AWS¶
Summary
Amazon Web Services (AWS) is Amazon's public cloud: 39 launched Regions and 123 Availability Zones as of 2026-06. This topic covers how to lay out AWS for real projects. It runs from a single account with one VPC, through multi-VPC networking (Transit Gateway, Cloud WAN, PrivateLink, VPC Lattice) and multi-Region DR, up to enterprise landing zones built with AWS Organizations, AWS Control Tower, IAM Identity Center, and organization policies (SCPs, RCPs, declarative policies).
Key Facts¶
| Attribute | Detail |
|---|---|
| Provider | Amazon Web Services, Inc. (Amazon.com subsidiary) |
| Footprint | 39 Regions, 123 AZs, 43 Local Zones (as of 2026-06). Saudi Arabia and Chile Regions announced for late 2026. AWS European Sovereign Cloud GA 2026-01-15 as a separate partition |
| Latest Version (date) | Not a versioned product. Tooling: AWS CLI v2 2.37.3 (2026-09). Terraform provider hashicorp/aws 6.66.0 (2026-09-21). AWS CDK 2.270.0 (2026-09-17). Control Tower landing zone 4.0 (2025-11-17) |
| Licensing | Proprietary cloud services. AWS CLI, CDK, and SDKs are Apache-2.0 |
| Pricing model | Pay as you go, plus Savings Plans and Reserved Instances. Organizations, Control Tower, IAM, and IAM Identity Center have no extra charge. Public IPv4 costs $0.005/hour per address since 2024-02-01 |
| Governance stack | AWS Organizations (SCPs, RCPs, declarative and management policies), AWS Control Tower, IAM Identity Center |
| Network stack | VPC, Transit Gateway, Cloud WAN, VPC peering, PrivateLink, VPC Lattice, Direct Connect, Site-to-Site VPN |
| IaC | CloudFormation, AWS CDK, Terraform/OpenTofu (hashicorp/aws), Pulumi, Landing Zone Accelerator 1.15.5 (2026-06-02) |
Full version, quota, and price tables are in Reference.
Architecture at a Glance¶
A typical enterprise landing zone: governance in the management account, security accounts that collect logs and findings, a Network account that owns the hub, and workload accounts that attach to it.
flowchart LR
subgraph Mgmt["Management account"]
ORG["Organizations + Control Tower<br/>SCP, RCP, declarative policies"]
IDC["IAM Identity Center"]
end
subgraph Sec["Security OU"]
LOG["Log Archive"]
AUD["Audit: GuardDuty, Security Hub"]
end
subgraph Net["Network account"]
HUB["Transit Gateway / Cloud WAN"]
NFW["Network Firewall"]
DX["Direct Connect"]
end
subgraph Wl["Workload accounts"]
P["prod VPCs"]
D["dev VPCs"]
end
ORG -->|"policies"| Wl
IDC -->|"permission sets"| Wl
P <--> HUB
D <--> HUB
HUB <--> NFW
HUB <--> DX
Wl -->|"CloudTrail, Config, findings"| Sec
Architecture Patterns at a Glance¶
| Pattern | Scope | Complexity | Typical Use Case |
|---|---|---|---|
| Single Account + Single VPC | One account, one VPC | Low | Small teams, prototypes, single-application workloads |
| Multi-VPC (Transit Gateway) | Hub-and-spoke via TGW | Medium-High | Enterprise with central networking, multi-team isolation |
| Multi-VPC (Cloud WAN) | Policy-defined global network | High | Three or more Regions, segmentation as code |
| Multi-VPC (VPC Peering) | Peer-to-peer VPC connections | Medium | Small number of VPCs (2-4) with simple connectivity |
| AWS PrivateLink | Service-oriented private access | Medium | Consuming or producing services privately across VPC or account boundaries |
| VPC Lattice | Application service network | Medium | Service-to-service (HTTP/gRPC/TCP) across accounts with IAM auth policies |
| Multi-Account + Organizations | OU tree with SCPs and RCPs | High | Large enterprises and regulated environments |
| Multi-AZ / Multi-Region | Cross-zone and cross-Region deployments | High | Production workloads that need HA and DR |
| DR: Backup & Restore | Backup to secondary Region | Low | Cost-optimized DR, tolerates day-level downtime |
| DR: Pilot Light | Minimal core in secondary Region | Medium | Cost-conscious orgs. Hours-level RTO |
| DR: Warm Standby | Scaled-down full replica | Medium-High | Most enterprises. Minutes-level RTO/RPO |
| DR: Active-Active | Full duplicate in several Regions | Very High | Mission-critical apps that need near-zero downtime |
| DMZ / Network Perimeter | Defense in depth with AWS Network Firewall | Medium | Regulated environments with inspection requirements |
| AWS Landing Zone | Org-wide foundation via Control Tower | Very High | Greenfield enterprise adoption of AWS |
Each pattern is explained, with diagrams, in Explanation.
What Changed in 2024-2026¶
| Date | Change |
|---|---|
| 2024-11-13 | Resource control policies (RCPs): resource-side guardrails for data perimeters |
| 2024-11 | Centralized root access: remove member-account root credentials, run short root sessions |
| 2024-12-01 | Declarative policies (EC2, VPC, EBS configuration enforced org-wide) |
| 2024-12 | VPC Lattice / PrivateLink resource configurations (TCP resources such as RDS) |
| 2025-06 / 2025-07 | Network Firewall native Transit Gateway attachment (all Regions from July) |
| 2025-06-30 | DynamoDB global tables multi-Region strong consistency GA (RPO 0) |
| 2025-09-19 | SCPs support the full IAM policy language |
| 2025-11-17 | Control Tower landing zone 4.0: optional integrations, no fixed OU layout, controls-only mode |
| 2025-11-20 | Regional NAT gateway and Cloud WAN routing policy |
| 2025-12-02 | Security Hub renamed Security Hub CSPM. A new unified AWS Security Hub went GA |
| 2026-01-15 | AWS European Sovereign Cloud GA (Brandenburg) |
| 2026-02-03 | IAM Identity Center multi-Region replication GA |
| 2026-05 | SCP quotas doubled: 10 SCPs per node, 10,240 characters each |
| 2026-07-15 | AWS CLI v1 entered maintenance mode (end of support 2027-07-15) |
| 2026-09-30 | AWS App Mesh end of support. Proton follows on 2026-10-07 and Pinpoint on 2026-10-30 |
The full lifecycle table is in Reference.
Key AWS Services¶
Networking¶
- VPC -- isolated virtual network with custom CIDR, subnets, route tables
- Transit Gateway (TGW) -- regional hub for connecting VPCs, VPNs, and Direct Connect
- AWS Cloud WAN -- managed global WAN defined by a core network policy
- VPC Peering -- direct peer-to-peer connection between two VPCs
- AWS PrivateLink -- service-oriented private connectivity through VPC endpoints
- Amazon VPC Lattice -- application-layer service network across VPCs and accounts
- NAT Gateway -- managed outbound NAT for private resources (zonal, or regional since 2025-11)
- Direct Connect -- dedicated physical connection to on-premises
- AWS Site-to-Site VPN -- IPsec VPN over the internet
- Elastic Load Balancing -- ALB (L7), NLB (L4), GWLB (L3 appliances)
- Route 53 -- managed DNS with health-check-based routing and failover
- Global Accelerator -- anycast acceleration for global user access
- AWS Network Firewall -- managed stateful L3-L7 inspection
Security¶
- AWS WAF -- web application firewall for ALB, CloudFront, API Gateway, and more
- AWS Shield -- DDoS protection (Standard is free. Advanced is paid)
- AWS Firewall Manager -- central firewall policy management across accounts
- Security Groups -- stateful per-ENI firewall
- Network ACLs -- stateless subnet-level packet filter
- Route 53 Resolver DNS Firewall -- outbound DNS filtering
Compute and Orchestration¶
- EC2 -- VMs with Auto Scaling groups for cross-AZ HA
- EKS -- managed Kubernetes
- ECS / Fargate -- managed container orchestration (ECS Express Mode is the App Runner successor)
- Lambda -- serverless functions
Data¶
- RDS -- managed relational DB with Multi-AZ and cross-Region read replicas
- Aurora -- MySQL/PostgreSQL-compatible, with Global Database for cross-Region replication
- DynamoDB -- NoSQL with Global Tables for multi-Region multi-active replication
- S3 -- object storage with Cross-Region Replication (CRR)
- ElastiCache -- managed Valkey, Redis OSS, and Memcached, with Global Datastore
Management and Governance¶
- AWS Organizations -- multi-account tree with OUs, SCPs, RCPs, and declarative policies
- AWS Control Tower -- landing zone automation with managed controls and Account Factory
- IAM Identity Center -- central workforce identity and SSO across accounts
- CloudTrail -- API audit logging
- AWS Config -- configuration compliance tracking
- Security Hub CSPM / Security Hub -- posture checks and correlated security findings
- GuardDuty -- threat detection
Evaluation¶
Strengths¶
- The broadest service catalog and Region footprint of the hyperscalers, with at least three AZs in every Region.
- The most complete multi-account governance toolkit. Organizations has three preventive policy layers (SCP for principals, RCP for resources, declarative for configuration) plus management policies.
- Several network building blocks for each scale: peering for small setups, Transit Gateway for regional hubs, Cloud WAN for global segmentation, and PrivateLink or VPC Lattice when you need services rather than networks.
- A mature IaC ecosystem: CloudFormation, CDK, and a Terraform provider with weekly releases.
Weaknesses and Trade-offs¶
- Network costs add up: TGW and Cloud WAN charge per attachment-hour plus $0.02/GB, NAT gateways charge $0.045/GB, and every public IPv4 address is billed. Look at data paths early (Reference).
- Many overlapping options (TGW vs Cloud WAN, PrivateLink vs Lattice, Security Hub vs Security Hub CSPM) make designs hard to choose. The service portfolio also changes. Several services went to maintenance or end of support in 2025-2026.
- Regional services (VPC, TGW, Lattice, Identity Center's primary Region) mean multi-Region designs need explicit replication and failover work.
- Lock-in: IAM, Organizations policies, and managed data services have no portable equivalent.
When It Fits¶
| Situation | Starting point |
|---|---|
| One team, one app | Single account + single VPC. Move to multi-account before production |
| Several teams or environments | Organizations + Control Tower landing zone. One account per team and environment |
| Many VPCs in one or two Regions | Transit Gateway hub in a Network account, shared with RAM |
| Three or more Regions | Cloud WAN with segments |
| Service-to-service across accounts | VPC Lattice (HTTP/gRPC/TCP) or PrivateLink (single service) |
| Regulated data | Landing zone + RCP data perimeter + central inspection + Security Hub CSPM standards |
Real-World Examples¶
| Scenario | Pattern(s) Used |
|---|---|
| Startup running a monolithic web app | Single Account + Single VPC |
| Mid-size SaaS company with 10+ microservices teams | Transit Gateway hub-spoke, multi-account per team |
| Large bank migrating to AWS with regulatory requirements | Full landing zone: Control Tower, SCPs, RCPs, Network Firewall, GuardDuty |
| E-commerce platform needing 99.99% uptime | Multi-AZ with ALB, Aurora Multi-AZ, Warm Standby DR |
| Global payments processor | Active-Active multi-Region with DynamoDB Global Tables, Global Accelerator |
| Manufacturing company with an on-premises data center | Transit Gateway + Direct Connect + Pilot Light DR |
Topic Map¶
- How-to Guides -- enable RCPs and declarative policies, create SCPs, centralize root access, upgrade Control Tower, share a TGW with RAM, Identity Center assignments, CLI recipes, monitoring, troubleshooting.
- Reference -- footprint, tooling versions, Organizations policy types and quotas, Control Tower 4.0 changes, TGW quotas, connectivity matrix, prices, HA/DR figures, service lifecycle changes, naming table, identity and encryption tables, landing zone checklist.
- Explanation -- how the layers fit, each network option (TGW, peering, PrivateLink, Cloud WAN, VPC Lattice), multi-account design and the SCP/RCP/declarative policy model, multi-Region and DR, perimeter design, landing zones, and the security model.
Related Topics¶
- Same domain: Google Cloud, Alibaba Cloud, Multi-Cloud Governance, Kubernetes, Infrastructure comparisons
- Comparison: Public Cloud Landing Zones (AWS vs Google Cloud vs Alibaba Cloud vs Tencent Cloud)
- IaC: Terraform, OpenTofu, Pulumi
- Secrets: HashiCorp Vault
- Kubernetes networking on EKS: Cilium, Calico
Sources¶
- AWS Regions and Availability Zones
- AWS Control Tower: multi-account strategy
- AWS Control Tower: key changes in landing zone 4.0
- AWS Landing Zone (Prescriptive Guidance)
- Organizing Your AWS Environment Using Multiple Accounts
- AWS Organizations: managing organization policies
- Introducing resource control policies (RCPs)
- AWS declarative policies launch
- AWS Organizations higher SCP quotas (2026-05)
- IAM Identity Center multi-Region replication
- Transit Gateway design best practices
- Transit Gateway quotas
- Building a Scalable and Secure Multi-VPC Network Infrastructure
- AWS VPC Connectivity Options
- AWS Cloud WAN routing policy
- Disaster Recovery Options in the Cloud
- DR Architecture Part III: Pilot Light and Warm Standby
- DR Architecture Part IV: Multi-site Active/Active
- Well-Architected Reliability Pillar: DR strategies
- Aurora Global Database
- DynamoDB Global Tables
- Network Firewall best practices
- Deployment models for AWS Network Firewall
- AWS Lifecycle Changes
- AWS Service Availability Updates (2026-03)
- AWS CLI v2 CHANGELOG
- Terraform AWS provider CHANGELOG
Questions¶
- How does Control Tower 4.0's optional-integration model change the case for Landing Zone Accelerator versus a plain Control Tower + AFT setup?
- Which services does the RCP list cover as of late 2026, and which data-perimeter gaps (services without RCP support) still need VPC endpoint policies or SCPs?
- What is the cost difference between Pilot Light, Warm Standby, and Active-Active DR for a typical three-tier web app on AWS?
- At what number of Regions and attachments does Cloud WAN become cheaper to operate than TGW inter-Region peering, once the $0.50/hour edge charge is included?
- How do Aurora Global Database switchover and DynamoDB multi-Region strong consistency compare in latency and operational complexity?
- How does AWS Control Tower's control model compare to Alibaba Cloud Governance Center's control policies in coverage and flexibility?