, such as subnets, security groups, route tables, interface endpoints, Internet gateways, NAT gateways, Amazon Transit Gateways and Amazon Route 53 private hosted zones. It securely provides private connections based on Amazon PrivateLink. It provides holistical planning and one-click deployment of networking connectivity based on transit gateway.
- Member Accounts: They are bootstrapped and configured based on the best practices recommended by Amazon Web Services.
- Other Regions: It deploys and governs other Amazon Web Services Regions. It provides cross-regional networking connectivity based on transit gateway peering connection.
Browse our portfolio of Amazon Web Services -built solutions to common architectural problems.
Find Amazon Web Services certified consulting and technology partners to help you get started.