Marketplace

Marketplace / Digital Downloads / AWS Landing Zone Terraform Starter Kit

AWS Landing Zone Terraform Starter Kit

A production-ready Terraform configuration for a secure AWS landing zone. Works as a single-account security baseline or a full multi-account setup with AWS Organizations, SCPs, Transit Gateway networking, and account vending. Every module can be toggled on or off - start simple and grow.

£249 + VAT Instant download (ZIP)

What's included

  • IAM baseline with strict password policy and Access Analyser
  • CloudTrail multi-region logging with S3 storage and lifecycle policies
  • GuardDuty threat detection with SNS alert notifications
  • Security Hub with CIS AWS Foundations Benchmark and AWS Best Practices
  • AWS Config with managed compliance rules (root MFA, encryption, S3 public access, default security groups)
  • Budget alerts at 80% and 100% thresholds
  • AWS Organizations with OUs (Security, Workloads, Sandbox)
  • Service Control Policies - deny root, require S3 encryption, restrict regions
  • Account vending module for self-service account provisioning
  • Hub VPC with Transit Gateway, shared to the organisation via RAM
  • Two egress patterns: centralised (NAT in hub) or distributed (NAT per spoke)
  • Terraform remote state backend (S3 + DynamoDB lock table)
  • Every module toggleable via variables - start simple, add complexity when ready
  • Compatible with Terraform 1.5+

Who is this for?

Platform teams and cloud architects setting up a new AWS environment or hardening an existing one. Works for single-account setups that need a security baseline, and scales to multi-account organisations that need OUs, SCPs, and centralised networking. Also valuable for consultants delivering landing zone projects who want a proven, codified starting point.

How it works

After purchase, you receive an instant download link via email. The download is a ZIP containing Terraform files organised by service. Copy the example tfvars file, set your values, and run terraform apply. Start with the single-account baseline (IAM, CloudTrail, GuardDuty, Config, budgets), then enable Organizations, SCPs, VPC, and account vending when you are ready to go multi-account.

1
Purchase
Stripe checkout
2
Automated Email
Stripe + Lambda + SES
3
Download
Secure link, 24hr expiry
4
Start Using
Immediate access

Architecture

Single-Account Baseline (always on) IAM Password + Analyser CloudTrail Multi-region GuardDuty Threat Detection Security Hub CIS Benchmark Config 10 Rules Budgets 80% + 100% S3 Public Block EBS Encryption Remote State (S3 + DDB) Multi-Account (optional) AWS Organizations Management Account Security OU Audit, Log Archive Workloads OU Production, Staging Sandbox OU Experimentation SCPs Root, Encrypt, Regions Account Vending Self-service Hub VPC + Transit Gateway Shared via RAM to all accounts in the organisation Choose Your Egress Pattern Centralised Egress Hub VPC has IGW + NAT. Spokes route through TGW. + Single point of control, consistent egress IPs + Fewer NAT gateways, easier firewall management - TGW data charges on internet traffic ~$130/month (TGW + 2 NAT gateways) Distributed Egress Hub is transit-only. Each spoke has its own NAT. + Independent resilience, lower latency + No TGW data charges for internet traffic - More NAT gateways, different egress IPs per account ~$65/month (TGW) + ~$65/month per spoke
£249 + VAT

After purchase, you will receive an instant download link via email.

Coming Soon