Sorry, currently no German translation is available for this blog post

Intro

The following blog post provides an overview of the ACAI reference architecture for an AWS Landing Zone.

Do you want to see an AWS Landing Zone that is enterprise-approved, scaleable and secure? Do you want to see this live and in action.

Whether you use Amazon Control Tower or maintain your AWS Landing Zone with IaC tools like Terraform, this lab might inspire you.

ACAI AWS Solutions

You will see the following modular ACAI assets woven together:

Link to ACAI Solutions Presentation

ACAI AWS Lab Overview

The IaC CI/CD part of the AWS AWS Lab is hosted in Azure DevOps: link

There you will find the pipeline-repos and pipelines and the Lab Settings .

CICD Pipeline Overview
AWS AccountAccount NameAccount IDAWS Service
Org Mgmtacai_aws-lab1_org-mgmt590183804009- Organization
- SCP
- Identity Center
Core SSOacai_aws-lab1_core-sso761018859750- Identity Center
Core Security Toolingacai_aws-lab1_core-security-tooling975050251880- Security Hub
- AWS Config
- ACAI ACF Account Cache
- ACAI SEMPER Enriched
- ACAI SEMPER Operations
Core Log Archiveacai_aws-lab1_core-log-archive058264189027- S3 Buckets
Core Baseliningacai_aws-lab1_core-baselining891376920850- ACAI PROVISIO

ACAI Lab AWS Accounts Meta-Data

Connect to the Lab

Use this link to connect to the AWS SSO portal: https://acai-lab1.awsapps.com/start

UsernamePassword
lab_user1@acai.gmbhACAI2024
lab_user2@acai.gmbhACAI2024

Assigned permissions: assignments.tf

ACAI Vecto Resources

The Core IaC CI/CD Resources are managed by ACAI VECTO - the pipeline repository can be found here:

CI/CD Pipelines

The underlying repositories of the following pipelines are listed below.

Layers

ACAI Consulting is specialized in AWS Multi Account Security and Governance.

If you have any questions, feel free to get in touch with us: blog@acai.gmbh

References

[1] aws-landing-zone/