Landing zones that survive growth
Multi-account or multi-project structure, organisational policy, centralised logging and billing separation. Built as Terraform modules with a documented decision record, so the next team to extend it can see why each boundary exists.
Network and connectivity design
VPC and subnet topology, transit and peering, private service access, DNS, and hybrid connectivity to on-premise. Designed around your actual traffic patterns and failure domains rather than a reference diagram.
Identity and access foundations
Federation with your identity provider, role design, permission boundaries and break-glass access. Least privilege that engineers can actually work inside, so nobody routes around it.
Migration and modernisation planning
An honest assessment of what should move, what should be rebuilt, and what should be left alone, with cost modelling before you commit, not after.