Skip to content
Beta

Landing Zones

Landing Zones establish the cloud foundation for governance, security, networking, and automation before migration waves begin.

In 5 trails

A landing zone is the structured cloud foundation that defines how your organization operates on STACKIT from day 1. It combines governance, identity, security, network design, cost controls, and automation into one coherent baseline.

Without this foundation, migration waves typically stall due to missing approvals, inconsistent controls, and repeated platform decisions.

The following visual summarizes the core components that should be addressed for a reliable platform baseline.

Landing zone core components Six building blocks of a secure landing zone. Landing zone core componentsThe six building blocks of a secure platform foundation on STACKIT.Account GovernanceAccount GovernanceHow do I structure my projects?Identity & Access ManagementIdentity & Access ManagementWho can do what on the platform?Security & ComplianceSecurity & ComplianceHow do I monitor and protect?Network ArchitectureNetwork ArchitectureHow are components securely connected?Cost Management and ControlCost Management and ControlHow do I keep spending in control?Automation (IaC)Automation (IaC)How is everything delivered and managed?
  • Control and risk reduction: Enforce security and compliance controls consistently across teams.
  • Scalable delivery baseline: Enable repeatable provisioning patterns for multiple migration waves.
  • Clear responsibilities: Define ownership boundaries for platform, security, and application teams.
  • Faster migration throughput: Avoid redesigning core controls for each application move.

Start the landing-zone stream as early as possible, in parallel with discovery.

  • Too late: Productive migrations are blocked because mandatory controls are not yet available.
  • Too early without discovery feedback: Application constraints are missed and later cause rework.

The practical model is a dual track: establish the platform baseline early, then refine application landing zone templates as discovery insights mature.

Two layers: Platform and Application Landing Zones

Section titled “Two layers: Platform and Application Landing Zones”

Platform Landing Zone

Company-wide foundation for governance, identity, security, networking, cost controls, and automation.

Open Platform Landing Zone

Application Landing Zone

Workload-specific implementation patterns derived from the platform baseline and discovery findings.

Open Application Landing Zone

To design a landing zone effectively, enterprises usually provide:

  • Organization and ownership model: Entities, project boundaries, and accountability model.
  • Compliance and policy requirements: Regulatory obligations and internal control policies.
  • Security requirements: IAM standards, network segmentation, encryption, and logging expectations.
  • Operations and support constraints: Incident handling, escalation paths, and handover model.
  • Application portfolio insights: Discovery findings about workload archetypes and dependencies.
  1. Define enterprise guardrails and target control model.
  2. Build and validate the platform landing zone baseline as code.
  3. Derive application landing zone templates from discovery and migration design.
  4. Pilot with selected workloads, then scale through migration factory runbooks.

To accelerate delivery, STACKIT provides concrete best practices and reusable templates:

Asset title
Framework
Asset type