IjyaLabs logo
IjyaLabs
Services·Cloud

Cloud Architecture & Migration

Cloud migrations stall or go over budget when networking, identity, security, and operations are not designed before workloads move.

2026-06-30·By Arun R Kaushik

Our Approach

Build a cloud architecture blueprint that covers connectivity, security baselines, identity, and operational readiness before any workload touches the cloud.

What This Service Covers

Cloud architecture and migration advisory for organizations moving workloads to AWS, Azure, or GCP — or optimizing what is already there.

Engagements cover landing zone design, hybrid connectivity (Direct Connect, ExpressRoute, Cloud Interconnect), network security in cloud, identity and access architecture, and migration sequencing. For multi-cloud deployments, this includes inter-cloud routing, policy consistency, and cost guardrails.

Scope areas

Landing zone and account/subscription design AWS Organizations, Azure Management Groups, GCP Folders. Account segmentation strategy, baseline SCPs and policies, tagging and cost allocation, centralized logging and audit trail setup.

Hybrid and private connectivity AWS Direct Connect, Azure ExpressRoute, GCP Dedicated Interconnect design. Routing policy between on-premises and cloud. BGP communities, failover routing, and bandwidth planning. SD-WAN integration with cloud on-ramp.

Cloud network architecture VPC/VNet design, transit architecture (AWS TGW, Azure vWAN, GCP NCC), private endpoints, DNS resolution strategy, and inter-region routing.

Identity and access IAM role architecture, federated identity (SAML/OIDC), least-privilege design, service account governance, and privileged access management for cloud workloads.

Security baselines Security group and NACL strategy, WAF placement, DDoS protection, cloud-native security tooling (GuardDuty, Defender, Security Command Center), and CSPM integration.

VMware Cloud on AWS and SDDC VMware Cloud on AWS (VMC) architecture and operations. SDDC design — management, compute, and edge clusters. NSX-T networking within VMC. Workload migration using VMware HCX — bulk migration, vMotion, and cold migration planning. Aviatrix integration for multi-cloud transit and secure connectivity.

Migration planning Workload discovery and dependency mapping, migration wave sequencing, cutover planning, rollback procedures, and post-migration validation checklists. VMware HCX for live migration between on-prem and VMC or between cloud providers.


Delivery Models

Remote Consultation

Advisory calls for architecture decisions, cloud design reviews, or specific problem areas (connectivity, cost, security). Half-day or full-day blocks. Deliverable: written notes and recommendations.

Remote Support Retainer

Monthly hours for ongoing cloud architecture support — design reviews for new workloads, security review of new services, cost optimization recommendations, and change advisory.

Engineer Basis (Project)

Fixed-scope engagement: current state assessment, cloud architecture design, landing zone build guidance, and migration plan. Remote-led; your team or a cloud partner executes the deployment. Typical scope: 3–8 weeks.


Typical Engagement Formats

Format Best for Typical Duration
Cloud Readiness Review Assess gaps before migration begins 1 week
Landing Zone Design New cloud foundation (greenfield) 2–4 weeks
Hybrid Connectivity Design DC to cloud private link 1–3 weeks
Migration Planning Sequencing and risk planning for workload move 2–4 weeks
Architecture Retainer Ongoing support for cloud platform team Monthly

Platforms and Tools

AWS (VPC, TGW, Direct Connect, IAM, GuardDuty, Control Tower), Azure (vNET, vWAN, ExpressRoute, Entra ID, Defender), GCP (VPC, NCC, Interconnect, IAM, SCC), VMware Cloud on AWS, VMware HCX, Aviatrix, Terraform, Ansible, CloudFormation. Certified: Azure Network Engineer Associate, HashiCorp Terraform Associate, Aviatrix Certified Engineer, VMware Cloud on AWS Specialist.