Goal: Reorganize and move the existing Linux infrastructure and IAM platform to a hybrid target environment (on-prem + hyperscaler)
Building Blocks:
Analysis & Target Architecture
Survey existing Linux systems, workloads, and interfaces
Design a scalable and highly available target infrastructure (including network and storage concepts)
Define the target architecture considering scalability, security, and availability
Assessment of the Existing IAM Solution
Survey the current IAM platform, workloads, and interfaces
Define the new target infrastructure (on-prem & cloud)
Integration of the Existing IAM Solution
Adopt and integrate the current IAM setup into the new target infrastructure (e.g. IDM, LDAP, Azure AD)
Architecture for central authentication & authorization across all target environments
SSO and MFA concepts including federation with hyperscalers (e.g. SAML, OIDC, SCIM)
Ensure auditability and compliance requirements (GDPR, ISO27001)
Migration Strategy
Define migration paths: lift & shift, replatforming
Define, plan, and orchestrate migrations including downtime, fallback, and testing concepts
Automation & Standardization
Further develop IaC (e.g. Terraform, Ansible)
Build reusable system and security modules
Hybrid/Multi-Cloud Architecture
Design and establish cloud connectivity (e.g. AWS, Azure, GCP)
Secure and federate identities of cloud resources with the existing IAM
Implement a consistent identity lifecycle
Handover & Documentation
Create operations, architecture, and security documentation
Conduct knowledge transfer workshops for operations and security