Skip to content

Scope, fee and working days are published on every engagement

CorePhysix Labs Technology lab

Specification CLD·102

CLD · Cloud & DevOps Defined scope Fixed fee

Terraform AWS Landing Zone

Your AWS environment defined in versioned Terraform with separate accounts and scoped IAM, so every infrastructure change is reviewed.

Fee · GST incl.
₹44,999
Duration
25 working days
Deliverables
7

01 Overview

Infrastructure created by clicking through a console cannot be reviewed, reproduced or changed safely. We describe your AWS footprint in Terraform: separate production and non-production accounts, a VPC whose private subnets genuinely stay private, IAM roles scoped to tasks rather than individuals, and remote state held in S3 with DynamoDB locking. Modules are designed for reuse, and a GitHub Actions plan-and-apply workflow means every change arrives as a pull request.

02 Deliverables

7 items

What you receive at handover

  1. D01 Terraform modules for IAM, VPC networking, subnets, security groups and core services
  2. D02 Multi-account layout keeping production and staging apart
  3. D03 S3 remote state with versioning and DynamoDB locking
  4. D04 GitHub Actions workflow that plans on pull request and applies on merge
  5. D05 Existing resources imported into state wherever practical
  6. D06 Documented conventions for naming, tagging and environments
  7. D07 Runbook for bootstrap, drift detection and disaster recovery

03 Outcomes

What should be true once it ships

  • No infrastructure change reaches production without review
  • Environments can be recreated from code rather than repaired by hand
  • New engineers learn the setup from the repository, not from colleagues' memories

04 Process

How the 4 stages run

  1. Discover Current resources, and how they were created, are inventoried
  2. Design We agree the account layout, the network topology and where module boundaries fall
  3. Implement Modules are written, resources imported and each environment applied
  4. Hand over Pairing sessions with your engineers, backed by written runbooks

05 Fit & inputs

A good fit for

  • Companies whose infrastructure is understood by only one person
  • Teams preparing for an audit that asks how changes get approved
  • Startups preparing to add another environment or region

What we need from you

  • Admin-level access to each AWS account included in the scope
  • A maintenance window for cutting over any shared networking
  • An engineer free to attend the handover sessions

These inputs are collected through the technical brief in your dashboard after payment. The duration is counted from when they arrive.

06 Answers

Questions about this engagement

Not from importing resources, which leaves them running. Any resource that must be recreated is scheduled with you, with a way to roll back.

We adapt established module patterns, but you receive plain Terraform rather than a wrapper only we can maintain.

Yes, built on Azure's equivalent subscription and landing zone model. Check with us before ordering so the scope can be confirmed.

This is technology work delivered digitally — nothing is shipped. Work is delivered into systems you control within the duration stated above, and the delivery and refund policies set out what happens if a date is missed.

REL Related

Often considered alongside.

All Cloud & DevOps

AWS Cost Reduction Audit

A line-by-line review of your AWS bill that returns ranked savings with rupee values and risks, so cost cuts never endanger production.

Line-by-line breakdown of three months of AWS spend

Fixed fee · GST incl.

₹12,999

Duration

6 working days

Zero-Downtime Deployment Migration

Blue-green or rolling releases with health checks and automatic rollback, so you ship in working hours without taking the product offline.

Blue-green or rolling deployment on ECS, Kubernetes or EC2

Fixed fee · GST incl.

₹29,999

Duration

14 working days

Kubernetes Cluster Hardening Sprint

Network policy, RBAC, resource limits, secrets handling and image scanning applied to a live cluster, closing its default security gaps.

Network policies that deny by default and allow only named traffic per namespace

Fixed fee · GST incl.

₹34,999

Duration

15 working days

GST included

₹44,999

Next step

Have a system that needs building, fixing or securing?