Network Foundation, $32M Program
Segmented VPCs on a Transit Gateway hub. Centralized inspection and egress. Built into the landing zone.
- $32M
- program on the network
- 0
- spoke internet gateways
- NIST
- SP 800-53 alignment
solid = account · long dash = VPC · short dash = zone or planned
Context
- $32M program; multiple workload teams; one shared network fabric.
- Isolation, inspection, and egress control required before first deploy.
- Had to integrate with the existing landing zone, not sit beside it.
Decision
- Hub-and-spoke: every workload VPC attaches to one Transit Gateway.
- TGW route tables enforce segmentation; spokes never talk directly.
- All outbound traffic hairpins through a central inspection VPC.
- Single egress path; no spoke owns an internet gateway.
Outcome
- Foundation carries the $32M program; teams deploy inside the guardrails.
- One inspection point; one egress; NIST-aligned security baselines by default.
- New spokes attach through the vended landing-zone pattern.