Skip to content

Multi Cloud Solutions

Enterprise and industry solutions

  • Azure
    • Azure Migration Service: Assess Hyper-V Environments
    • Azure Identity & Access Managemen
    • Azure Kubernetes Service (AKS) with Terraform deployment
    • Onboarding : Azure Infrastructure
    • Onboarding : Azure Secure APIs/Services
    • Onboarding : Azure Infrastructure deployment
    • Onboarding : Azure Configure NSG, ASG, Firewall, and Service Endpoints
    • Onboarding: Resilient and scaleable application
    • Onboarding : Azure Migration, Backup, Recovery
    • Onboarding : Azure Resource Management
    • Azure Credential Management
      • Onboarding : Azure Data Encryption
      • Onboarding : Azure Data Storages and databases
        • Azure Storage and Best Practices
    • Onboarding : Azure Compute
    • Onboarding : Azure Active Directory
    • Onboarding : Azure API Performance and secure backend
    • Onboarding : Modern Applications
    • Onboarding : Serverless and message passing architecture
    • Onboarding : Azure Access Management
  • AWS
    • AWS : IAM User
    • AWS : Virtual Private Network (VPC)
    • AWS : Resiliency
    • AWS : DynamoDB
    • AWS : Business Objectives
    • AWS : Infrastructure Deployment
    • AWS : Monitor, React, and Recover
  • GCP
  • Cloud Dev
    • Design Patterns
    • Docker, container, Kubernetes
    • Develop containerized microservices in VS
    • Develop Azure Function App in VS
    • Develop frontend for backend via Vue
    • Authentication methods
    • API Lifecycle
    • RESTful API Design
    • OAuth 2.0 and OpenID Connect
    • Secure Code Check list
    • Visual Studio Code Online
    • Terraform : Cloud
    • Using Terraform to deploy GCP services
  • Solutions
    • Bring Your Enterprise on Cloud
      • Security
        • Azure Security
        • AWS Compliance Gate Securities
        • GCP Compliance Gate Securities
    • Multi-Cloud
    • ITIL
    • Enterprise solution for API Management

Tag: Guardrail

Architecture, AWS, Azure Cloud, GCP

Clouds : Organization Structure

AzureAWSGCP
Azure PolicyGuardrails
(via the ControlTower Service)
Organization Policy Service
–Organization Service (optional)Organization Node
RootRoot Account–
Management Group (optional)Organization Unit (optional)
(via the Organization Service)
Folder (optional)
SubscriptionAccount
(via the Organization Service)
–
Resource Group–Project
ResourcesResourcesResources

Azure Policy

The following types are available:

Apply a policy to a management group.

A policy can be applied to the management group. This policy is inherited with the management group’s management groups and subscriptions.

Apply a policy to a subscription.

AWS Guardrail

The following types are available:

Apply an AWS Config to an Organization Unit via the Guardrail Service.

Apply an AWS Config to an Account via the Guardrail Service.

GCP Organization Policy

See resource hierarchy: https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy


Inheritance

When a policy is set on an organization/ top node all descendants of that node inherit this policy by default. If you set a policy at the root organization node/ root account, then the configuration of restrictions defined by that policy will be passed down through all descendant folders, projects, services, and resources.

My opinion

AWS Advantage: In some scenarios is necessary to have only one VPC for the whole organization and the projects must use this VPC but from different Accounts. It’s possible in AWS because we have cross-account shared services.

In Azure and GCP we cannot share a VPC or a VNet between two Subscriptions or Projects.


Featured PostAccount, AWS, Azure, ControlTower, GCP, Guardrail, ManagementGroup, Organization, SubscriptionLeave a comment
Blog at WordPress.com.
  • Subscribe Subscribed
    • Multi Cloud Solutions
    • Already have a WordPress.com account? Log in now.
    • Multi Cloud Solutions
    • Subscribe Subscribed
    • Sign up
    • Log in
    • Report this content
    • View site in Reader
    • Manage subscriptions
    • Collapse this bar
 

Loading Comments...