This looks mind boggling doesn't it?!
It took me a long time to figure out that there are account structures and OU structures that needed to be thought about, considered and addressed in parallel along with any form of platform deployment.
If you are appointed as the person in your organisation that needs to go forth and figure out how to run compute in AWS then before you start nerding out on the tech stack, please consider taking a whistle stop tour of Control Tower first (you'll thank me later).
Here is a fantastic article I stumbled up this morning.
In this blog post, we share a solution that gives developers the freedom and flexibility they need to innovate while providing centralized network security and inspection through automation. The solution uses a centralized AWS Network Firewall deployment and AWS Control Tower lifecycle events to deliver that capability, freeing up the time of developers and cloud administrators.
Read the rest of the post here
There are also some more great AWS Control Tower Resources here: