Skip to content

Commit b2577bd

Browse files
committed
updated before you start activities
1 parent fc325e3 commit b2577bd

File tree

4 files changed

+30
-20
lines changed

4 files changed

+30
-20
lines changed

landing-zones/standard_landing_zones/cis_lz_v2/cis_landing_zone_v2.md

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -7,10 +7,14 @@
77
 
88

99
## 1. Before You Start
10-
Before starting and creating the configuration, we recommend:
11-
1. Understand [CIS Landing Zone v2 Architecture](https://docs.oracle.com/en/solutions/cis-oci-benchmark/index.html) and the OCI elements involved, as you'll be configuring the solution.
12-
2. Review the [GitHub Repository](https://github.com/oracle-quickstart/oci-cis-landingzone-quickstart) as it contains the complete solution documentation.
13-
3. Execute the Live Labs ["Deploy a Secure Landing Zone in OCI"](https://apexapps.oracle.com/pls/apex/r/dbpm/livelabs/view-workshop?wid=3662).
10+
Before starting and creating the configuration, we recommend the following activities.
11+
12+
 
13+
14+
| STEP | ACTIVITY | GUIDANCE |
15+
|---|---|---|
16+
| 1 | Understand **Solution** | Understand [CIS Landing Zone v2 Architecture](https://docs.oracle.com/en/solutions/cis-oci-benchmark/index.html) and the OCI elements involved, as you'll be configuring the solution. </br> Review the [GitHub Repository](https://github.com/oracle-quickstart/oci-cis-landingzone-quickstart) as it contains the complete solution documentation. |
17+
| 2 | Train with **LiveLabs** | Execute the Live Labs ["Deploy a Secure Landing Zone in OCI"](https://apexapps.oracle.com/pls/apex/r/dbpm/livelabs/view-workshop?wid=3662).
1418

1519

1620

landing-zones/standard_landing_zones/oelz_v2/oelz_v2.md

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,21 +2,28 @@
22

33
## 1. BEFORE YOU START
44

5-
Before you start it's crucial to understand [OELZ v2 Architecture](https://blogs.oracle.com/cloudsecurity/post/enterprise-scale-baseline-landing-zone-version2) well and all elements involved, as you'll be configuring the solution. The [CAF](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/landing-zone-v2.htm) and [GitHub Repository](https://github.com/oracle-quickstart/oci-landing-zones) contains the complete solution documentation.
5+
Before starting and creating the configuration, we recommend the following activities.
6+
7+
&nbsp;
8+
9+
| STEP | ACTIVITY | GUIDANCE |
10+
|---|---|---|
11+
| 1 | Understand the **Solution** | It's very important to understand [OELZ v2 Architecture](https://blogs.oracle.com/cloudsecurity/post/enterprise-scale-baseline-landing-zone-version2) well and all elements involved, as you'll be configuring the solution. The [CAF](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/landing-zone-v2.htm) and [GitHub Repository](https://github.com/oracle-quickstart/oci-landing-zones) contains the complete solution documentation.
12+
| 2 | Train with **LiveLabs** | We recommend also to execute the [OELZ Live Labs](https://apexapps.oracle.com/pls/apex/dbpm/r/livelabs/view-workshop?wid=3470) to understand the solution with hands-on experience, with a step-by-step deployment guide.
613

714

815

916
&nbsp;
1017

1118
## 2. CREATE THE SETUP CONFIGURATION
1219

13-
Follow the guidelines presented [here](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/configuration-landing-zone-v2.htm).
20+
To create your configurations follow the guidelines presented [here](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/configuration-landing-zone-v2.htm).
1421

1522
&nbsp;
1623

1724
## 3. DEPLOY THE CONFIGURATION
1825

19-
Follow the guidelines presented [here](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/implementation-landing-zone-v2.htm).
26+
To deploy the configuration follow the guidelines presented [here](https://docs.oracle.com/en-us/iaas/Content/cloud-adoption-framework/implementation-landing-zone-v2.htm).
2027

2128

2229

landing-zones/standard_landing_zones/standard_landing_zones.md

Lines changed: 10 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -44,20 +44,19 @@ There are **two solutions** OCI Standard Landing Zones:
4444
Find below an executive review of some key requirements that will influence the standard landing zone decision - without any customization:
4545

4646
&nbsp;
47-
48-
49-
| DOMAIN | REQUIREMENT | SOLUTION |
50-
|---|---|---|
51-
| **Segregation of Duties** | A dedicated **Network** Team, **Security** Team, **Database** Team, and **Applications** Team, operating their respective resources. | CIS LZ v2 |
52-
| **Segregation of Duties** | A dedicated **Network** Team, **Security** Team, and possibly a Team per **Application** operating their respective resources. | OELZ v2 |
53-
| **Network** | Strong workload network isolation with **NSGs**. | CIS LZ v2 |
54-
| **Security** | **CIS Compliant** solution with embedded **CIS validations**. | CIS LZ v2 |
55-
| **IAM** | The target tenancy **without Identity Domains**. | CIS LZ v2 |
56-
| **Cost** | Starting with **no initial OCI consumption**. | CIS LZ v2 |
47+
| # | DOMAIN | REQUIREMENT (The customer requires...)| SOLUTION |
48+
|:-:|---|---|---|
49+
| 1 | **Segregation of Duties** | A dedicated **Network** Team, **Security** Team, **Database** Team, and **Applications** Team, operating their respective resources. | CIS LZ v2 |
50+
| 2 | **Segregation of Duties** | A dedicated **Network** Team, **Security** Team, and possibly **one Team per Application** operating their respective resources. | OELZ v2 |
51+
| 3 | **Network** | Strong workload network isolation with **NSGs**. | CIS LZ v2 |
52+
| 4 | **Security** | **CIS Compliant** solution with embedded **CIS validations**. | CIS LZ v2 |
53+
| 5 | **IAM** | A target tenancy **without Identity Domains**. | CIS LZ v2 |
54+
| 6 | **Workloads** | The main use case focused on **database workloads** and there is **one team responsible** for these workloads. Relates to point 1. | CIS LZ v2 |
55+
| 7 | **Cost** | Starting with **no initial OCI consumption**. | CIS LZ v2 |
5756

5857
&nbsp;
5958

60-
For other design considerations (such as hub & spoke, several environments, ExaCS ready, etc.), both solutions will tend to fit. Note the support model for both solutions is UPL 1.0.
59+
For other design considerations (such as hub & spoke, several environments, ExaCS ready, etc.), both solutions will tend to fit. Note the **support model for both solutions is UPL 1.0**.
6160

6261
If after reviewing the table above the solution is not clear:
6362
1. Visit [**landing zone landscape**](/landing-zones/commons/select_your_solution.pdf) for further consideration.

landing-zones/tailored_landing_zones/tailored_landing_zones.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -40,15 +40,15 @@ There are **two assets** for creating OCI tailored landing zones, one for **desi
4040
### 2.1 Design - with a Blueprint
4141
To tailor a landing zone we recommend using the **[OCI Open LZ Blueprint](https://github.com/oracle-quickstart/terraform-oci-open-lz)**, which is a **reference solution** and a **repeatable design process**. It presents an end-to-end coherent solution - with the security, network, and operations views - of what an organization-wide landing zone looks like, with fine-grained segregation of duties, strong isolation of resources, and a scaleable operating model.
4242

43-
The **benefits** of this blueprint is that it can be completely **adjusted and easily simplified** into any other type of landing zone, by following the design steps towards your needs. Using this reference blueprint will help **create a day-two operational model ready to scale** - using the IaC solution presented in the next section.
43+
The **benefit** of this blueprint is that it can be completely **adjusted and easily simplified** into any other type of landing zone, by following the design steps towards your needs. Using this reference blueprint will help **create a day-two operational model ready to scale** - using the IaC solution presented in the next section.
4444

4545

4646
&nbsp;
4747

4848
### 2.2 Run - with Configuration and Infrastructure as Code
4949
For this type of approach **we recommend** the use of the **CIS LZ v3 Terraform modules**, to **configure** the resources with *json/hcl* terraform native interfaces.
5050

51-
The **benefits** of using this approach is:
51+
The **benefits** of using this approach are:
5252
- **Focus on Value**: Focus on configuring the design and resources, instead of coding them. This means shorter time-to-value, lower effort, and lower risk.
5353
- **Best Practices**: Use existing top-quality terraform modules that are open and full of best practices. It's possible to leverage this to evolve OCI terraform skills and apply future IaC best practices. This also means lower risk and lower efforts.
5454
- **Scale Day Two**: Being able to split operational configurations from code it's a game change in cloud operations, and will simplify drastically the day-two operations, opening the path for a GitOps operating model and potentially simpler automation. The cloud operators will only work with configurations, not code.

0 commit comments

Comments
 (0)