Landing Zone
Deploy a secure, scalable, and sovereign cloud foundation that accelerates adoption while enforcing governance from day one.

What is a Landing Zone?
A Landing Zone is an ready to use, secure, and scalable cloud environment that provides the foundation for deploying and managing workloads according to best practices.
- Platform-level foundation: Centralizes organization-wide IAM policies, VPC network boundaries, security controls, and consolidated billing into a single governed baseline.
- Application-level execution: Tailors this baseline to specific workloads like microservices or databases, allowing teams to innovate rapidly while automatically inheriting all security guardrails.
Benefits of Scaleway Landing Zone
Security by Design
Enforce centralized identity management, RBAC, and strict network isolation.
Sovereignty & Compliance
Build on an infrastructure that inherently shields customers from extraterritorial data access laws

Automated Scalability
Rely on Infrastructure as Code (IaC) to ensure reproducible and consistent environments.
The pillars of Scaleway Landing Zone
Our framework covers the essential architectural pillars to structure your cloud:
| Pillar | Key Objective & Description |
|---|---|
| Organization & Governance | Logically isolate infrastructure resources using projects while maintaining centralized billing. |
| Networking | Enforce segmentation using private networks and control outbound traffic with public gateways. |
| Security & Compliance | Implement Role-Based Access Control (RBAC) and integrate corporate directories via SAML SSO. |
| Observability | Automatically aggregate metrics via Cockpit and ensure traceability with Audit Trail. |
| Automation (IaC) | Describe and manage all foundational elements using Terraform, Pulumi, or OpenTofu. |
| FinOps & GreenOps | Control budgets and track the environmental footprint of your infrastructure. |
| Disaster Recovery | Define RTO/RPO objectives and implement appropriate failover strategies. |
What you will learn in the complete guide ?
How to perfectly segregate human Member accounts from programmatic Application accounts.
Step-by-step guidance for Hub-and-Spoke designs and Private DNS resolution using customer-managed resolvers.
Deploying central firewalls and managing encryption keys via Scaleway Key Manager.
In-depth technical requirements for Pilot Light, Warm Standby, and Active-Active architectures.

Fill in the form to download the document
Why choose Scaleway?
Our European, multi-cloud & open source DNA
We are a European Cloud trusted by more than 50 000 customers in 160 countries. Our services are protected by European regulations.
Sustainable by design
100% of electricity consumed in our data centers comes from renewable energy. Decommissioned hardware is securely reused & recycled.
24/7 Ticket support
Our technical assistance is available 24/7 to answer all your questions and assist you. Upgrade to support plan to reach directly by phone.
Transparent & predictable billing
Our services are designed to offer you the best price/performance ratio, with straightforward billing to grow your business and keep your expenses under control.

