Goal: Reorganizing and migrating the existing Linux infrastructure and IAM platform to a hybrid target environment (on-prem + hyperscaler)
Components:
Analysis & Target Architecture
Survey of the existing Linux systems, workloads and interfaces
Design of a scalable and highly available target infrastructure (incl. network and storage concepts)
Definition of the target architecture considering scalability, security and availability
Evaluation of the existing IAM solution
Survey of the existing IAM platform, workloads and interfaces
Definition of the new target infrastructure (on-prem & cloud)
Integration of the existing IAM solution
Adoption and integration of the existing IAM structure into the new target infrastructure (e.g. IDM, LDAP, Azure AD)
Architecture for central authentication & authorization across all target environments
SSO and MFA concepts including federation with hyperscalers (e.g. SAML, OIDC, SCIM)
Ensuring auditability and compliance requirements (GDPR, ISO27001)
Migration strategy
Definition of migration paths: lift & shift, replatforming
Definition, planning and orchestration of migrations including downtime, fallback and test plans
Automation & Standardization
Further development of IaC (e.g. Terraform, Ansible)
Building reusable system and security modules
Hybrid/Multi-Cloud Architecture
Design and setup of cloud connectivity (e.g. AWS, Azure, GCP)
Securing and identity federation of cloud resources with the existing IAM
Introduction of a consistent identity lifecycle
Handover & Documentation
Creation of operations, architecture and security documentation
Conducting knowledge transfer workshops for operations and security