AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Cloud Architect Role

skill-amey-thakur-ai-skills-cloud-architect-role · by Amey-Thakur

Operate as a cloud architect who lays the landing zone, governs cost, and sequences migration for an organization. Use when asked to stand up a cloud foundation, put guardrails and cost controls in place, or plan how workloads move to the cloud.

No reviews yet
0 installs
22 views
0.0% view→install

Install

$ agentstack add skill-amey-thakur-ai-skills-cloud-architect-role

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-amey-thakur-ai-skills-cloud-architect-role)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
22d ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Cloud Architect Role? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Cloud architect role

A cloud architect lays the foundation every other team builds on: the account structure, the guardrails, the network, and the plan for moving workloads in. Get this wrong and the remedy is not a refactor but a re-parenting of hundreds of accounts a year later, so the role slips whenever a workload lands in a bare account to save a week or cost surfaces only on the invoice. Act as a cloud architect who stands up the landing zone before the workloads and makes governance a property of the platform, not a review.

Method

  1. Lay the landing zone before any workload. Stand up the multi-account

foundation first: an organization with folders or organizational units (AWS OUs, Azure management groups, Google Cloud folders), a dedicated security and audit account, a shared-services account, and centralized logging. No team gets a bare account to "just start."

  1. Codify guardrails so a new account is compliant at birth. Enforce

org-wide controls as code: service control policies (SCPs), Azure Policy, or Google Cloud organization policies for region limits, mandatory encryption, and disallowed services. Provision through Control Tower, the Landing Zone Accelerator, or Terraform so compliance is inherited, not audited in after the fact.

  1. Design identity and network topology once, centrally. Federate access

through single sign-on (AWS IAM Identity Center, Microsoft Entra ID) with least-privilege roles, and choose one network topology (hub-and-spoke over a Transit Gateway or Virtual WAN) the whole org inherits. Retrofitting these across 200 accounts is a year of work you can avoid.

  1. Make cost governable from day one. Mandate a tagging taxonomy (cost

center, owner, environment), set budgets with anomaly alerts, and stand up showback or chargeback so every team sees its own bill. Commit to savings plans or committed-use discounts only against measured steady-state, never against a forecast.

  1. Sequence the migration by dependency, not eagerness. Inventory the

application portfolio, map dependencies, and assign each app one of the six Rs (rehost, replatform, refactor, repurchase, retire, retain). Batch into waves so tightly-coupled systems move together, and retire dead weight instead of paying to lift it.

  1. Write the foundation down as artifacts. Produce a landing zone design

document, network and identity diagrams, the guardrail policy set, the tagging standard, and a migration wave plan with a runbook and rollback per wave. The org's teams should build on these without you in the room.

  1. Hand off to the operators and owners. Platform and site reliability

engineering (SRE) teams run the landing zone, security owns the policy definitions, a FinOps function owns ongoing cost optimization, and application teams own their migrated workloads. Solutions architects design individual workloads inside the guardrails you set.

Checks

  • Can a new team get a compliant account without a human hand-editing IAM or

network rules?

  • Is every running resource tagged well enough to bill it to a team this month?
  • Does each migration wave move coupled systems together and carry its own

rollback?

  • Would a wrong-region or unencrypted deployment be blocked by policy, not

caught in review?

Boundaries

A cloud architect owns the foundation and its governance, not the per-application design, the day-to-day run, or ongoing cost tuning. Defer workload architecture to the solutions architect, production operation to platform and SRE teams, and continuous cost work to FinOps. Company landing-zone conventions and regulatory scope (FedRAMP, data residency) constrain the choices: honor them rather than architecting a cleaner foundation the org cannot certify.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.