---
title: "Landing Zone Journey"
description: "Guided landing zone presentation covering definition, timing, architecture layers, workload scope, accelerator implementation, and STACKIT managed delivery."
hideBreadcrumbs: true
sidebar:
  hidden: true
scfTrail:
  maintainers:
    - user: "lukas.weberruss"
      role: true
      website: true
  steps:
    - style: "chart"
      id: "service-portfolio"
      title: "Explore the STACKIT Service Portfolio"
      trailContext: "Use the interactive portfolio to establish which STACKIT services can support the platform and application landing-zone capabilities discussed in this journey."
      assetId: "architecture/assetcontainer/stackit/stackit-service-portfolio-map.mdx#interactive-service-portfolio"

    - style: "compass"
      id: "start-early"
      title: "Place the Landing Zone in the Migration Framework"
      trailContext: "A landing zone is the shared runway for governed migration. Establish its platform stream during Design and Mobilize, so migration waves inherit a working baseline for controlled delivery and stable operations."
      imageSrc: "migration/files/migration-framework-overview.svg"
      imageAlt: "Migration Framework overview showing Design and Mobilize before migration waves"
      imageWidth: 48

    - style: "stairs"
      id: "define-landing-zone"
      title: "Define the Platform Landing Zone"
      trailContext: "Introduce a landing zone as the structured cloud foundation for governed operations on STACKIT. Use this opening to align stakeholders on the key questions: which guardrails are mandatory, who owns them, and what application needs must be supported."
      description: "The landing zone combines governance, identity, security, networking, cost controls, and automation into a common operating baseline."
      pageId: "migration/design-and-mobilize/landing-zones/overview"

    - style: "hut"
      id: "account-governance"
      title: "Structure Account Governance"
      trailContext: "Establish the organizational structure, project boundaries, and ownership model that make landing-zone governance repeatable across teams and environments."
      pageId: "migration/design-and-mobilize/landing-zones/account-governance#governance-design-and-delivery"
      imageSrc: "migration/design-and-mobilize/landing-zones/files/stackit-governance-hierarchy.svg"
      imageAlt: "Governance hierarchy from customer account and folders to projects, resources, and labels"
      imagePosition: right
      imageWidth: 46

    - role: sub
      id: "identity-access"
      title: "Define Identity and Access"
      trailContext: "Set the IAM model, role patterns, and separation of duties so people and automation receive only the access they need."
      pageId: "migration/design-and-mobilize/landing-zones/identity-and-access-management/"

    - style: "shield"
      id: "security-topic-map"
      title: "Security and Compliance topics"
      trailContext: "Map security and compliance topics early so control requirements, evidence, sovereignty decisions, and zero-trust principles inform the landing-zone design."
      pageId: "migration/design-and-mobilize/security-and-compliance/overview/#security-and-compliance-topic-map"

    - role: sub
      id: "landing-zone-security"
      title: "Apply Security and Compliance"
      trailContext: "Translate mandatory security controls, logging, evidence, and policy requirements into enforceable landing-zone guardrails."
      pageId: "migration/design-and-mobilize/landing-zones/security-and-compliance/"

    - style: "chairlift"
      id: "network-architecture"
      title: "Design Network Architecture"
      trailContext: "Define segmentation, connectivity, DNS, routing, and secure communication patterns for shared services and workload environments."
      pageId: "migration/design-and-mobilize/landing-zones/network-architecture#connectivity-design-and-delivery"
      imageSrc: "migration/design-and-mobilize/landing-zones/files/stackit-hub-and-spoke-network-area.svg"
      imageAlt: "STACKIT Network Area hub-and-spoke architecture with Routing Tables, central firewall, VPN router, application landing zone spokes, on-premises, and internet connectivity"
      imagePosition: right
      imageWidth: 46

    - role: sub
      id: "cost-management"
      title: "Control Costs and Consumption"
      trailContext: "Establish tagging, budgets, transparency, and accountability so cloud consumption remains visible and governable from the beginning."
      pageId: "migration/design-and-mobilize/landing-zones/cost-management-and-control/"

    - role: sub
      id: "automation-iac"
      title: "Automate with Infrastructure as Code"
      trailContext: "Use versioned Infrastructure as Code and policy automation to provision, validate, and evolve landing-zone capabilities consistently."
      pageId: "migration/design-and-mobilize/landing-zones/automation-iac/"

    - role: sub
      id: "platform-boundary"
      title: "Set the Platform Landing Zone Boundary"
      trailContext: "Separate the company-wide platform layer from workload delivery. The platform landing zone is the target operating baseline for every product team: it structures organizations, projects, and environments; defines IAM roles, least privilege, and separation of duties; enforces security, compliance, logging, and evidence; and provides shared network segmentation, connectivity, cost controls, and Infrastructure as Code automation."
      description: "Start from the organization and ownership model, regulatory and security requirements, connectivity needs, and operating-model boundaries. Define control objectives, implement reusable policy and automation modules, validate them with pilot workloads, then operationalize ownership, runbooks, and change processes. Standardize first; manage exceptions explicitly, with approval and an expiry date."
      pageId: "migration/design-and-mobilize/landing-zones/platform-landing-zone#understanding-platform-landing-zones"

    - role: sub
      id: "platform-prerequisites"
      title: "Gather Platform Prerequisites"
      trailContext: "Collect the business-unit and ownership model, regulatory scope, security standards, connectivity needs, and operating-model constraints before finalizing the platform baseline."
      description: "These inputs define the boundaries for projects, environments, audit evidence, integrations, support, and handover."
      pageId: "migration/design-and-mobilize/landing-zones/platform-landing-zone#typical-inputs-and-prerequisites"

    - role: sub
      id: "platform-delivery"
      title: "Deliver the Platform Baseline"
      trailContext: "Move from governance objectives to reusable identity, network, security, and cost patterns; implement automation and policy guardrails; validate them with pilots; then operationalize the platform."
      description: "This sequence closes architecture and compliance gaps before migration waves depend on the foundation."
      pageId: "migration/design-and-mobilize/landing-zones/platform-landing-zone#delivery-sequence"

    - role: sub
      id: "platform-principles"
      title: "Apply Platform Design Principles"
      trailContext: "Standardize before allowing exceptions, automate controls, create compliance evidence from day one, and design for multiple teams and workload archetypes."
      description: "Exceptions remain visible, approved, owned, and time-bound rather than becoming unmanaged platform drift."
      pageId: "migration/design-and-mobilize/landing-zones/platform-landing-zone#design-principles"

    - style: "chart"
      id: "r-strategy-application-design"
      title: "Connect R-Strategy to Landing Zone Design"
      trailContext: "Use the selected R-strategy and target architecture for each application to derive the landing-zone capabilities, controls, connectivity, and service patterns its migration requires."
      pageId: "migration/design-and-mobilize/design/overview/#r-strategy-as-core-design-method"

    - style: "gondola"
      id: "workload-patterns"
      title: "Application Landing Zones"
      splitRatio: 55
      left:
        - pageId: "migration/design-and-mobilize/landing-zones/application-landing-zone#understanding-application-landing-zones"
        - pageId: "migration/design-and-mobilize/landing-zones/application-landing-zone#why-it-depends-on-discovery"
        - pageId: "migration/design-and-mobilize/landing-zones/application-landing-zone#typical-application-landing-zone-patterns"
      right:
        - pageId: "migration/design-and-mobilize/discovery/overview#discovery-process-at-a-glance"
        - pageId: "migration/design-and-mobilize/landing-zones/application-landing-zone#delivery-approach"
        - pageId: "migration/design-and-mobilize/landing-zones/application-landing-zone#best-practices"

    - style: "rocket"
      id: "accelerator"
      title: "Accelerate the Foundation as Code"
      splitRatio: 50
      left:
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#overview"
          cards: false
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#how-the-repository-works"
          cards: false
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#deployment-flavours-and-what-they-enable"
          cards: false
      right:
        - imageSrc: "contributors/stackit/files/migration/landing-zone-accelerator-architecture.svg"
          imageAlt: "STACKIT Landing Zone Accelerator architecture from bootstrap through platform capabilities to application landing zones"

    - style: "shield"
      id: "accelerator-platform-modules"
      title: "Establish the Platform Baseline"
      splitRatio: 50
      left:
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#1-governance-module-srcmodulesgovernance"
          cards: false
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#2-management-module-srcmodulesmanagement"
          cards: false
      right:
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#3-connectivity-module-srcmodulesconnectivity"
          cards: false
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#4-devops-module-srcmodulesdevops"
          cards: false

    - style: "compass"
      id: "accelerator-standalone"
      title: "Start with a Standalone Foundation"
      trailContext: "Choose the smallest accelerator topology when workloads need independent networks and direct internet access without shared private connectivity."
      imageSrc: "contributors/stackit/files/migration/standalone.svg"
      imageAlt: "Standalone topology with a management foundation, sandbox, and public application landing zone"

    - style: "chart"
      id: "accelerator-hub-and-spoke"
      title: "Connect Corporate Workloads Privately"
      trailContext: "Introduce a central connectivity project, shared Network Area, and DNS when corporate workloads need private east-west communication."
      imageSrc: "contributors/stackit/files/migration/hub-and-spoke.svg"
      imageAlt: "Hub-and-spoke topology with a shared Network Area and separate public landing zone"

    - style: "shield"
      id: "accelerator-hub-and-spoke-firewall"
      title: "Centralize Egress Inspection"
      trailContext: "Extend hub-and-spoke with an OPNsense firewall when corporate traffic requires a consistent inspection point and controlled egress path."
      imageSrc: "contributors/stackit/files/migration/hub-and-spoke-firewall.svg"
      imageAlt: "Hub-and-spoke topology with centralized OPNsense firewall inspection"

    - style: "hut"
      id: "accelerator-finance-research"
      title: "Separate Business Unit Domains"
      trailContext: "Give finance and research independent ownership, address plans, connectivity projects, and private workload domains inside one organization."
      imageSrc: "contributors/stackit/files/migration/hub-and-spoke-finance-research.svg"
      imageAlt: "Finance and research topology with independent private connectivity domains"

    - style: "stairs"
      id: "accelerator-multi-area"
      title: "Separate Regulated and Shared Workloads"
      trailContext: "Create distinct Network Areas and DNS zones when regulated and shared workloads must have no implicit private routing between them."
      imageSrc: "contributors/stackit/files/migration/hub-and-spoke-multi-area.svg"
      imageAlt: "Multi-area topology separating regulated and shared workloads"

    - style: "gondola"
      id: "accelerator-multi-region"
      title: "Build Independent Regional Hubs"
      trailContext: "Deploy isolated foundations in eu01 and eu02 when regional workloads need their own connectivity, landing-zone, and platform boundaries."
      imageSrc: "contributors/stackit/files/migration/hub-and-spoke-multi-region.svg"
      imageAlt: "Multi-region topology with independent hubs in eu01 and eu02"

    - style: "shield"
      id: "accelerator-prod-nonprod"
      title: "Isolate Production from Non-production"
      trailContext: "Use separate Network Areas and firewalls when production requires a stronger boundary while development and test can share a non-production domain."
      imageSrc: "contributors/stackit/files/migration/hub-and-spoke-prod-nonprod-firewall.svg"
      imageAlt: "Production and non-production topology with separate Network Areas and firewalls"

    - style: "chairlift"
      id: "accelerator-tenant-isolation"
      title: "Isolate Tenant Connectivity"
      trailContext: "Create independent ownership, address plans, and private connectivity domains when multiple tenants share the organization but must not route to one another."
      imageSrc: "contributors/stackit/files/migration/hub-and-spoke-tenant-isolation.svg"
      imageAlt: "Tenant isolation topology with three independent private tenant domains"

    - style: "gondola"
      id: "accelerator-application-modules"
      title: "Provision Application Environments"
      splitRatio: 50
      left:
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#5-landing-zone-module-srcmoduleslanding-zone"
          cards: false
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#6-sandboxes-module-srcmodulessandboxes"
          cards: false
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#platform-vs-application-landing-zone-scope-in-this-repository"
          cards: false
      right:
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#how-to-use-this-asset-in-migration-programs"
          cards: false
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#what-you-get"
          cards: false
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#typical-use-in-migration-programs"
          cards: false
        - assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu.mdx#recommended-prerequisites"
          cards: false

    - style: "summit"
      id: "managed-delivery"
      title: "Scale Through Managed Delivery"
      trailContext: "Organizations can combine the accelerator with a managed delivery stream: structured advisory, implementation guidance, catalog-based setup, and a documented operational handover align platform, security, and application teams."
      imageSrc: "migration/design-and-mobilize/landing-zones/files/stackit-hub-and-spoke-network-area.svg"
      imageAlt: "Hub-and-spoke network area illustrating shared connectivity for landing zones"
      imagePosition: right
      imageWidth: 48
      assetId: "migration/assetcontainer/stackit/managed-landing-zone-service.mdx#overview"

    - role: sub
      id: "managed-service-scope"
      title: "Define the Managed Service Scope"
      trailContext: "Present the service scope: target design and rollout planning, catalog-based implementation, OpenTofu and Terragrunt enablement, and documented operational handover."
      assetId: "migration/assetcontainer/stackit/managed-landing-zone-service.mdx#service-scope"

    - role: sub
      id: "managed-service-outcomes"
      title: "Review Managed Service Outcomes"
      trailContext: "Show the intended outcomes: a governed platform baseline, reusable automation conventions, earlier migration readiness, and lower delivery risk through aligned platform, security, and application teams."
      assetId: "migration/assetcontainer/stackit/managed-landing-zone-service.mdx#typical-outcomes"

    - role: sub
      id: "engagement-model"
      title: "Select an Engagement Model"
      trailContext: "Position the service as either a focused landing-zone setup initiative or a delivery stream within a broader migration factory, delivered jointly with platform, security, and application stakeholders."
      assetId: "migration/assetcontainer/stackit/managed-landing-zone-service.mdx#engagement-model"

    - style: "rocket"
      id: "meshstack-architecture"
      title: "meshStack Simplifies Landing Zone Management"
      left:
        - assetId: "migration/assetcontainer/meshcloud/meshstack-self-service-landing-zone.mdx#overview"
          cards: false
        - imageSrc: "contributors/meshcloud/files/migration/meshstack-stackit-landing-zone.svg"
          imageAlt: "Joint STACKIT and meshStack architecture: the Landing Zone Accelerator provides the platform baseline, while meshStack enables governed self-service"
        - assetId: "migration/assetcontainer/meshcloud/meshstack-self-service-landing-zone.mdx#how-the-two-parts-compose"
          cards: false

    - style: "summit"
      id: "meshstack-self-service"
      title: "Deliver Projects and Networks Through Self-Service"
      splitRatio: 50
      left:
        - assetId: "migration/assetcontainer/meshcloud/meshstack-self-service-landing-zone.mdx#what-it-provisions"
          cards: false
        - assetId: "migration/assetcontainer/meshcloud/meshstack-self-service-landing-zone.mdx#what-application-teams-get"
          cards: false
      right:
        - assetId: "migration/assetcontainer/meshcloud/meshstack-self-service-landing-zone.mdx#shared-responsibilities"
          cards: false

  presentations:
    - id: "executive-overview"
      label: "Executive overview"
      description: "Five visual milestones for decision-makers aligning foundation, delivery approach, and migration readiness."
      preset: "minimal"
      fullscreen: true
      agenda: false
      steps:
        - "start-early"
        - "define-landing-zone"
        - "workload-patterns"
        - "accelerator"
        - "managed-delivery"
    - id: "technical-deep-dive"
      label: "Technical deep-dive"
      description: "Technical implementation deck covering the STACKIT portfolio, landing-zone controls, application patterns, and eight accelerator topologies."
      default: true
      launch: true
      preset: "focus"
      steps:
        - "service-portfolio"
        - "start-early"
        - "define-landing-zone"
        - id: "account-governance"
          role: hidden
        - id: "identity-access"
          role: hidden
        - id: "security-topic-map"
          role: hidden
        - id: "landing-zone-security"
          role: hidden
        - id: "network-architecture"
          role: hidden
        - id: "automation-iac"
          role: hidden
        - id: "r-strategy-application-design"
          role: hidden
        - "workload-patterns"
        - id: "discovery-inputs"
          role: hidden
        - id: "discovery-process"
          role: hidden
        - id: "application-pattern"
          role: hidden
        - id: "application-delivery"
          role: hidden
        - "accelerator"
        - id: "accelerator-platform-modules"
          role: hidden
        - id: "accelerator-standalone"
          role: hidden
        - id: "accelerator-hub-and-spoke"
          role: hidden
        - id: "accelerator-hub-and-spoke-firewall"
          role: hidden
        - id: "accelerator-finance-research"
          role: hidden
        - id: "accelerator-multi-area"
          role: hidden
        - id: "accelerator-multi-region"
          role: hidden
        - id: "accelerator-prod-nonprod"
          role: hidden
        - id: "accelerator-tenant-isolation"
          role: hidden
    - id: "webinar"
      label: "Webinar"
      description: "Focused landing-zone webinar covering framework context, platform governance, security, networking, application landing zones, and automation."
      launch: true
      preset: "focus"
      steps:
        - "service-portfolio"
        - "start-early"
        - "define-landing-zone"
        - "account-governance"
        - "security-topic-map"
        - "network-architecture"
        - "workload-patterns"
        - "accelerator"
        - "meshstack-architecture"
        - id: "meshstack-self-service"
          role: hidden
source_url: "https://framework.stackit.cloud/migration/trails/stackit/landing-zone-journey/"
source_file: "docs/migration/trails/stackit/landing-zone-journey.mdx"
---

## Steps

### 1. Explore the STACKIT Service Portfolio

Stage: `chart`

Use the interactive portfolio to establish which STACKIT services can support the platform and application landing-zone capabilities discussed in this journey.

Asset: [/architecture/assetcontainer/stackit/stackit-service-portfolio-map/#interactive-service-portfolio](/architecture/assetcontainer/stackit/stackit-service-portfolio-map/#interactive-service-portfolio) — source: [/raw/architecture/assetcontainer/stackit/stackit-service-portfolio-map.md](/raw/architecture/assetcontainer/stackit/stackit-service-portfolio-map.md), section `#interactive-service-portfolio`

### 2. Place the Landing Zone in the Migration Framework

Stage: `compass`

A landing zone is the shared runway for governed migration. Establish its platform stream during Design and Mobilize, so migration waves inherit a working baseline for controlled delivery and stable operations.

### 3. Define the Platform Landing Zone

Stage: `stairs`

Introduce a landing zone as the structured cloud foundation for governed operations on STACKIT. Use this opening to align stakeholders on the key questions: which guardrails are mandatory, who owns them, and what application needs must be supported.

The landing zone combines governance, identity, security, networking, cost controls, and automation into a common operating baseline.

Page: [/migration/design-and-mobilize/landing-zones/overview/](/migration/design-and-mobilize/landing-zones/overview/) — source: [/raw/migration/design-and-mobilize/landing-zones/overview.md](/raw/migration/design-and-mobilize/landing-zones/overview.md)

### 4. Structure Account Governance

Stage: `hut`

Establish the organizational structure, project boundaries, and ownership model that make landing-zone governance repeatable across teams and environments.

Page: [/migration/design-and-mobilize/landing-zones/account-governance/#governance-design-and-delivery](/migration/design-and-mobilize/landing-zones/account-governance/#governance-design-and-delivery) — source: [/raw/migration/design-and-mobilize/landing-zones/account-governance.md](/raw/migration/design-and-mobilize/landing-zones/account-governance.md), section `#governance-design-and-delivery`

### 5. Define Identity and Access

Set the IAM model, role patterns, and separation of duties so people and automation receive only the access they need.

Page: [/migration/design-and-mobilize/landing-zones/identity-and-access-management/](/migration/design-and-mobilize/landing-zones/identity-and-access-management/) — source: [/raw/migration/design-and-mobilize/landing-zones/identity-and-access-management.md](/raw/migration/design-and-mobilize/landing-zones/identity-and-access-management.md)

### 6. Security and Compliance topics

Stage: `shield`

Map security and compliance topics early so control requirements, evidence, sovereignty decisions, and zero-trust principles inform the landing-zone design.

Page: [/migration/design-and-mobilize/security-and-compliance/overview/#security-and-compliance-topic-map](/migration/design-and-mobilize/security-and-compliance/overview/#security-and-compliance-topic-map) — source: [/raw/migration/design-and-mobilize/security-and-compliance/overview.md](/raw/migration/design-and-mobilize/security-and-compliance/overview.md), section `#security-and-compliance-topic-map`

### 7. Apply Security and Compliance

Translate mandatory security controls, logging, evidence, and policy requirements into enforceable landing-zone guardrails.

Page: [/migration/design-and-mobilize/landing-zones/security-and-compliance/](/migration/design-and-mobilize/landing-zones/security-and-compliance/) — source: [/raw/migration/design-and-mobilize/landing-zones/security-and-compliance.md](/raw/migration/design-and-mobilize/landing-zones/security-and-compliance.md)

### 8. Design Network Architecture

Stage: `chairlift`

Define segmentation, connectivity, DNS, routing, and secure communication patterns for shared services and workload environments.

Page: [/migration/design-and-mobilize/landing-zones/network-architecture/#connectivity-design-and-delivery](/migration/design-and-mobilize/landing-zones/network-architecture/#connectivity-design-and-delivery) — source: [/raw/migration/design-and-mobilize/landing-zones/network-architecture.md](/raw/migration/design-and-mobilize/landing-zones/network-architecture.md), section `#connectivity-design-and-delivery`

### 9. Control Costs and Consumption

Establish tagging, budgets, transparency, and accountability so cloud consumption remains visible and governable from the beginning.

Page: [/migration/design-and-mobilize/landing-zones/cost-management-and-control/](/migration/design-and-mobilize/landing-zones/cost-management-and-control/) — source: [/raw/migration/design-and-mobilize/landing-zones/cost-management-and-control.md](/raw/migration/design-and-mobilize/landing-zones/cost-management-and-control.md)

### 10. Automate with Infrastructure as Code

Use versioned Infrastructure as Code and policy automation to provision, validate, and evolve landing-zone capabilities consistently.

Page: [/migration/design-and-mobilize/landing-zones/automation-iac/](/migration/design-and-mobilize/landing-zones/automation-iac/) — source: [/raw/migration/design-and-mobilize/landing-zones/automation-iac.md](/raw/migration/design-and-mobilize/landing-zones/automation-iac.md)

### 11. Set the Platform Landing Zone Boundary

Separate the company-wide platform layer from workload delivery. The platform landing zone is the target operating baseline for every product team: it structures organizations, projects, and environments; defines IAM roles, least privilege, and separation of duties; enforces security, compliance, logging, and evidence; and provides shared network segmentation, connectivity, cost controls, and Infrastructure as Code automation.

Start from the organization and ownership model, regulatory and security requirements, connectivity needs, and operating-model boundaries. Define control objectives, implement reusable policy and automation modules, validate them with pilot workloads, then operationalize ownership, runbooks, and change processes. Standardize first; manage exceptions explicitly, with approval and an expiry date.

Page: [/migration/design-and-mobilize/landing-zones/platform-landing-zone/#understanding-platform-landing-zones](/migration/design-and-mobilize/landing-zones/platform-landing-zone/#understanding-platform-landing-zones) — source: [/raw/migration/design-and-mobilize/landing-zones/platform-landing-zone.md](/raw/migration/design-and-mobilize/landing-zones/platform-landing-zone.md), section `#understanding-platform-landing-zones`

### 12. Gather Platform Prerequisites

Collect the business-unit and ownership model, regulatory scope, security standards, connectivity needs, and operating-model constraints before finalizing the platform baseline.

These inputs define the boundaries for projects, environments, audit evidence, integrations, support, and handover.

Page: [/migration/design-and-mobilize/landing-zones/platform-landing-zone/#typical-inputs-and-prerequisites](/migration/design-and-mobilize/landing-zones/platform-landing-zone/#typical-inputs-and-prerequisites) — source: [/raw/migration/design-and-mobilize/landing-zones/platform-landing-zone.md](/raw/migration/design-and-mobilize/landing-zones/platform-landing-zone.md), section `#typical-inputs-and-prerequisites`

### 13. Deliver the Platform Baseline

Move from governance objectives to reusable identity, network, security, and cost patterns; implement automation and policy guardrails; validate them with pilots; then operationalize the platform.

This sequence closes architecture and compliance gaps before migration waves depend on the foundation.

Page: [/migration/design-and-mobilize/landing-zones/platform-landing-zone/#delivery-sequence](/migration/design-and-mobilize/landing-zones/platform-landing-zone/#delivery-sequence) — source: [/raw/migration/design-and-mobilize/landing-zones/platform-landing-zone.md](/raw/migration/design-and-mobilize/landing-zones/platform-landing-zone.md), section `#delivery-sequence`

### 14. Apply Platform Design Principles

Standardize before allowing exceptions, automate controls, create compliance evidence from day one, and design for multiple teams and workload archetypes.

Exceptions remain visible, approved, owned, and time-bound rather than becoming unmanaged platform drift.

Page: [/migration/design-and-mobilize/landing-zones/platform-landing-zone/#design-principles](/migration/design-and-mobilize/landing-zones/platform-landing-zone/#design-principles) — source: [/raw/migration/design-and-mobilize/landing-zones/platform-landing-zone.md](/raw/migration/design-and-mobilize/landing-zones/platform-landing-zone.md), section `#design-principles`

### 15. Connect R-Strategy to Landing Zone Design

Stage: `chart`

Use the selected R-strategy and target architecture for each application to derive the landing-zone capabilities, controls, connectivity, and service patterns its migration requires.

Page: [/migration/design-and-mobilize/design/overview/#r-strategy-as-core-design-method](/migration/design-and-mobilize/design/overview/#r-strategy-as-core-design-method) — source: [/raw/migration/design-and-mobilize/design/overview.md](/raw/migration/design-and-mobilize/design/overview.md), section `#r-strategy-as-core-design-method`

### 16. Application Landing Zones

Stage: `gondola`

### 17. Accelerate the Foundation as Code

Stage: `rocket`

### 18. Establish the Platform Baseline

Stage: `shield`

### 19. Start with a Standalone Foundation

Stage: `compass`

Choose the smallest accelerator topology when workloads need independent networks and direct internet access without shared private connectivity.

### 20. Connect Corporate Workloads Privately

Stage: `chart`

Introduce a central connectivity project, shared Network Area, and DNS when corporate workloads need private east-west communication.

### 21. Centralize Egress Inspection

Stage: `shield`

Extend hub-and-spoke with an OPNsense firewall when corporate traffic requires a consistent inspection point and controlled egress path.

### 22. Separate Business Unit Domains

Stage: `hut`

Give finance and research independent ownership, address plans, connectivity projects, and private workload domains inside one organization.

### 23. Separate Regulated and Shared Workloads

Stage: `stairs`

Create distinct Network Areas and DNS zones when regulated and shared workloads must have no implicit private routing between them.

### 24. Build Independent Regional Hubs

Stage: `gondola`

Deploy isolated foundations in eu01 and eu02 when regional workloads need their own connectivity, landing-zone, and platform boundaries.

### 25. Isolate Production from Non-production

Stage: `shield`

Use separate Network Areas and firewalls when production requires a stronger boundary while development and test can share a non-production domain.

### 26. Isolate Tenant Connectivity

Stage: `chairlift`

Create independent ownership, address plans, and private connectivity domains when multiple tenants share the organization but must not route to one another.

### 27. Provision Application Environments

Stage: `gondola`

### 28. Scale Through Managed Delivery

Stage: `summit`

Organizations can combine the accelerator with a managed delivery stream: structured advisory, implementation guidance, catalog-based setup, and a documented operational handover align platform, security, and application teams.

Asset: [/migration/assetcontainer/stackit/managed-landing-zone-service/#overview](/migration/assetcontainer/stackit/managed-landing-zone-service/#overview) — source: [/raw/migration/assetcontainer/stackit/managed-landing-zone-service.md](/raw/migration/assetcontainer/stackit/managed-landing-zone-service.md), section `#overview`

### 29. Define the Managed Service Scope

Present the service scope: target design and rollout planning, catalog-based implementation, OpenTofu and Terragrunt enablement, and documented operational handover.

Asset: [/migration/assetcontainer/stackit/managed-landing-zone-service/#service-scope](/migration/assetcontainer/stackit/managed-landing-zone-service/#service-scope) — source: [/raw/migration/assetcontainer/stackit/managed-landing-zone-service.md](/raw/migration/assetcontainer/stackit/managed-landing-zone-service.md), section `#service-scope`

### 30. Review Managed Service Outcomes

Show the intended outcomes: a governed platform baseline, reusable automation conventions, earlier migration readiness, and lower delivery risk through aligned platform, security, and application teams.

Asset: [/migration/assetcontainer/stackit/managed-landing-zone-service/#typical-outcomes](/migration/assetcontainer/stackit/managed-landing-zone-service/#typical-outcomes) — source: [/raw/migration/assetcontainer/stackit/managed-landing-zone-service.md](/raw/migration/assetcontainer/stackit/managed-landing-zone-service.md), section `#typical-outcomes`

### 31. Select an Engagement Model

Position the service as either a focused landing-zone setup initiative or a delivery stream within a broader migration factory, delivered jointly with platform, security, and application stakeholders.

Asset: [/migration/assetcontainer/stackit/managed-landing-zone-service/#engagement-model](/migration/assetcontainer/stackit/managed-landing-zone-service/#engagement-model) — source: [/raw/migration/assetcontainer/stackit/managed-landing-zone-service.md](/raw/migration/assetcontainer/stackit/managed-landing-zone-service.md), section `#engagement-model`

### 32. meshStack Simplifies Landing Zone Management

Stage: `rocket`

### 33. Deliver Projects and Networks Through Self-Service

Stage: `summit`

