About This Architecture
AWS Secure Reference Architecture (SRA) landing zone spanning two availability zones with centralized governance via AWS Organizations, Control Tower, and SCPs enforcing region and root user restrictions. Traffic flows through CloudFront and WAF to an Application Load Balancer distributing requests across EC2 UI and Workflow Engine instances in public subnets, with ECS Backend Services and Lambda Async Processors in private subnets accessing RDS Oracle primary/standby and DynamoDB Global Tables for data persistence. Security Tooling Account runs GuardDuty, Security Hub, and CloudTrail organization trail; Log Archive Account centralizes audit logs; IAM Identity Center manages user access across member accounts. This architecture demonstrates AWS best practices for compliance, high availability, encryption via KMS, and least-privilege IAM roles. Fork and customize this diagram on Diagrams.so to match your organization's region policies, instance types, and workload requirements. The multi-AZ design with RDS replication and DynamoDB global tables ensures RPO/RTO targets for mission-critical applications.