Skip to content

AWS

Summary

Amazon Web Services (AWS) is Amazon's public cloud: 39 launched Regions and 123 Availability Zones as of 2026-06. This topic covers how to lay out AWS for real projects. It runs from a single account with one VPC, through multi-VPC networking (Transit Gateway, Cloud WAN, PrivateLink, VPC Lattice) and multi-Region DR, up to enterprise landing zones built with AWS Organizations, AWS Control Tower, IAM Identity Center, and organization policies (SCPs, RCPs, declarative policies).

Key Facts

Attribute Detail
Provider Amazon Web Services, Inc. (Amazon.com subsidiary)
Footprint 39 Regions, 123 AZs, 43 Local Zones (as of 2026-06). Saudi Arabia and Chile Regions announced for late 2026. AWS European Sovereign Cloud GA 2026-01-15 as a separate partition
Latest Version (date) Not a versioned product. Tooling: AWS CLI v2 2.37.3 (2026-09). Terraform provider hashicorp/aws 6.66.0 (2026-09-21). AWS CDK 2.270.0 (2026-09-17). Control Tower landing zone 4.0 (2025-11-17)
Licensing Proprietary cloud services. AWS CLI, CDK, and SDKs are Apache-2.0
Pricing model Pay as you go, plus Savings Plans and Reserved Instances. Organizations, Control Tower, IAM, and IAM Identity Center have no extra charge. Public IPv4 costs $0.005/hour per address since 2024-02-01
Governance stack AWS Organizations (SCPs, RCPs, declarative and management policies), AWS Control Tower, IAM Identity Center
Network stack VPC, Transit Gateway, Cloud WAN, VPC peering, PrivateLink, VPC Lattice, Direct Connect, Site-to-Site VPN
IaC CloudFormation, AWS CDK, Terraform/OpenTofu (hashicorp/aws), Pulumi, Landing Zone Accelerator 1.15.5 (2026-06-02)

Full version, quota, and price tables are in Reference.

Architecture at a Glance

A typical enterprise landing zone: governance in the management account, security accounts that collect logs and findings, a Network account that owns the hub, and workload accounts that attach to it.

flowchart LR
    subgraph Mgmt["Management account"]
        ORG["Organizations + Control Tower<br/>SCP, RCP, declarative policies"]
        IDC["IAM Identity Center"]
    end
    subgraph Sec["Security OU"]
        LOG["Log Archive"]
        AUD["Audit: GuardDuty, Security Hub"]
    end
    subgraph Net["Network account"]
        HUB["Transit Gateway / Cloud WAN"]
        NFW["Network Firewall"]
        DX["Direct Connect"]
    end
    subgraph Wl["Workload accounts"]
        P["prod VPCs"]
        D["dev VPCs"]
    end
    ORG -->|"policies"| Wl
    IDC -->|"permission sets"| Wl
    P <--> HUB
    D <--> HUB
    HUB <--> NFW
    HUB <--> DX
    Wl -->|"CloudTrail, Config, findings"| Sec

Architecture Patterns at a Glance

Pattern Scope Complexity Typical Use Case
Single Account + Single VPC One account, one VPC Low Small teams, prototypes, single-application workloads
Multi-VPC (Transit Gateway) Hub-and-spoke via TGW Medium-High Enterprise with central networking, multi-team isolation
Multi-VPC (Cloud WAN) Policy-defined global network High Three or more Regions, segmentation as code
Multi-VPC (VPC Peering) Peer-to-peer VPC connections Medium Small number of VPCs (2-4) with simple connectivity
AWS PrivateLink Service-oriented private access Medium Consuming or producing services privately across VPC or account boundaries
VPC Lattice Application service network Medium Service-to-service (HTTP/gRPC/TCP) across accounts with IAM auth policies
Multi-Account + Organizations OU tree with SCPs and RCPs High Large enterprises and regulated environments
Multi-AZ / Multi-Region Cross-zone and cross-Region deployments High Production workloads that need HA and DR
DR: Backup & Restore Backup to secondary Region Low Cost-optimized DR, tolerates day-level downtime
DR: Pilot Light Minimal core in secondary Region Medium Cost-conscious orgs. Hours-level RTO
DR: Warm Standby Scaled-down full replica Medium-High Most enterprises. Minutes-level RTO/RPO
DR: Active-Active Full duplicate in several Regions Very High Mission-critical apps that need near-zero downtime
DMZ / Network Perimeter Defense in depth with AWS Network Firewall Medium Regulated environments with inspection requirements
AWS Landing Zone Org-wide foundation via Control Tower Very High Greenfield enterprise adoption of AWS

Each pattern is explained, with diagrams, in Explanation.

What Changed in 2024-2026

Date Change
2024-11-13 Resource control policies (RCPs): resource-side guardrails for data perimeters
2024-11 Centralized root access: remove member-account root credentials, run short root sessions
2024-12-01 Declarative policies (EC2, VPC, EBS configuration enforced org-wide)
2024-12 VPC Lattice / PrivateLink resource configurations (TCP resources such as RDS)
2025-06 / 2025-07 Network Firewall native Transit Gateway attachment (all Regions from July)
2025-06-30 DynamoDB global tables multi-Region strong consistency GA (RPO 0)
2025-09-19 SCPs support the full IAM policy language
2025-11-17 Control Tower landing zone 4.0: optional integrations, no fixed OU layout, controls-only mode
2025-11-20 Regional NAT gateway and Cloud WAN routing policy
2025-12-02 Security Hub renamed Security Hub CSPM. A new unified AWS Security Hub went GA
2026-01-15 AWS European Sovereign Cloud GA (Brandenburg)
2026-02-03 IAM Identity Center multi-Region replication GA
2026-05 SCP quotas doubled: 10 SCPs per node, 10,240 characters each
2026-07-15 AWS CLI v1 entered maintenance mode (end of support 2027-07-15)
2026-09-30 AWS App Mesh end of support. Proton follows on 2026-10-07 and Pinpoint on 2026-10-30

The full lifecycle table is in Reference.

Key AWS Services

Networking

  • VPC -- isolated virtual network with custom CIDR, subnets, route tables
  • Transit Gateway (TGW) -- regional hub for connecting VPCs, VPNs, and Direct Connect
  • AWS Cloud WAN -- managed global WAN defined by a core network policy
  • VPC Peering -- direct peer-to-peer connection between two VPCs
  • AWS PrivateLink -- service-oriented private connectivity through VPC endpoints
  • Amazon VPC Lattice -- application-layer service network across VPCs and accounts
  • NAT Gateway -- managed outbound NAT for private resources (zonal, or regional since 2025-11)
  • Direct Connect -- dedicated physical connection to on-premises
  • AWS Site-to-Site VPN -- IPsec VPN over the internet
  • Elastic Load Balancing -- ALB (L7), NLB (L4), GWLB (L3 appliances)
  • Route 53 -- managed DNS with health-check-based routing and failover
  • Global Accelerator -- anycast acceleration for global user access
  • AWS Network Firewall -- managed stateful L3-L7 inspection

Security

  • AWS WAF -- web application firewall for ALB, CloudFront, API Gateway, and more
  • AWS Shield -- DDoS protection (Standard is free. Advanced is paid)
  • AWS Firewall Manager -- central firewall policy management across accounts
  • Security Groups -- stateful per-ENI firewall
  • Network ACLs -- stateless subnet-level packet filter
  • Route 53 Resolver DNS Firewall -- outbound DNS filtering

Compute and Orchestration

  • EC2 -- VMs with Auto Scaling groups for cross-AZ HA
  • EKS -- managed Kubernetes
  • ECS / Fargate -- managed container orchestration (ECS Express Mode is the App Runner successor)
  • Lambda -- serverless functions

Data

  • RDS -- managed relational DB with Multi-AZ and cross-Region read replicas
  • Aurora -- MySQL/PostgreSQL-compatible, with Global Database for cross-Region replication
  • DynamoDB -- NoSQL with Global Tables for multi-Region multi-active replication
  • S3 -- object storage with Cross-Region Replication (CRR)
  • ElastiCache -- managed Valkey, Redis OSS, and Memcached, with Global Datastore

Management and Governance

  • AWS Organizations -- multi-account tree with OUs, SCPs, RCPs, and declarative policies
  • AWS Control Tower -- landing zone automation with managed controls and Account Factory
  • IAM Identity Center -- central workforce identity and SSO across accounts
  • CloudTrail -- API audit logging
  • AWS Config -- configuration compliance tracking
  • Security Hub CSPM / Security Hub -- posture checks and correlated security findings
  • GuardDuty -- threat detection

Evaluation

Strengths

  • The broadest service catalog and Region footprint of the hyperscalers, with at least three AZs in every Region.
  • The most complete multi-account governance toolkit. Organizations has three preventive policy layers (SCP for principals, RCP for resources, declarative for configuration) plus management policies.
  • Several network building blocks for each scale: peering for small setups, Transit Gateway for regional hubs, Cloud WAN for global segmentation, and PrivateLink or VPC Lattice when you need services rather than networks.
  • A mature IaC ecosystem: CloudFormation, CDK, and a Terraform provider with weekly releases.

Weaknesses and Trade-offs

  • Network costs add up: TGW and Cloud WAN charge per attachment-hour plus $0.02/GB, NAT gateways charge $0.045/GB, and every public IPv4 address is billed. Look at data paths early (Reference).
  • Many overlapping options (TGW vs Cloud WAN, PrivateLink vs Lattice, Security Hub vs Security Hub CSPM) make designs hard to choose. The service portfolio also changes. Several services went to maintenance or end of support in 2025-2026.
  • Regional services (VPC, TGW, Lattice, Identity Center's primary Region) mean multi-Region designs need explicit replication and failover work.
  • Lock-in: IAM, Organizations policies, and managed data services have no portable equivalent.

When It Fits

Situation Starting point
One team, one app Single account + single VPC. Move to multi-account before production
Several teams or environments Organizations + Control Tower landing zone. One account per team and environment
Many VPCs in one or two Regions Transit Gateway hub in a Network account, shared with RAM
Three or more Regions Cloud WAN with segments
Service-to-service across accounts VPC Lattice (HTTP/gRPC/TCP) or PrivateLink (single service)
Regulated data Landing zone + RCP data perimeter + central inspection + Security Hub CSPM standards

Real-World Examples

Scenario Pattern(s) Used
Startup running a monolithic web app Single Account + Single VPC
Mid-size SaaS company with 10+ microservices teams Transit Gateway hub-spoke, multi-account per team
Large bank migrating to AWS with regulatory requirements Full landing zone: Control Tower, SCPs, RCPs, Network Firewall, GuardDuty
E-commerce platform needing 99.99% uptime Multi-AZ with ALB, Aurora Multi-AZ, Warm Standby DR
Global payments processor Active-Active multi-Region with DynamoDB Global Tables, Global Accelerator
Manufacturing company with an on-premises data center Transit Gateway + Direct Connect + Pilot Light DR

Topic Map

  • How-to Guides -- enable RCPs and declarative policies, create SCPs, centralize root access, upgrade Control Tower, share a TGW with RAM, Identity Center assignments, CLI recipes, monitoring, troubleshooting.
  • Reference -- footprint, tooling versions, Organizations policy types and quotas, Control Tower 4.0 changes, TGW quotas, connectivity matrix, prices, HA/DR figures, service lifecycle changes, naming table, identity and encryption tables, landing zone checklist.
  • Explanation -- how the layers fit, each network option (TGW, peering, PrivateLink, Cloud WAN, VPC Lattice), multi-account design and the SCP/RCP/declarative policy model, multi-Region and DR, perimeter design, landing zones, and the security model.

Sources

Questions

  • How does Control Tower 4.0's optional-integration model change the case for Landing Zone Accelerator versus a plain Control Tower + AFT setup?
  • Which services does the RCP list cover as of late 2026, and which data-perimeter gaps (services without RCP support) still need VPC endpoint policies or SCPs?
  • What is the cost difference between Pilot Light, Warm Standby, and Active-Active DR for a typical three-tier web app on AWS?
  • At what number of Regions and attachments does Cloud WAN become cheaper to operate than TGW inter-Region peering, once the $0.50/hour edge charge is included?
  • How do Aurora Global Database switchover and DynamoDB multi-Region strong consistency compare in latency and operational complexity?
  • How does AWS Control Tower's control model compare to Alibaba Cloud Governance Center's control policies in coverage and flexibility?