Context · Insurance tech · Germany

Terraform landing zone for insurance workloads

Built a reusable landing zone with logging, network, and IAM baselines so product teams could ship without reinventing security each sprint.

accounts under one LZ
3

accounts under one LZ

assessment to plan
1 wk

assessment to plan

Challenge

An insurance-technology provider needed new product accounts without copying VPC templates by hand each sprint. Auditors wanted consistent logging and IAM; developers wanted a paved path that did not block releases.

Approach

One-week assessment turned into a written landing-zone plan: account vending, network hub, central logging and IAM roles product teams inherit by default.

Implemented entirely in Terraform with reviewable modules and remote state - no click-ops foundation.

Onboarded three accounts through the same pipeline, with documentation aimed at internal platform engineers, not a black-box handoff.

Outcome

Three accounts now share one landing zone; new environments follow the same guardrails. Product teams ship into approved patterns instead of reinventing security every sprint.

FAQ

Which cloud provider?

This engagement centred on AWS Organizations patterns; the same Terraform-first approach applies to Azure and GCP landing zones when needed.

Did you migrate legacy workloads?

Scope was foundation and onboarding for new accounts. Legacy migration was planned as a follow-on phase with separate acceptance criteria.