---
title: "Enterprise Cloud Onboarding Blueprint"
description: Standardized multi-layer blueprint guiding product teams through secure, compliant platform onboarding into localized STACKIT environments and Network Areas.
scfTrail:
  tags: ["wip"]
  maintainers:
    - user: "tobias.mueller"
  steps:
    - style: "compass"
      title: "Strategic Alignment & Maturity"
      id: "strategic-alignment"
      trailContext: "Every successful project journey starts with a maturity check. Product teams use our automated assessment to map their target application architecture against organizational cloud compliance guidelines."
      description: "Includes initial assessment questionnaires, team mapping templates, and kick-off workshop assets."
    
    - style: "hut"
      title: "Understand the Two Landing-Zone Layers"
      id: "landing-zone-layers"
      trailContext: "Before provisioning starts, teams align on the split between the platform landing zone (organization-wide guardrails, connectivity, identity) and the application landing zone their workload will live in."
      pageId: "migration/design-and-mobilize/landing-zones/overview/#two-layers-platform-and-application-landing-zones"

    - style: "hut"
      title: "Basecamp: Platform Provisioning"
      id: "platform-provisioning"
      trailContext: "Once aligned, we automatically provision a dedicated project environment inside the Central Hub & Spoke network topology. Secure landing zone boundaries, enterprise IAM patterns, and core network configurations apply instantly."
      assetId: "migration/assetcontainer/stackit/landing-zone-foundation-opentofu"

    - style: "shield"
      title: "Governance & Guardrails Scan"
      id: "guardrails-scan"
      trailContext: "Before any deployment happens, our automated checkpoint scans the infrastructure baseline. This ensures that the newly created space strictly adheres to sovereign cloud guidelines and BSI C5 security baselines."
      assetId: "architecture/assetcontainer/open-contributors/tm2-security-big-picture#4-reference-matrix"

    - style: "gondola"
      title: "Continuous Delivery Automation"
      id: "cd-automation"
      trailContext: "Connecting your workspace to the centralized CI/CD infrastructure. Secure repository mirroring, dynamic runner registration, and enterprise Helm delivery blueprints are configured out-of-the-box."

    - style: "rocket"
      title: "Container Platform Bootstrapping"
      id: "container-bootstrap"
      trailContext: "The final milestone of the technical onboarding journey: standing up your cluster. Applications are deployed onto fully managed, highly available container runtimes controlled with continuous GitOps reconciliation."
      assetId: "migration/assetcontainer/stackit/replatform-automation-spring-boot-vm-to-kubernetes-terraform"
  presentations:
    - id: exec
      label: "Executive overview"
      description: "Executive framing: headline steps in the agenda, technical detail nested or off-agenda."
      steps:
        - strategic-alignment
        - { id: landing-zone-layers, role: sub }
        - platform-provisioning
        - guardrails-scan
        - cd-automation
        - { id: container-bootstrap, role: hidden }
    - id: technical
      label: "Technical deep-dive"
      description: "Implementation-focused view: technical steps as agenda headlines, strategy nested."
      steps:
        - { id: strategic-alignment, role: sub }
        - landing-zone-layers
        - platform-provisioning
        - guardrails-scan
        - cd-automation
        - container-bootstrap
source_url: "https://framework.stackit.cloud/migration/trails/tm/cloud-onboarding-journey/"
source_file: "docs/migration/trails/tm/cloud-onboarding-journey.mdx"
---

## Steps

### 1. Strategic Alignment & Maturity

Stage: `compass`

Every successful project journey starts with a maturity check. Product teams use our automated assessment to map their target application architecture against organizational cloud compliance guidelines.

Includes initial assessment questionnaires, team mapping templates, and kick-off workshop assets.

### 2. Understand the Two Landing-Zone Layers

Stage: `hut`

Before provisioning starts, teams align on the split between the platform landing zone (organization-wide guardrails, connectivity, identity) and the application landing zone their workload will live in.

Page: [/migration/design-and-mobilize/landing-zones/overview/#two-layers-platform-and-application-landing-zones](/migration/design-and-mobilize/landing-zones/overview/#two-layers-platform-and-application-landing-zones) — source: [/raw/migration/design-and-mobilize/landing-zones/overview.md](/raw/migration/design-and-mobilize/landing-zones/overview.md), section `#two-layers-platform-and-application-landing-zones`

### 3. Basecamp: Platform Provisioning

Stage: `hut`

Once aligned, we automatically provision a dedicated project environment inside the Central Hub & Spoke network topology. Secure landing zone boundaries, enterprise IAM patterns, and core network configurations apply instantly.

Asset: [/migration/assetcontainer/stackit/landing-zone-foundation-opentofu/](/migration/assetcontainer/stackit/landing-zone-foundation-opentofu/) — source: [/raw/migration/assetcontainer/stackit/landing-zone-foundation-opentofu.md](/raw/migration/assetcontainer/stackit/landing-zone-foundation-opentofu.md)

### 4. Governance & Guardrails Scan

Stage: `shield`

Before any deployment happens, our automated checkpoint scans the infrastructure baseline. This ensures that the newly created space strictly adheres to sovereign cloud guidelines and BSI C5 security baselines.

Asset: [/architecture/assetcontainer/open-contributors/tm2-security-big-picture/#4-reference-matrix](/architecture/assetcontainer/open-contributors/tm2-security-big-picture/#4-reference-matrix) — source: [/raw/architecture/assetcontainer/open-contributors/tm2-security-big-picture.md](/raw/architecture/assetcontainer/open-contributors/tm2-security-big-picture.md), section `#4-reference-matrix`

### 5. Continuous Delivery Automation

Stage: `gondola`

Connecting your workspace to the centralized CI/CD infrastructure. Secure repository mirroring, dynamic runner registration, and enterprise Helm delivery blueprints are configured out-of-the-box.

### 6. Container Platform Bootstrapping

Stage: `rocket`

The final milestone of the technical onboarding journey: standing up your cluster. Applications are deployed onto fully managed, highly available container runtimes controlled with continuous GitOps reconciliation.

Asset: [/migration/assetcontainer/stackit/replatform-automation-spring-boot-vm-to-kubernetes-terraform/](/migration/assetcontainer/stackit/replatform-automation-spring-boot-vm-to-kubernetes-terraform/) — source: [/raw/migration/assetcontainer/stackit/replatform-automation-spring-boot-vm-to-kubernetes-terraform.md](/raw/migration/assetcontainer/stackit/replatform-automation-spring-boot-vm-to-kubernetes-terraform.md)

