Cloud Foundations
Cloud Foundations is an Amazon Web Services solution that transforms enterprise cloud adoption by delivering a production-ready, multi-account cloud environment with comprehensive governance, security, and operational capabilities.
Introduction
Cloud Foundations is an Amazon Web Services solution that transforms enterprise cloud adoption by delivering a production-ready, multi-account cloud environment with comprehensive governance, security, and operational capabilities. Built on the Amazon Web Services Cloud Foundations whitepaper, it implements 30 essential cloud capabilities through automated infrastructure-as-code deployment, including centralized account management via Account Factory, automated security baselines with Amazon Config rules and remediation, and comprehensive logging with centralized storage. The solution provides advanced networking capabilities through VPC-sharing and TGW-sharing models with hub-spoke architectures, supporting centralized egress control, traffic inspection with Amazon Network Firewall and Gateway Load Balancer, multi-regional connectivity via transit gateway peering, and centralized VPC endpoint access for cost optimization. Cloud resource management is streamlined through Product Factory's infrastructure-as-definition approach with JSON-based provisioning across essential Amazon Web Services and automated deployment pipelines. With built-in multi-regional deployment, Amazon Control Tower integration, Amazon IAM Identity Center federation, automated backup management, and real-time security monitoring through GuardDuty and Security Hub integration, Cloud Foundations delivers up to 80% reduction in implementation time while providing a scalable foundation that maintains operational excellence and cost optimization from day one.
The Cloud Foundations Quick Start Pack
The Cloud Foundations Quick Start Pack provides two editions at present
|
Standard Edition
|
Lite Edition
|
---|---|---|
Delivery mode
|
Amazon Web Services |
Amazon Web Services and partners |
Basic landing zone
|
Included |
Included |
Basic networking
|
Included |
Included |
Basic training
|
Included |
Included |
Backup and config rules
|
Included |
Included |
Account Factory
|
Included |
Not included |
Advanced capabilities
|
Included |
Not included |
Extended networking
|
Optional |
Not included |
Extended training
|
Optional |
Not included |
Cloud resource management
|
Optional |
Not included |
Major advantages
Architecture diagram
Page topics
Select technical blog posts
1. Blog post: Use Cloud Foundations to holistically plan and one-click deploy two network sharing models in multi-account organizations on the cloud, February 2023
2. Blog post: Use Cloud Foundations to plan and design multi-regional hub-spoke network topology on the cloud and one-click deploy east-west south-north traffic inspection separated or combined, November 2023
3. Blog post: Use Cloud Foundations Product Factory to plan, design and one-click deploy infrastructural cloud resources such as multi-account access control and permission policies, March 2024
5. Blog post: Cloud Foundations demo videos part one: from deployment to daily operations, April 2025
6. Blog post: Manage Control Tower with Cloud Foundations: govern regions, manage organizations, create or enroll accounts, enable controls, May 2025