Context · Insurance tech · Germany
Terraform landing zone for insurance workloads
Built a reusable landing zone with logging, network, and IAM baselines so product teams could ship without reinventing security each sprint.
- accounts under one LZ
- 3
- assessment to plan
- 1 wk
accounts under one LZ
assessment to plan
Challenge
An insurance-technology provider needed new product accounts without copying VPC templates by hand each sprint. Auditors wanted consistent logging and IAM; developers wanted a paved path that did not block releases.
Approach
One-week assessment turned into a written landing-zone plan: account vending, network hub, central logging and IAM roles product teams inherit by default.
Implemented entirely in Terraform with reviewable modules and remote state - no click-ops foundation.
Onboarded three accounts through the same pipeline, with documentation aimed at internal platform engineers, not a black-box handoff.
Outcome
Three accounts now share one landing zone; new environments follow the same guardrails. Product teams ship into approved patterns instead of reinventing security every sprint.
FAQ
Which cloud provider?
This engagement centred on AWS Organizations patterns; the same Terraform-first approach applies to Azure and GCP landing zones when needed.
Did you migrate legacy workloads?
Scope was foundation and onboarding for new accounts. Legacy migration was planned as a follow-on phase with separate acceptance criteria.