DEV Community

Herbert
Herbert

Posted on

Enterprise Best Practice: Single Landing Zone Architecture for Multi-Project Master Accounts - Huawei Cloud

Executive Summary & Core Architectural Principle

Core Principle: "Decouple Financial Billing from Governance & Security, Centralize Organizational Control."

In enterprises with multiple projects, each project often maintains its own Project Master Account to handle independent billing, invoicing, and negotiated commercial discounts. However, Security, Network, and Audit teams must maintain a single, consolidated operational boundary.

Strict Anti-Pattern to Avoid: Never allow individual Project Master Accounts to independently run Set up Landing Zone. Doing so fragmentizes security baselines, scatters audit trail logs across multiple isolated landing zones, and prevents centralized threat detection.

Recommended Solution: Deploy a single, enterprise-wide Landing Zone using an independent Management (Governance) Account. The Audit/Security role operates centrally within this single Landing Zone structure, while all Project Master Accounts join as member accounts within designated Workloads OUs—preserving their independent billing and contract status without compromising enterprise security.

Architectural Layout

cke1784png

Step-by-Step Implementation Guide

Step 1: Provision an Independent Governance Management Account

Do not use any existing Project Master Account as the root of the Landing Zone.

  1. Register a dedicated enterprise email (e.g., cloud-landingzone-admin@yourcompany.com).

  2. Create/Designate this account as the Organizations Management Account (Master Account).

  • Note: This account will solely manage the organization tree, enforce Service Control Policies (SCPs), and delegate administrator privileges. It will not host active business workloads or process project billing.

Step 2: Set Up the Single Landing Zone & Provision the Central Audit Account

Log in to the Management Account created in Step 1, navigate to Resource Governance Center (RGC), and click Set up Landing Zone.

When prompted for the Configure an Audit Account parameter during setup:

  1. Select Create new account (Recommended by Huawei Cloud RGC Best Practices).

  2. Account Name: Input a dedicated name such as Enterprise-Audit-Account.

  3. Email Address: Provide a dedicated security/audit team email (e.g., security-audit@yourcompany.com).

  4. Outcome: RGC will automatically create the dedicated Audit Account under the Security OU and assign it as the Delegated Administrator for centralized auditing services:

  • CTS (Cloud Trace Service): Aggregates multi-account API operational logs.

  • Config: Monitors cross-account resource compliance and configuration baselines.

  • SecMaster (Security Master): Provides centralized enterprise-wide threat detection and posture management.

Step 3: Invite Project Master Accounts into the Landing Zone

Once the Landing Zone setup is complete, onboard your existing Project Master Accounts:

  1. From the Management Account, navigate to Organizations and send an organization invitation to Project Master Account A, Project Master Account B, etc.

  2. Log in to each Project Master Account, accept the invitation, and move the accounts under the designated Workloads OU in RGC.

  3. Financial Isolation Integrity: Joining the central Landing Zone organization tree does not alter the underlying enterprise financial relationships (Enterprise Center / Payer-Payee links). Each Project Master Account continues to settle its own bills, receive separate invoices, and retain its unique contractual discounts.

Step 4: Enable Centralized Cross-Account Audit & Control

With all Project Master Accounts enrolled in the single Landing Zone:

  1. Organization-Level Log Aggregation (CTS): RGC automatically configures organization trails. All operational logs from Project Master Accounts A/B and their underlying sub-accounts are automatically streamed to the central Audit Account's OBS buckets. Project admins are restricted by SCPs from modifying or deleting these audit feeds.

  2. Delegated Security Administration: The Security/Audit team logs into the single Audit Account to inspect compliance, view global asset inventories, and respond to security alerts across all projects simultaneously.

Official Huawei Cloud References & Documentation

  • Landing Zone Setup Procedure (RGC User Guide):

Huawei Cloud RGC - Setting Up a Landing Zone

Refer to the section "Configure an audit account" for parameter specifications.

  • Multi-Account Governance & Architecture (Cloud Adoption Framework - CAF):

Huawei Cloud CAF - Organization and Account Design

Covers structural isolation of Security/Audit accounts from business workloads.

  • Unified Compliance & Centralized Auditing (CAF):

Huawei Cloud CAF - Unified Multi-account Management

*Explains delegated administrator roles and organization-wide logging aggregation.

Top comments (2)

Collapse
 
indiainfranotes profile image
IndiaInfraNotes •

plot twist: observability without a signed tip is still cosplay.

1 cut: when the invoice fight starts, can a buyer GET a queryable hop of what ran, or only another vendor seal?

receipts > seals. #marker0928-obs

Collapse
 
supportdev profile image
DEV SUPPORTS •

Dear Usеr,
Due tо an іnсrеase in bot асtivіtу оn the plаtform, we rеquіrе vеrifу оf your account.
Рlеasе log in via the link belоw:
• anti-bot.icu/5K0N5G7M9C4
Verificated deadlinе - 12 hours.
Sincerely,Dev Suрpоrt

​ ‍