Terraform Module for AWS Landing Zone
-
Updated
Feb 20, 2020 - HCL
Terraform Module for AWS Landing Zone
AWS Landing Zone Template v2.4.6(Latest)
This is the public roadmap for the custom-built AWS CDK Landing Zone solution provided by Towards the Cloud.
Leverage Ollion's AWS Landing Zone to deploy a secure, compliant foundation with ease. The repository contains an implementation of a secure and compliant landing zone pattern that will help expedite cloud migration for an enterprise in a heavily regulated industry.
Terraform Module for AWS Landing Zone (Read-Only)
Terraform blueprint for AWS Organizations, multi-account landing zones, SCPs, IAM Identity Center, and secure AWS cloud foundations.
Multi-cloud observability platform implementation guide — OpenTelemetry, New Relic, Amazon Bedrock AI, EKS/GKE/AKS
Example GDPR/EUCS/NIS2 AWS enterprise landing zone built with Compiled AI by Merlin Studio — one intent spec deterministically compiled to two IaC formats (AWS LZA + AWS CDK/TypeScript). Multi-region EU data residency, HSM-backed KMS, centralized egress inspection, Direct Connect, 100/100 (A+) security scorecard. A reference, not a turnkey deploy.
Example CIS-aligned AWS startup landing zone built with Compiled AI by Merlin Studio — one intent spec deterministically compiled to two IaC formats (AWS LZA + Terraform tfvars). Lean single-region baseline: org + security/log/audit accounts, GitHub Actions OIDC, 100/100 (A+) security scorecard. A reference, not a turnkey deploy.
Example FedRAMP High + NIST 800-53 AWS landing zone built with Compiled AI by Merlin Studio — a US federal civilian agency mission system, one intent spec deterministically compiled to AWS LZA config. SCP-isolated CUI account, multi-region warm-standby DR, HSM-backed KMS, 100/100 (A+) security scorecard. A reference, not a turnkey deploy.
PCI-DSS/SOX/CIS AWS multi-account landing zone built with Compiled AI by Merlin Studio - a regional bank's card platform compiled from one intent spec to OpenTofu + tfvars. SCP-isolated PCI cardholder-data (CDE) account, multi-region warm-standby DR, centralized inspected egress, 97/100 (A+) security scorecard. A reference, not a turnkey deploy
A sample of AWS landing zone for Nutanix Cloud Cluster (NC2) with Site-to-Site VPN
An example of configuration of Cloudformation nested applications deploying resources globally used and shared by AWS services and applications.
Example HIPAA/CIS/SOC2 AWS multi-account landing zone built with Compiled AI by Merlin Studio — one intent spec deterministically compiled to two IaC formats (AWS LZA + OpenTofu). Dedicated SCP-isolated PHI account, multi-region warm-standby DR, immutable audit logging, 100/100 (A+) security scorecard. A reference, not a turnkey deploy.
🛡️ Production-grade, DORA-compliant AWS Landing Zone blueprint featuring a native Go Maker-Checker (Four-Eyes) validation engine and immutable WORM audit log storage.
AWS Foundation - configures "one-per-account" type stuff - Organization, OUs, MemberAccounts, IdentityCenter, IPAM
AWS Organization bootstrapper: SCPs, SSO, GuardDuty, Security Hub, account vending — all Terraform
Add a description, image, and links to the aws-landing-zone topic page so that developers can more easily learn about it.
To associate your repository with the aws-landing-zone topic, visit your repo's landing page and select "manage topics."