flowchart TB
root["Organisation Root<br/><i>policy: deny unapproved regions</i>"]
subgraph plat["Platform"]
direction TB
ident["Identity<br/><i>directory, privileged access</i>"]
conn["Connectivity<br/><i>hub VNet/VPC, firewall, DNS, VPN</i>"]
mgmt["Management<br/><i>logs, backup, monitoring</i>"]
end
subgraph land["Landing Zones"]
direction TB
subgraph corp["Corporate"]
p1["Prod A<br/><i>spoke</i>"]
n1["Non-Prod A<br/><i>spoke</i>"]
end
subgraph online["Internet-Facing"]
p2["Prod B<br/><i>spoke</i>"]
n2["Non-Prod B<br/><i>spoke</i>"]
end
end
sandbox["Sandbox<br/><i>spend cap, no connectivity, auto-expire</i>"]
decom["Decommissioned<br/><i>deny all</i>"]
root --> plat
root --> land
root --> sandbox
root --> decom
conn --- p1
conn --- n1
conn --- p2
conn --- n2
mgmt -.->|"diagnostics forwarded"| land
ident -.->|"roles and groups"| land
Deployment & Infrastructure View
Cloud Landing Zone Diagram
The account, network, identity and policy scaffolding every future workload will be dropped into, drawn before the first workload exists.
Landing Zones
Design