---
title: Architecture Patterns
description: Compare boundary-centric and Zero Trust patterns, define selection criteria, and establish practical target architectures for migration.
sidebar:
  label: Architecture Patterns
  order: 11
source_url: "https://framework.stackit.cloud/migration/design-and-mobilize/security-and-compliance/architecture-patterns/"
source_file: "docs/migration/design-and-mobilize/security-and-compliance/architecture-patterns.mdx"
---

## Purpose

This module helps you define where boundary-centric controls are required and where Zero Trust patterns should be the default.

## Pattern 1: Boundary-centric architecture

- **Core principle**: Protect workloads through segmentation, route control, and centralized inspection.
- **Typical implementation**: Hub-and-spoke topology with central firewall and managed ingress and egress paths.
- **Primary strengths**: Clear traffic governance and familiar operations for on-premises teams.
- **Typical limits**: Risk of over-reliance on network boundaries for identity and workload protection.

{/* vale off */}

## Example: STACKIT Hub & Spoke Architecture

{/* vale on */}

The following diagram illustrates a typical implementation of the hub & spoke principle in STACKIT:

- Each project (spoke) is connected to the central Shared Network Area (SNA) through peering.
- The routing tables in the SNA enforce that all traffic between projects and to the internet always passes through the central firewall in the hub.
- The hub provides central network functions: firewall (all communication is routed here), VPN gateway (on-premises connectivity), and internet breakout (internet access).
- Shared services are available to all projects and are also connected through the SNA.
- Communication to the internet or on-premises is only possible through the central components in the hub.
  This ensures clear separation, central control, and high security—no direct traffic between projects, everything is routed through the central infrastructure.

![STACKIT Network Area hub-and-spoke architecture with Routing Tables, central firewall, VPN router, application landing zone spokes, on-premises, and internet connectivity](../landing-zones/files/stackit-hub-and-spoke-network-area.svg)

## Pattern 2: Zero Trust-oriented architecture

- **Core principle**: Never trust by location; verify explicitly and continuously.
- **Typical implementation**: Identity-based access, strong authentication, encryption, and policy enforcement close to workloads.
- **Primary strengths**: Strong fit for distributed systems and internet-facing patterns.
- **Typical limits**: Requires mature identity governance and disciplined policy operations.

## Zero trust domains

Use the interactive map to open the dedicated domain pages.

<ZeroTrustSVG
  style={{
    width: "100%",
    maxWidth: "801px",
    height: "auto",
    display: "block",
    margin: "1rem auto",
  }}
/>

## Practical combination strategy

- **Foundation layer**: Keep mandatory network controls for segmentation and regulated paths.
- **Access layer**: Use identity-first authorization for user and service access.
- **Data layer**: Enforce encryption and key-governance controls independent of location.
- **Operations layer**: Correlate network and identity telemetry for detection and evidence.

## STACKIT references

- **Network Area and Routing Tables**: <LinkChip href="https://docs.stackit.cloud/products/network/core-networking/network-area/basics/concepts/">Concepts</LinkChip> and <LinkChip href="https://docs.stackit.cloud/products/network/core-networking/network-area/basics/routing-tables/">Routing Tables</LinkChip>
- **Unified Firewall**: <LinkChip href="https://docs.stackit.cloud/products/network/network-security/unified-firewall/basics/introduction/">Documentation</LinkChip>
- **Access and identity context**: <LinkChip href="https://docs.stackit.cloud/platform/access-and-identity/">Documentation</LinkChip>

## Anti-patterns to avoid

- **Topology as security proxy**: Segmentation is treated as replacement for identity and workload controls.
- **Zero Trust in name only**: Missing strong authentication, policy enforcement, or encryption standards.
- **Unmanaged transition patterns**: Temporary hybrid patterns remain without convergence plan.
