Patterns / Cloud Architecture
Cloud Migration
Landing zone first, workload waves second — with guardrails encoded rather than documented.
Landing Zone
Guardrails as Code
Wave 1
Wave n
Run & FinOps
Conceptual flow
Problem
Workload-by-workload migration without a landing zone produces inconsistent security, network, and cost postures.
Context
Enterprises moving regulated workloads into public or hybrid cloud under audit scrutiny.
Solution
Establish identity, network, logging, and policy guardrails as code in a landing zone, then migrate workloads in dependency-aware waves with explicit exit criteria.
Benefits
- Consistent controls
- Predictable cost model
- Repeatable wave execution
Risks
- Landing zone over-engineering
- Latency to on-premise dependencies
- Cost drift after go-live
Trade-offs
- Upfront platform work before first workload value
When to use
- Regulated estates
- Multi-team migration at scale
When not to use
- A single isolated workload
- Short-lived environments
Related patterns
Discuss this pattern
How have you applied it — and where did it break? Bring your experience to the community.
Open the discussion