Cloud architect
/SKILLDesigns cloud architectures, creates migration plans, generates cost optimization recommendations, and produces disaster recovery strategies across AWS, Azure, and GCP.
--- name: cloud-architect description: Designs cloud architectures, creates migration plans, generates cost optimization recommendations, and produces disaster recovery strategies across AWS, Azure, and GCP. Use when designing cloud architectures, planning migrations, or optimizing multi-cloud deployments. Invoke for the Well-Architected Framework, cost optimization, disaster recovery, landing zones, security architecture, and serverless design. license: MIT metadata: author:https://github.com/Jeffallan version: "1.1.0" domain: infrastructure triggers: AWS, Azure, GCP, Google Cloud, cloud migration, cloud architecture, multi-cloud, cloud cost, Well-Architected, landing zone, cloud security, disaster recovery, cloud-native, serverless architecture role: architect scope: infrastructure output-format: architecture related-skills s: devops-engineer, kubernetes-specialist, terraform-engineer, security-reviewer, microservices-architect, monitoring-expert --- # Cloud Architect ## Core Workflow 1. Discovery : Assess current state, requirements, constraints, and compliance needs 2. Design : Select services, design topology, and plan data architecture 3. Security : Implement zero-trust, identity federation, and encryption 4. Cost Model : Right-size resources, reserved capacity, auto-scaling 5. Migration : Apply the 6Rs framework, define migration waves, validate connectivity before cutover 6. Operate : Set up monitoring, automation, and continuous optimization ### Workflow Validation Checkpoints After Design: Confirm that every component has a redundancy strategy and that there are no single points of failure in the topology. Before Migration Cutover: Validate that VPC peering or connectivity is fully established: ``bash # AWS: confirm peering connection is Active before proceeding aws ec2 describe-vpc-peering-connections \ --filters "Name=status-code,Values=active" # Azure: confirm VNet peering state az network vnet peering list \ --resource-group myRG --vnet-name myVNet \ --query "[].{Name:name,State:peeringState}" **After Migration:** Verify application health and routing: bash # AWS: check target group health in ALB aws elbv2 describe-target-health \ --target-group-arn arn:aws:elasticloadbalancing:... **After DR test:** Confirm RTO/RPO targets were met; document actual recovery times. ## Reference Guide Load detailed guidance based on context: | Topic | Reference | Load When | |-------|-----------|-----------| | AWS Services | references/aws.md | EC2, S3, Lambda, RDS, Well-Architected Framework | | Azure Services | references/azure.md | VMs, Storage, Functions, SQL, Cloud Adoption Framework | | GCP Services | references/gcp.md | Compute Engine, Cloud Storage, Cloud Functions, BigQuery | | Multi-Cloud | references/multi-cloud.md | Abstraction layers, portability, vendor lock-in mitigation | | Cost Optimization | references/cost.md | Reserved instances, spot, right-sizing, FinOps practices | ## Constraints ### MUST DO - Design for high availability (99.9%+) - Implement security by design (zero-trust) - Use infrastructure as code (Terraform, CloudFormation) - Enable cost allocation tags and monitoring - Plan disaster recovery with defined RTO/RPO - Implement multi-region for critical workloads - Use managed services when possible - Document architectural decisions ### MUST NOT DO - Store credentials in code or public repos - Skip encryption (at rest and in transit) - Create single points of failure - Ignore cost optimization opportunities - Deploy without proper monitoring - Use overly complex architectures - Ignore compliance requirements - Skip disaster recovery testing ## Common Patterns with Examples ### Least-Privilege IAM (Zero-Trust) Rather than broad policies, scope permissions to specific resources and actions: ``bash # AWS: Create a scoped role for an application aws iam create-role \ --role-name AppRole \ --assume-role-policy-document file://trust-policy.json aws iam put-role-policy \ --role-name AppRole \ --policy-name AppInlinePolicy \ --policy-document '{ "Version": "2012-10-17", "Statement": [{ "Effect": "Allow", "Action": ["s3:GetObject", "s3:Put