A landing zone is a framework that Alibaba Cloud provides for enterprises to migrate business to the cloud. Landing zones help you regulate and implement resource structures, access security, network architectures, and security compliance systems in the cloud. This way, you can create a secure, efficient, and manageable cloud environment. Cloud Governance Center provides blueprint templates that you can use to build landing zones with higher efficiency. This topic describes how to use a standard blueprint to build a landing zone.
Background information
Cloud Governance Center automatically checks whether a resource directory is created for a specified management account. If no resource directory is created for the management account, Cloud Governance Center automatically creates a resource directory for the management account.
Step 1: Configure items
Step 2: Create folders
A folder is an organizational unit in a resource directory. A folder may indicate a branch, a line of business, or a project of your enterprise. Each folder can contain member accounts and subfolders that are in a tree-shaped organizational structure. You can manage accounts and resources by using folders. For example, you can allocate resources, manage permissions, and implement security control and compliance control by using folders.
We recommend that you create the following folders based on the best practices. If the folders are not created for the management account, Cloud Governance Center automatically creates the folders.
- Core: This folder contains member accounts that are used to manage resources.
- Applications: This folder contains member accounts that are used to perform specific business operations.
In the Added Items section, click Create Folder. On the right of the page, the automatically created folders are displayed. You can change the name of each folder. If you no longer need a folder, you can delete the folder.
In addition to the Core and Applications folders, you can perform the following steps to create finer-grained folders by department or business environment: Log on to the Resource Management console, choose Resource Directory > Overview > Organization. On the left of the Organization tab, select a node and click Create Folder.
Step 3: Create core accounts.
You can create core accounts for existing functional units. This way, you can perform subsequent governance tasks. The governance tasks include resource allocation, permission management, security control, and compliance control.
Step 4: Configure protection rules
You can configure and enable the protection rules of Cloud Config in a centralized manner. This prevents the basic configurations and the resource structure that are created from being modified in Cloud Governance Center. This also ensures the security of multi-account environments.
In the Guardrails section, view protection rules and select the required protection rules. For more information about protection rules, see Configure protection rules in a centralized manner.
Step 5: Run a task to build the landing zone
- After you configure the preceding parameters, click Next: Preview. On the page that appears, check the configuration information about each item.
- After you verify the information, click Configure.
- View the status of the task and click Close after the task is completed.