Cloud Migration and Landing Zone

Migrating and Enabling Prisma’s Cloud-Native Foundation on AWS
Prisma Retail AI is a retail technology company that gives brands and retailers AI-driven insights for pricing, promotions and in-store execution, combining machine learning with real-time analytics across global markets.
binbash planned and executed the full migration from Prisma’s previous cloud environment to AWS, establishing a modern multi-account AWS Landing Zone and deploying a containerized development environment on Amazon EKS — all designed in alignment with the AWS Well-Architected Framework.
Expanding an AI platform without a governed cloud
As Prisma expanded its AI capabilities and platform footprint, its infrastructure faced several challenges:
A lack of centralized governance across multiple environments and AWS accounts.
Manual and fragmented infrastructure provisioning, limiting developer productivity.
Security inconsistencies that could hinder compliance-readiness and operational resilience.
No unified container orchestration strategy for managing services in a scalable way.
A multi-account Landing Zone, every resource as code
binbash implemented an AWS-native architecture using its open-source Leverage™ framework and the AWS Well-Architected Framework: a secure multi-account AWS Landing Zone, Amazon EKS for container orchestration, and fully automated infrastructure delivered with Terraform.
AWS Landing Zone: Dedicated accounts for management, shared services, security and development workloads, governed via AWS Organizations and Service Control Policies.
Identity & Access Management: Centralized login and role-based permissions using AWS IAM Identity Center, with preconfigured permission sets for developer and DevOps roles across all accounts.
Amazon EKS (Dev): A development cluster on managed node groups with spot instances for cost optimization, and workload isolation via namespaces, RBAC and network policies.
Security Baseline: Organization-wide encrypted volumes, MFA, IAM Access Analyzer, VPC flow logs and secure S3 policies, with centralized CloudTrail and KMS-based encryption.
Infrastructure as Code: Every resource defined with Terraform modules from the binbash Leverage™ framework, for reproducibility, modularity and compliance.
What Prisma runs today
- 4
- AWS accounts under one OrganizationManagement, shared services, security and development, governed by SCPs.
- 100%
- of the platform defined in TerraformEvery resource from binbash Leverage™ modules — reproducible and auditable.
- 1
- legacy cloud provider retiredCritical workloads migrated onto AWS in full.
A containerized development environment on Amazon EKS, enabling faster and more reliable service deployments.
Higher developer productivity through GitOps, VPN-secured private access and automated provisioning.
A stronger security posture and auditability, with centralized logging, IAM policies and encryption.
An internal engineering team onboarded through documentation and demo sessions for long-term autonomy.
“A committed and highly capable team, available throughout the project and through to its completion.”
Delivered in five milestones
Landing Zone Setup: A multi-account AWS architecture with governance, security and networking layers.
EKS Deployment: A development Kubernetes cluster with its supporting tools and integrations.
VPN & Secure Access: Pritunl-based private access and DNS resolution across environments.
CI/CD Tooling: ArgoCD and its GitOps components, automating service lifecycle management.
Documentation & Demos: Full documentation, IaC repositories and weekly delivery demos.
A foundation for production workloads
With binbash’s Leverage™ reference architecture, Prisma migrated from a legacy cloud provider to AWS and now runs a modern, secure and scalable foundation for its AI-powered retail platform, aligned with the AWS Well-Architected Framework — with operational improvements in security, deployment automation, cost efficiency and cloud governance.

