---
title: AWS and Azure Target Service Mappings
description: Complete reference mapping of AWS and Azure services to the full STACKIT service portfolio for compute, data, networking, security, and operations.
sidebar:
  label: Target Service Mappings
  order: 9
source_url: "https://framework.stackit.cloud/migration/design-and-mobilize/design/aws-azure-target-service-mappings/"
source_file: "docs/migration/design-and-mobilize/design/aws-azure-target-service-mappings.mdx"
---

## Purpose

Use these mappings to create an initial target design for workloads moving from AWS or Azure to
STACKIT. The tables cover the full STACKIT service portfolio, not only the services typically used
in a landing zone foundation, so they also apply to application, data, and platform migrations that
go beyond the initial landing zone. Confirm the application architecture, data profile,
availability needs, integration contracts, and operating model for every workload before approving
a migration wave.

## Landing zone foundation

For AWS and Azure landing zones, STACKIT provides a structured migration path that maps account and
subscription structures, network segmentation, identity and access controls, security policies,
logging, monitoring, and governance guardrails into a STACKIT landing zone before application
migration waves begin. The STACKIT Landing Zone Accelerator provides a reusable, automated
foundation for establishing these target controls consistently and at scale.

Start with the [Landing Zones overview](/migration/design-and-mobilize/landing-zones/overview/) to establish the platform baseline before workload migrations begin.

## Compute and containers

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **Amazon EC2** | **Azure Virtual Machines** | **STACKIT Compute Engine** (Linux Server, Windows Server) for VM-based workloads, including application runtime, middleware, operating system, storage, network configuration, and operational controls. |
| **AWS Nitro Enclaves** | **Azure confidential VMs** | **STACKIT Compute Engine** machine types with confidential computing (AMD SEV) for hardware-based memory isolation. |
| **Amazon EC2 GPU instances (P/G-series)** | **Azure NC/ND-series** | **STACKIT Compute Engine** GPU machine types, and GPU-enabled node pools on **STACKIT Kubernetes Engine**, for GPU-accelerated and AI/ML workloads. |
| **Amazon EKS** | **Azure AKS / self-managed Kubernetes** | **STACKIT Kubernetes Engine (SKE)** for managed Kubernetes operation. Stateless applications can be redeployed through GitOps; stateful workloads can use backup and restore or continuous data replication with staged traffic migration. |
| **AWS Elastic Beanstalk** | **Azure App Service-style workloads** | **STACKIT Cloud Foundry** for applications that fit a managed PaaS model, including Java, Node.js, Python, Ruby, web applications, APIs, and microservices. |
| **AWS Wavelength / Local Zones** | **Azure Edge Zones** | **STACKIT Edge Cloud** for managed Kubernetes clusters deployed close to factories, retail, or logistics locations, and in hybrid-cloud setups. |
| **Amazon ECR** | **Azure Container Registry** | **STACKIT Container Registry** for container image storage, image lifecycle management, access control, vulnerability scanning, and deployment-pipeline integration. |

## Storage

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **Amazon S3** | **Azure Blob Storage** | **STACKIT Object Storage** for controlled data copy, synchronization, validation, and operational handover. |
| **Amazon EFS** | **Azure Files / NFS file services** | **STACKIT File Storage** using a private connectivity path, initial copy, iterative delta synchronization, and a final consistency cutover. |
| **Amazon EBS** | **Azure Managed Disks** | **STACKIT Block Storage** attached to STACKIT Compute Engine or used as persistent storage for Kubernetes workloads, with application-level data migration and validation. |
| **AWS Backup** | **Azure Backup** | **STACKIT Server Backup Management** together with application- and database-specific backup, restore, retention, and disaster-recovery procedures. |
| **Amazon S3 Glacier** | **Azure Archive Storage tier** | **STACKIT Archiving**, an audit-proof, immutable storage service for compliant long-term retention. |

## Databases

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **Amazon RDS/Aurora for PostgreSQL** | **Azure Database for PostgreSQL** | **STACKIT PostgreSQL Flex**, a managed ACID relational database with automated patching, backups, and scaling. |
| **Amazon RDS/Aurora for MySQL** | **Azure Database for MySQL/MariaDB** | **STACKIT MariaDB** for dynamic, relational-database workloads. |
| **SQL Server on Amazon EC2** | **Azure SQL Database / Azure SQL Managed Instance** | **STACKIT SQLServer Flex**, a managed MSSQL database with high availability, automated backups, and scaling. |
| **Amazon DocumentDB** | **Azure Cosmos DB (MongoDB API)** | **STACKIT MongoDB Flex**, a managed document database with automated maintenance, scaling, and backups. |
| **Amazon ElastiCache** | **Azure Cache for Redis** | **STACKIT Redis** or **STACKIT Key Value Store** for caching, pub/sub, and low-latency data access. |
| **Amazon OpenSearch Service** | **Azure AI Search** | **STACKIT OpenSearch** for managed search and analytics clusters, indexing, querying, and visualizing data. |
| **Self-managed databases on Amazon EC2** | **Self-managed databases on Azure VMs** | **STACKIT Compute Engine** as a target for databases that initially retain their existing engine and operating model, migrated as part of a later optimization wave. |

## Data and AI

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **AWS Glue / Amazon Kinesis Data Firehose** | **Azure Data Factory ingestion** | **STACKIT Intake**, a managed streaming-ingestion service using the Kafka protocol to land data in platform tables. |
| **Amazon Athena / Redshift Spectrum** | **Azure Synapse serverless SQL** | **STACKIT Dremio**, a self-service data lakehouse with a high-performance SQL engine and unified data access layer. |
| **AWS Step Functions** | **Azure Data Factory pipelines / Logic Apps** | **STACKIT Workflows**, a workflow-orchestration engine for authoring, scheduling, and monitoring pipelines as code. |
| **Amazon SageMaker Studio Notebooks** | **Azure Machine Learning Notebooks** | **STACKIT Notebooks**, a managed JupyterHub service for collaborative data science and analytics. |
| **Amazon SageMaker Experiments** | **Azure Machine Learning experiment tracking** | **STACKIT AI Model Experiments**, a managed MLflow service for tracking AI training runs. |
| **Amazon Bedrock / SageMaker endpoints** | **Azure OpenAI Service / Azure Machine Learning endpoints** | **STACKIT AI Model Serving** for managed hosting of AI and LLM models with autoscaling. |

## Networking and content delivery

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **Amazon VPC** | **Azure VNet** | **STACKIT Virtual Network** and **STACKIT Network Area (SNA)**, together with network interfaces and public IP addresses, for network segmentation across projects. |
| **AWS Security Groups** | **Azure Network Security Groups** | **STACKIT Security Groups** mapped into the target network segmentation and least-privilege access model. |
| **Amazon Route 53** | **Azure DNS** | **STACKIT DNS** for zones, records, imports, controlled TTL changes, and cutover of public or private service endpoints. |
| **Amazon Route 53 Resolver** | **Azure Private DNS Resolver** | **STACKIT DNS Resolver** for secure, sovereign, and high-performance DNS resolution inside STACKIT network areas. |
| **AWS ELB, ALB, or NLB** | **Azure Load Balancer / Application Gateway** | **STACKIT Network Load Balancer** and **STACKIT Application Load Balancer** for traffic distribution, health checks, and controlled cutover patterns. |
| **Amazon CloudFront** | **Azure CDN / Front Door** | **STACKIT CDN** for global edge caching that accelerates content delivery and includes DDoS protection. |
| **AWS Direct Connect** | **Azure ExpressRoute / MPLS-connected environments** | **STACKIT VPN** for secure site-to-site and hybrid/multi-cloud connectivity between source environments and STACKIT Network Areas, designed with validated bandwidth, latency, MTU, routing, and resilience. |

## Security, identity, and access

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **AWS IAM** | **Azure RBAC / Microsoft Entra ID** | **STACKIT identity and access management (IAM)** roles, permissions, and service accounts, federated through the **STACKIT Identity Provider (IdP)** with OIDC, SAML, SCIM, and Microsoft Entra ID integration. |
| **AWS Secrets Manager** | **Azure Key Vault** | **STACKIT Secrets Manager** and **STACKIT KMS** for secret storage, encryption-key handling, access control, and rotation. |
| **AWS Security Hub** | **Azure Defender for Cloud** | **STACKIT Cloud Security Posture Management (CSPM)** for proactive control, comprehensive visibility, automated detection, and guided mitigation of security risks. |
| **AWS Network Firewall / Firewall Manager** | **Azure Firewall** | **STACKIT Unified Firewall** for centralized, wizard-driven firewall rule management across STACKIT infrastructure. |

## Messaging and notifications

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **Amazon SQS / AMQP messaging** | **Azure Service Bus queues** | **STACKIT RabbitMQ**, a managed message broker providing reliable queues, routing, and pub/sub for application-level integration and messaging design. |
| **Amazon SES** | **Azure Communication Services Email** | **STACKIT MailOut**, a transactional email service for automated sending of registration, notification, and order-confirmation emails. |

## Observability and operations

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **Amazon CloudWatch** | **Azure Monitor / Log Analytics** | **STACKIT Observability**, **STACKIT Logs**, **STACKIT LogMe**, and **STACKIT Telemetry Router** for metrics, logs, alerting, dashboards, and audit-stream routing. |
| **AWS CloudTrail** | **Azure Activity Log** | **STACKIT Audit Log** for recording and reviewing activities across projects and organizations. |
| **AWS Systems Manager Automation** | **Azure Automation** | **STACKIT Automation Service** for scheduling, workflows, and stateful orchestration of recurring administrative cloud operations. |
| **AWS Systems Manager Run Command** | **Azure Run Command** | **STACKIT Run Command** for remote execution of scripts and commands across virtual machines. |
| **AWS Systems Manager Patch Manager** | **Azure Update Management** | **STACKIT Server Update Management** for automated OS update processes on Linux and Windows servers. |

## Developer platform and infrastructure tooling

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **AWS CodeCommit** | **Azure DevOps Repos and pipelines** | **STACKIT Git** with integrated Git pipelines for source control and CI/CD automation. |
| **AWS CloudFormation/CDK** | **Azure Bicep/ARM templates** | The **STACKIT Terraform Provider**, Pulumi provider, or other STACKIT Infrastructure as Code tooling for declarative, version-controlled provisioning. |
| **AWS CLI** | **Azure CLI** | **STACKIT CLI** for scripting and automating STACKIT resources from the command line. |
| **AWS SDKs** | **Azure SDKs** | **STACKIT Cloud SDKs** for programmatic access to STACKIT services from common languages. |
| **AWS REST APIs** | **Azure REST APIs** | **STACKIT API**, including the IaaS API, for direct, authenticated access to platform resources. |

## Governance, cost, and marketplace

| AWS service | Azure service | STACKIT target service or approach |
| --- | --- | --- |
| **AWS Organizations** | **Azure Management Groups** | **STACKIT Customer Accounts** and **STACKIT Resource Manager** for organizing resources into organizations, folders, and projects. |
| **AWS Cost Explorer/Budgets** | **Azure Cost Management + Billing** | STACKIT **Costs and billing**, including the Cost Dashboard, for tracking and understanding cloud resource costs. |
| **AWS Marketplace** | **Azure Marketplace** | **STACKIT Marketplace** for procuring partner software and services and deploying curated solutions. |
| **AWS Support Plans** | **Azure Support Plans** | **STACKIT Support** for enterprise support tiers with defined response times. |

## Using the mappings in a migration design

1. Classify the workload with the [Workload Migration Use Cases](/migration/design-and-mobilize/design/workload-migration-use-cases/).
2. Select the target services and record the required data, identity, network, security, and operations patterns.
3. Choose the appropriate [R-strategy](/migration/design-and-mobilize/design/overview/#r-strategy-as-core-design-method) and define the migration runbook.
4. Validate the target design against the landing-zone baseline before scheduling the workload into a migration wave.
