Shopwave's EKS landing zone
This diagram is a reference landing zone for Shopwave's orders and loyalty services. In the VPC, three private subnets (one per zone) host the nodes, which Karpenter manages, and the Pods consume VPC IPs from them, with a secondary CIDR reserved for Pods so that node subnets are not consumed. Public subnets host the ALB and NLB created by the Load Balancer Controller. EKS ENIs connect the managed control plane, and VPC endpoints give private access to ECR, S3 and STS.
Around the cluster: ECR holds scanned, signed images; Secrets Manager with KMS holds credentials that the External Secrets Operator syncs; RDS multi-AZ holds relational data, reachable only from Pods that have the right security group through security groups for pods; CloudWatch and Managed Prometheus provide audit logs and SLO dashboards. Reveal the groups with the right arrow.
Notice which decisions from earlier modules show up: subnet sizing and prefix delegation (Module 3), identity through Pod Identity roles (Module 4), EBS volumes in a zone (Module 5), and the operations stack (Module 6). A landing zone is the place where these choices are encoded once, in Terraform, and reused for every new cluster.
What is missing deliberately is any long-lived credential, any public node, and any manually created resource. The cluster itself, the add-ons configuration and the IAM roles come from code; the workloads come from GitOps.