Architecture & adoption

Frameworks for making cloud decisions deliberately and revisiting them as the system evolves.

Well-Architected Framework

A repeatable review of whether a workload is secure, reliable, efficient, cost-aware, sustainable, and operationally sound.

Use it when

Designing a new workload, preparing a production launch, or reviewing an existing platform.

  • Operational excellence
  • Security
  • Reliability
  • Performance efficiency
  • Cost optimization
  • Sustainability
  1. Describe the workload and its business goals
  2. Review each pillar with evidence
  3. Record risks and trade-offs
  4. Prioritize remediation work
  5. Repeat after meaningful change

Cloud Adoption Framework

A structured path from cloud strategy to landing zones, migration, governance, security, and ongoing management.

Use it when

Starting or scaling cloud adoption across multiple teams, subscriptions, accounts, or workloads.

  • Strategy and outcomes
  • Adoption plan
  • Landing zone readiness
  • Migration and modernization
  • Governance
  • Management and security
  1. Define motivations and measurable outcomes
  2. Inventory workloads and skills
  3. Prepare identity, networking, policy, and account structure
  4. Adopt in controlled waves
  5. Govern and operate continuously

Delivery & source control

Practices that keep changes small, reviewable, reproducible, and safe to release.

Branching Strategy

An agreed model for how code moves from an idea to an integrated, releasable change.

Use it when

Defining repository rules or fixing slow integration, merge conflicts, and unclear release ownership.

  • Trunk-based development
  • GitHub Flow
  • GitFlow
  • Release branches
  • Short-lived feature branches
  • Protected branches
  1. Start from release frequency and risk
  2. Choose the simplest fitting model
  3. Keep branches short-lived
  4. Automate checks and reviews
  5. Document hotfix and release paths

Continuous Integration & Delivery

Integrate frequently and use an automated path to build, test, package, and promote every change.

Use it when

Teams need faster feedback, consistent artifacts, and repeatable releases.

  • Fast feedback
  • Build once, promote many
  • Automated quality gates
  • Environment parity
  • Progressive delivery
  1. Trigger on every change
  2. Run fast validation first
  3. Create an immutable artifact
  4. Promote with policy and approvals
  5. Observe the release and roll back safely

GitOps

Operate systems from declarative desired state stored in Git and reconciled automatically by controllers.

Use it when

Managing Kubernetes or other declarative platforms where auditability and drift correction matter.

  • Git as source of truth
  • Pull-based reconciliation
  • Declarative state
  • Drift detection
  • Auditable changes
  1. Change desired state through a pull request
  2. Validate policy and configuration
  3. Merge the approved state
  4. Let a controller reconcile
  5. Alert on failed reconciliation or drift

Operations, security & cost

Shared disciplines that turn reliability, security, and financial responsibility into daily engineering work.

Site Reliability Engineering

Apply software engineering to operations and balance reliability work with product delivery through explicit service objectives.

Use it when

A service needs measurable reliability targets and a disciplined response to operational load.

  • SLIs and SLOs
  • Error budgets
  • Toil reduction
  • Blameless postmortems
  • Capacity planning
  1. Measure user-visible reliability
  2. Set realistic objectives
  3. Use error budgets to guide release risk
  4. Automate repetitive work
  5. Learn from incidents

DevSecOps

Make security a shared, automated part of design, development, delivery, and operations.

Use it when

Security feedback arrives too late or ownership is isolated in a separate approval stage.

  • Threat modeling
  • Least privilege
  • Software supply chain
  • Policy as code
  • Continuous scanning
  1. Model threats early
  2. Protect identities and secrets
  3. Scan code, dependencies, images, and infrastructure
  4. Enforce risk-based policy
  5. Monitor and respond in production

Infrastructure as Code

Define infrastructure in versioned, reviewable configuration and apply it through automated workflows.

Use it when

Infrastructure must be reproducible across environments and changes need an audit trail.

  • Declarative configuration
  • Reusable modules
  • Remote state
  • Plan before apply
  • Drift management
  1. Model the desired infrastructure
  2. Review a generated plan
  3. Apply through automation
  4. Verify outcomes
  5. Detect and resolve drift

FinOps

Create shared visibility and accountability so engineering, finance, and business teams optimize cloud value together.

Use it when

Cloud spend is growing, ownership is unclear, or cost decisions are disconnected from product value.

  • Allocation and tagging
  • Unit economics
  • Budgets and forecasts
  • Rightsizing
  • Commitment management
  1. Make cost data visible
  2. Allocate spend to owners
  3. Define useful unit metrics
  4. Optimize architecture and usage
  5. Review forecasts and commitments continuously
Search