Blog

What’s New in the ITGix AWS Landing Zone: Recent Platform Enhancements

Picture of Boris Yakimov
Boris Yakimov
COO & DevOps Lead
05.06.2026
Reading time: 4 mins.
Last Updated: 05.06.2026

Table of Contents

The ITGix AWS Landing Zone continues to evolve with a clear goal: enabling organizations to build secure, compliant, and scalable AWS environments with less operational overhead.

Across recent releases (v1.2.0 through v1.6.0), we’ve introduced major improvements spanning security, compliance, CI/CD automation, networking, observability, and operational efficiency. These updates are designed for teams managing multi-account AWS architectures that require strong governance without sacrificing flexibility.

In this post, we highlight the most impactful updates and explain how they improve day-to-day operations for cloud and platform teams.

aws

One of the most requested capabilities is now available: automated CI/CD pipelines for the Landing Zone itself.

Built on AWS CodePipeline and CodeBuild, the new pipeline module enables infrastructure deployments across multiple AWS accounts directly from a version control repository using AWS CodeConnections.

To ensure safe and reliable deployments, the pipeline includes multiple hardening mechanisms:

  • SHA-256 checksum validation for plan integrity
  • Commit SHA validation between plan and apply stages
  • Account and region validation
  • Plan metadata tracking with build IDs and timestamps
  • TTL enforcement for plan validity (default: 30 minutes)
  • Strict artifact presence validation – apply stages use only approved plan files, with no re-planning

This brings the same rigor teams expect from application CI/CD into infrastructure lifecycle management.

Security remains a core focus across every release of the ITGix AWS Landing Zone.

Support for PCI DSS v4.0.1 has been added to SecurityHub scanning, complementing existing NIST and CIS Benchmark checks. Combined with targeted remediation of findings, this significantly strengthens the default compliance posture.

AWS Config is now enabled across all accounts, automatically collecting configuration data and storing historical state in S3. Conformance packs can be enabled quickly to scan against multiple security standards.

Several organization-wide access improvements have been implemented:

  • Stronger IAM password policies aligned with PCI DSS 4.0.1
  • Prevention of public S3 bucket access across all accounts
  • Root credential management enabled for member accounts
  • Default EBS volume encryption enforced everywhere

A comprehensive set of Service Control Policies now provides preventive guardrails, including:

  • Mandatory resource tagging for cost allocation
  • Disabled IAM user and access key creation (Identity Center only)
  • Region restrictions to approved AWS regions
  • Protection against accounts leaving the organization
  • Deletion protection for CloudTrail, S3, DynamoDB, and KMS
  • Enforced encryption for S3 object uploads
  • Account quarantine capability for security incidents

These controls reduce risk while maintaining operational consistency.

GuardDuty has been refactored to support the latest AWS APIs and expanded to include all supported detection types:

  • S3 Data Events
  • EKS Audit Logs
  • EBS Malware Protection
  • RDS Login Events
  • Lambda Network Logs
  • Runtime Monitoring

Each detection feature can now be enabled or disabled conditionally, allowing teams to balance coverage and cost.

The Landing Zone now includes a Just-In-Time (JIT) access tool, known as the TEAM tool, deployed in the Security account.

Key capabilities include:

  • Predefined groups for requestors, approvers, and administrators
  • Scheduled access windows for future access needs
  • Full auditability of access requests and approvals

This eliminates standing production access and enforces least-privilege access by design.

Using AWS Observability Access Manager (OAM), logs and metrics from all accounts are now centralized in the Logging & Auditing account.

This enables:

  • Centralized log search via CloudWatch Log Insights
  • Organization-wide alerting on CloudWatch metrics
  • A single operational view across all accounts

AWS Managed Client VPN has been refactored to integrate more efficiently with Transit Gateway. A single VPN endpoint can now provide access to dev, stage, and prod environments, with access controlled via groups and Identity Center SSO.

New options include:

  • Simplified per-account VPC deployments (HA across 3 AZs)
  • Automated VPC peering
  • WireGuard VPN behind an NLB
  • Shared-services VPC support

Updates include:

  • Federated DNS zones across environments
  • Route 53 resolver query logging per VPC
  • Optional DNS query/response logging
  • Updated diagrams and documentation

An automated script now checks for newer Terraform module versions and generates update reports, simplifying Landing Zone maintenance.

Automated start/stop schedules for EC2 and RDS help reduce non-production costs.

CloudWatch log groups with unlimited retention are now automatically updated to a 365-day retention policy.

AWS Backup is centrally managed with organization-wide policies. Resources can be automatically backed up by applying a simple tag.

Recent infrastructure-level updates include:

  • AWS Control Tower integration
  • Terraform AWS provider v6 upgrade
  • Terraform state locking moved to S3
  • GitHub-based Terraform module repositories
  • GitHub OIDC integration for role assumption
  • Improved documentation, diagrams, and client handover artifacts

With each release, the ITGix AWS Landing Zone moves closer to a fully self-service, compliance-ready cloud platform.

Upcoming roadmap items include:

  • Self-service Client VPN portal
  • IPAM integration
  • IPv6 support
  • Expanded multi-region service coverage

If your organization is looking to accelerate its AWS journey with a secure and scalable foundation, contact our team to learn how the ITGix AWS Landing Zone can help.

Newsletter for Tech experts

Signal, not noise -

straight to your inbox.

Join 12,000+ engineers and business leaders getting field notes on SRE, DevOps and cloud- native reliability.

Deep-dive tech blogs & case studies
Emerging tech, curated

Your Work Email

We respect your inbox. Read our Privecy Policy

More Posts

Introduction In event-driven Kubernetes architectures, CPU and memory utilization often fail to reflect real system pressure. A worker pod may sit idle from a CPU perspective while thousands of messages...
Reading
Modern infrastructure is becoming exponentially harder to operate. What once worked – a handful of dashboards, static alerts, and engineers jumping into incidents – no longer scales in today’s cloud-native...
Reading
Get In Touch
ITGix provides you with expert consultancy and tailored DevOps services to accelerate your business growth.
Newsletter for
Tech Experts
Join 12,000+ business leaders and engineers who receive blogs, e-Books, and case studies on emerging technology.