You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: landing-zones/standard_landing_zones/cis_lz_v2/cis_landing_zone_v2.md
+8-4Lines changed: 8 additions & 4 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,10 +7,14 @@
7
7
8
8
9
9
## 1. Before You Start
10
-
Before starting and creating the configuration, we recommend:
11
-
1. Understand [CIS Landing Zone v2 Architecture](https://docs.oracle.com/en/solutions/cis-oci-benchmark/index.html) and the OCI elements involved, as you'll be configuring the solution.
12
-
2. Review the [GitHub Repository](https://github.com/oracle-quickstart/oci-cis-landingzone-quickstart) as it contains the complete solution documentation.
13
-
3. Execute the Live Labs ["Deploy a Secure Landing Zone in OCI"](https://apexapps.oracle.com/pls/apex/r/dbpm/livelabs/view-workshop?wid=3662).
10
+
Before starting and creating the configuration, we recommend the following activities.
11
+
12
+
13
+
14
+
| STEP | ACTIVITY | GUIDANCE |
15
+
|---|---|---|
16
+
| 1 | Understand **Solution**| Understand [CIS Landing Zone v2 Architecture](https://docs.oracle.com/en/solutions/cis-oci-benchmark/index.html) and the OCI elements involved, as you'll be configuring the solution. </br> Review the [GitHub Repository](https://github.com/oracle-quickstart/oci-cis-landingzone-quickstart) as it contains the complete solution documentation. |
17
+
| 2 | Train with **LiveLabs** | Execute the Live Labs ["Deploy a Secure Landing Zone in OCI"](https://apexapps.oracle.com/pls/apex/r/dbpm/livelabs/view-workshop?wid=3662).
Copy file name to clipboardExpand all lines: landing-zones/standard_landing_zones/oelz_v2/oelz_v2.md
+10-3Lines changed: 10 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,21 +2,28 @@
2
2
3
3
## 1. BEFORE YOU START
4
4
5
-
Before you start it's crucial to understand [OELZ v2 Architecture](https://blogs.oracle.com/cloudsecurity/post/enterprise-scale-baseline-landing-zone-version2) well and all elements involved, as you'll be configuring the solution. The [CAF](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/landing-zone-v2.htm) and [GitHub Repository](https://github.com/oracle-quickstart/oci-landing-zones) contains the complete solution documentation.
5
+
Before starting and creating the configuration, we recommend the following activities.
6
+
7
+
8
+
9
+
| STEP | ACTIVITY | GUIDANCE |
10
+
|---|---|---|
11
+
| 1 | Understand the **Solution** | It's very important to understand [OELZ v2 Architecture](https://blogs.oracle.com/cloudsecurity/post/enterprise-scale-baseline-landing-zone-version2) well and all elements involved, as you'll be configuring the solution. The [CAF](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/landing-zone-v2.htm) and [GitHub Repository](https://github.com/oracle-quickstart/oci-landing-zones) contains the complete solution documentation.
12
+
| 2 | Train with **LiveLabs** | We recommend also to execute the [OELZ Live Labs](https://apexapps.oracle.com/pls/apex/dbpm/r/livelabs/view-workshop?wid=3470) to understand the solution with hands-on experience, with a step-by-step deployment guide.
6
13
7
14
8
15
9
16
10
17
11
18
## 2. CREATE THE SETUP CONFIGURATION
12
19
13
-
Follow the guidelines presented [here](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/configuration-landing-zone-v2.htm).
20
+
To create your configurations follow the guidelines presented [here](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/configuration-landing-zone-v2.htm).
14
21
15
22
16
23
17
24
## 3. DEPLOY THE CONFIGURATION
18
25
19
-
Follow the guidelines presented [here](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/implementation-landing-zone-v2.htm).
26
+
To deploy the configuration follow the guidelines presented [here](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/implementation-landing-zone-v2.htm).
Copy file name to clipboardExpand all lines: landing-zones/standard_landing_zones/standard_landing_zones.md
+10-11Lines changed: 10 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -44,20 +44,19 @@ There are **two solutions** OCI Standard Landing Zones:
44
44
Find below an executive review of some key requirements that will influence the standard landing zone decision - without any customization:
45
45
46
46
47
-
48
-
49
-
| DOMAIN | REQUIREMENT | SOLUTION |
50
-
|---|---|---|
51
-
|**Segregation of Duties**| A dedicated **Network** Team, **Security** Team, **Database** Team, and **Applications** Team, operating their respective resources. | CIS LZ v2 |
52
-
|**Segregation of Duties**| A dedicated **Network** Team, **Security** Team, and possibly a Team per **Application** operating their respective resources. | OELZ v2 |
| 1 |**Segregation of Duties**| A dedicated **Network** Team, **Security** Team, **Database** Team, and **Applications** Team, operating their respective resources. | CIS LZ v2 |
50
+
| 2 |**Segregation of Duties**| A dedicated **Network** Team, **Security** Team, and possibly **one Team per Application** operating their respective resources. | OELZ v2 |
| 6 |**Workloads**| The main use case focused on **database workloads** and there is **one team responsible** for these workloads. Relates to point 1. | CIS LZ v2 |
For other design considerations (such as hub & spoke, several environments, ExaCS ready, etc.), both solutions will tend to fit. Note the support model for both solutions is UPL 1.0.
59
+
For other design considerations (such as hub & spoke, several environments, ExaCS ready, etc.), both solutions will tend to fit. Note the **support model for both solutions is UPL 1.0**.
61
60
62
61
If after reviewing the table above the solution is not clear:
63
62
1. Visit [**landing zone landscape**](/landing-zones/commons/select_your_solution.pdf) for further consideration.
Copy file name to clipboardExpand all lines: landing-zones/tailored_landing_zones/tailored_landing_zones.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -40,15 +40,15 @@ There are **two assets** for creating OCI tailored landing zones, one for **desi
40
40
### 2.1 Design - with a Blueprint
41
41
To tailor a landing zone we recommend using the **[OCI Open LZ Blueprint](https://github.com/oracle-quickstart/terraform-oci-open-lz)**, which is a **reference solution** and a **repeatable design process**. It presents an end-to-end coherent solution - with the security, network, and operations views - of what an organization-wide landing zone looks like, with fine-grained segregation of duties, strong isolation of resources, and a scaleable operating model.
42
42
43
-
The **benefits** of this blueprint is that it can be completely **adjusted and easily simplified** into any other type of landing zone, by following the design steps towards your needs. Using this reference blueprint will help **create a day-two operational model ready to scale** - using the IaC solution presented in the next section.
43
+
The **benefit** of this blueprint is that it can be completely **adjusted and easily simplified** into any other type of landing zone, by following the design steps towards your needs. Using this reference blueprint will help **create a day-two operational model ready to scale** - using the IaC solution presented in the next section.
44
44
45
45
46
46
47
47
48
48
### 2.2 Run - with Configuration and Infrastructure as Code
49
49
For this type of approach **we recommend** the use of the **CIS LZ v3 Terraform modules**, to **configure** the resources with *json/hcl* terraform native interfaces.
50
50
51
-
The **benefits** of using this approach is:
51
+
The **benefits** of using this approach are:
52
52
-**Focus on Value**: Focus on configuring the design and resources, instead of coding them. This means shorter time-to-value, lower effort, and lower risk.
53
53
-**Best Practices**: Use existing top-quality terraform modules that are open and full of best practices. It's possible to leverage this to evolve OCI terraform skills and apply future IaC best practices. This also means lower risk and lower efforts.
54
54
-**Scale Day Two**: Being able to split operational configurations from code it's a game change in cloud operations, and will simplify drastically the day-two operations, opening the path for a GitOps operating model and potentially simpler automation. The cloud operators will only work with configurations, not code.
0 commit comments