EAOT
Patterns / Cloud Architecture

Cloud Migration

Landing zone first, workload waves second — with guardrails encoded rather than documented.

Landing Zone
Guardrails as Code
Wave 1
Wave n
Run & FinOps

Conceptual flow

Problem

Workload-by-workload migration without a landing zone produces inconsistent security, network, and cost postures.

Context

Enterprises moving regulated workloads into public or hybrid cloud under audit scrutiny.

Solution

Establish identity, network, logging, and policy guardrails as code in a landing zone, then migrate workloads in dependency-aware waves with explicit exit criteria.

Benefits

  • Consistent controls
  • Predictable cost model
  • Repeatable wave execution

Risks

  • Landing zone over-engineering
  • Latency to on-premise dependencies
  • Cost drift after go-live

Trade-offs

  • Upfront platform work before first workload value

When to use

  • Regulated estates
  • Multi-team migration at scale

When not to use

  • A single isolated workload
  • Short-lived environments

Discuss this pattern

How have you applied it — and where did it break? Bring your experience to the community.

Open the discussion