Goal: Reorganize and move the existing Linux infrastructure and IAM platform to a hybrid target environment (on-prem + hyperscaler)
Components:
Analysis & Target Architecture
Survey the existing Linux systems, workloads, and interfaces
Design a scalable and highly available target infrastructure (including network and storage concepts)
Define the target architecture considering scalability, security, and availability
Assessment of the existing IAM solution
Survey the current IAM platform, workloads, and interfaces
Define the new target infrastructure (on-prem & cloud)
Integration of the existing IAM solution
Adopt and integrate the existing IAM setup into the new target infrastructure (e.g. IDM, LDAP, Azure AD)
Architecture for central authentication & authorization across all target environments
SSO and MFA concepts including federation with hyperscalers (e.g. SAML, OIDC, SCIM)
Ensure auditability and compliance requirements (GDPR, ISO27001)
Migration strategy
Define migration paths: lift & shift, replatforming
Define, plan, and orchestrate migrations including downtime, fallback, and test plans
Automation & standardization
Further develop IaC (e.g. Terraform, Ansible)
Build reusable system and security modules
Hybrid/Multi-Cloud Architecture
Design and build cloud connectivity (e.g. AWS, Azure, GCP)
Secure and federate cloud resources with the existing IAM
Introduce a consistent identity lifecycle
Handover & Documentation
Create operations, architecture, and security documentation
Conduct knowledge-transfer workshops for operations and security