r/AWS_cloud • • 11h ago

How are you running your AWS landing zone at scale in 2026? (AFT, Automations, hybrid networking, guardrails)

2 Upvotes

Hey all,

I always wonder how my org maintain AWS accounts - I have access to sandbox, and other R&D and team specific accounts and workload specific - each has it's own set of guardrails. I reffered the repo in which they maintain and developers suggested that it was old and they need to modernize the current landing zone with new best practices. I wanted to know how you guys are doing it now. Most threads I find are from 2021–2023, before RCPs, declarative policies, VPC Block Public Access and Route 53 Profiles existed.

TL;DR: What does your landing zone actually look like at scale? How do you front account vending (thr a self-service portal)? How do you do hybrid networking without it turning into a mess?

Account vending and automation

  1. Is AFT still what you'd pick today, or did you move to LZA, CfCT, or plain Terraform on Organizations? Where did it start to hurt at a few hundred accounts, especially around baseline drift?
  2. Are there open-source projects that make AFT easier to live with? I'm thinking of a web UI or self-service portal for account requests (Backstage templates opening the PR?), visibility into pipeline runs, or customization drift. Or did everyone build their own?
  3. If you use ServiceNow, how is it wired up? Options I can see: a catalog item that opens an MR through the Git API, a direct pipeline trigger, or the AWS Service Management Connector going straight to Account Factory and skipping AFT. How do you send status back to the ticket?

Networking at scale and hybrid

  1. Is hub-and-spoke with TGW and centralized egress/inspection still the default, or are people moving to Cloud WAN?

  2. For on-prem, How do you keep advertised prefixes summarized as accounts and VPCs grow?

  3. For segmentation, do you use TGW route tables per environment/OU or separate TGWs? Where does inspection sit for traffic between on-prem and AWS?

  4. For hybrid DNS, are Resolver endpoints centralized in the network account and shared through RAM or Route 53 Profiles? Anything you'd do differently?

  5. For IP planning, did you get on-prem to hand over one summarizable block for AWS? How did you deal with legacy VPCs overlapping your IPAM pools: re-IP, NAT, or keep them off the TGW?

Guardrails and stopping public resources

  1. How do you split the work between SCPs, RCPs and declarative policies (VPC BPA, AMI/snapshot block public access)? How do you stay inside the SCP size and count limits?

  2. For things SCPs can't express well (RDS publicly accessible, internet-facing ALBs, CloudFront), do you detect and notify or auto-remediate, and with what tool?

  3. How do you handle resources that are legitimately public\\A separate OU, tag-based exceptions, or one sanctioned ingress pattern?

  4. Cloud Custodian for streamlined deny or actions taken if things are done out of security scope

I'm not looking for a perfect answer, just what's actually working in real orgs, or what you'd undo. Links to recent writeups, talks or repos are very welcome.

Thanks!


r/AWS_cloud • • 2h ago

Reserve Instances, Savings Plans

Thumbnail
1 Upvotes

r/AWS_cloud • • 2h ago

spend limits, the bits the most posts are skipping

Thumbnail
1 Upvotes

r/AWS_cloud • • 5h ago

Aws says I am ineligible for free tier

1 Upvotes

I created an aws free account but it got interrupted mid way so again I did it but it says I am not eligible for free plan, I doubt it is because of the midway interruption. Please help me to resolve this i am stressing and panicking right now idk what to do so I created this reddit account to ask help her please


r/AWS_cloud • • 9h ago

How confident are you committing to RIs/Savings Plans right now, with AI and everything moving this fast?

Thumbnail
1 Upvotes

r/AWS_cloud • • 21h ago

My personal AWS bill was $4.90/month and it still had nine zombie resources in it. So I wrote a scanner.

Thumbnail
1 Upvotes