Goal: Reorganize and migrate the existing Linux infrastructure and IAM platform to a hybrid target environment (on-prem + hyperscaler)
Components:
Analysis & Target Architecture
Survey existing Linux systems, workloads, and interfaces
Design a scalable and highly available target infrastructure (incl. network and storage concepts)
Define the target architecture considering scalability, security, and availability
Assessment of the existing IAM solution
Survey the existing IAM platform, workloads, and interfaces
Define the new target infrastructure (on-prem & cloud)
Integration of the existing IAM solution
Adopt and integrate the existing IAM structure into the new target infrastructure (e.g., IDM, LDAP, Azure AD)
Architecture for centralized authentication & authorization across all target environments
SSO and MFA concepts including federation with hyperscalers (e.g., SAML, OIDC, SCIM)
Ensure auditability and compliance requirements (GDPR, ISO27001)
Migration Strategy
Define migration paths: lift & shift, replatforming
Define, plan, and orchestrate moves including downtime, fallback, and testing concepts
Automation & Standardization
Further develop IaC (e.g., Terraform, Ansible)
Build reusable system and security modules
Hybrid/Multi-Cloud Architecture
Design and deploy cloud connectivity (e.g., AWS, Azure, GCP)
Secure and establish identity federation of cloud resources with the existing IAM
Introduce a consistent identity lifecycle
Handover & Documentation
Create operational, architecture, and security documentation
Conduct knowledge transfer workshops for operations and security