AWS Organizations Landing Zone from scratch
Designing a secure multi-account structure for a mid-size fintech — Control Tower, SCPs, centralized logging and network isolation between prod, staging and sandbox.
Landing zones, multi-region patterns, security blueprints.
— documented from production engagements across AWS, Azure and GCP.
Designing a secure multi-account structure for a mid-size fintech — Control Tower, SCPs, centralized logging and network isolation between prod, staging and sandbox.
Full FinOps audit of a 200k€/month AWS workload — rightsizing EC2, migrating to Graviton, Reserved Instances strategy and Spot for batch workloads.
Replacing flat VPC peering with a zero-trust model — AWS Network Firewall, PrivateLink, IAM Identity Center and GuardDuty for a HDS-certified healthcare workload.
200+ VMs migrated over 6 months with zero business interruption — Azure Migrate, ASR for coexistence, ExpressRoute for the cutover window and Azure Policy for governance.
End-to-end lakehouse built on ADLS Gen2, Databricks Unity Catalog and Azure Purview — ingesting 50+ sources, enforcing data contracts and serving BI teams in near real time.
Full GitOps pipeline for 12 dev teams — Terraform for AKS clusters, Flux CD for app delivery, Azure Key Vault for secrets and OPA Gatekeeper for policy enforcement.
End-to-end streaming platform processing 2M events/day — Pub/Sub → Dataflow → BigQuery, with Looker Studio dashboards refreshed every 90 seconds for operations teams.
Scoping and deploying an Assured Workloads environment to meet French data residency requirements — VPC Service Controls, CMEK, Access Transparency and Cloud Armor.
Active-active setup across europe-west1 and europe-west4 — GKE Autopilot, Cloud Spanner for global consistency, Global Load Balancer with health-based failover under 30 seconds.
Full write-ups with diagrams and decision logs are being assembled.
Want to discuss a specific architecture challenge? Get in touch.