binbash

Cloud Migration and Landing Zone

Prisma

Migrating and Enabling Prisma’s Cloud-Native Foundation on AWS

Prisma Retail AI is a retail technology company that gives brands and retailers AI-driven insights for pricing, promotions and in-store execution, combining machine learning with real-time analytics across global markets.

binbash planned and executed the full migration from Prisma’s previous cloud environment to AWS, establishing a modern multi-account AWS Landing Zone and deploying a containerized development environment on Amazon EKS — all designed in alignment with the AWS Well-Architected Framework.

Expanding an AI platform without a governed cloud

As Prisma expanded its AI capabilities and platform footprint, its infrastructure faced several challenges:

  • A lack of centralized governance across multiple environments and AWS accounts.

  • Manual and fragmented infrastructure provisioning, limiting developer productivity.

  • Security inconsistencies that could hinder compliance-readiness and operational resilience.

  • No unified container orchestration strategy for managing services in a scalable way.

A multi-account Landing Zone, every resource as code

binbash implemented an AWS-native architecture using its open-source Leverage™ framework and the AWS Well-Architected Framework: a secure multi-account AWS Landing Zone, Amazon EKS for container orchestration, and fully automated infrastructure delivered with Terraform.

  • AWS Landing Zone: Dedicated accounts for management, shared services, security and development workloads, governed via AWS Organizations and Service Control Policies.

  • Identity & Access Management: Centralized login and role-based permissions using AWS IAM Identity Center, with preconfigured permission sets for developer and DevOps roles across all accounts.

  • Amazon EKS (Dev): A development cluster on managed node groups with spot instances for cost optimization, and workload isolation via namespaces, RBAC and network policies.

  • Security Baseline: Organization-wide encrypted volumes, MFA, IAM Access Analyzer, VPC flow logs and secure S3 policies, with centralized CloudTrail and KMS-based encryption.

  • Infrastructure as Code: Every resource defined with Terraform modules from the binbash Leverage™ framework, for reproducibility, modularity and compliance.

What Prisma runs today

4
AWS accounts under one OrganizationManagement, shared services, security and development, governed by SCPs.
100%
of the platform defined in TerraformEvery resource from binbash Leverage™ modules — reproducible and auditable.
1
legacy cloud provider retiredCritical workloads migrated onto AWS in full.
  • A containerized development environment on Amazon EKS, enabling faster and more reliable service deployments.

  • Higher developer productivity through GitOps, VPN-secured private access and automated provisioning.

  • A stronger security posture and auditability, with centralized logging, IAM policies and encryption.

  • An internal engineering team onboarded through documentation and demo sessions for long-term autonomy.

Damián BarlettaCTO, Prisma

“A committed and highly capable team, available throughout the project and through to its completion.”

Delivered in five milestones

  • Landing Zone Setup: A multi-account AWS architecture with governance, security and networking layers.

  • EKS Deployment: A development Kubernetes cluster with its supporting tools and integrations.

  • VPN & Secure Access: Pritunl-based private access and DNS resolution across environments.

  • CI/CD Tooling: ArgoCD and its GitOps components, automating service lifecycle management.

  • Documentation & Demos: Full documentation, IaC repositories and weekly delivery demos.

A foundation for production workloads

With binbash’s Leverage™ reference architecture, Prisma migrated from a legacy cloud provider to AWS and now runs a modern, secure and scalable foundation for its AI-powered retail platform, aligned with the AWS Well-Architected Framework — with operational improvements in security, deployment automation, cost efficiency and cloud governance.

Planning a migration to AWS?