Overview
LARA (Labyrinth Labs Reference Architecture) is a professional services engagement that delivers a complete, production-grade AWS landing zone and cloud-native platform tailored to your workloads. Built on AWS best practices and open-source tooling, LARA is composed of modular, fully customizable Infrastructure as Code components — so you launch quickly, scale reliably, and retain full ownership of the codebase and intellectual property.
The engagement covers the entire AWS foundation: multi-account governance with AWS Organizations, AWS IAM Identity Center (SSO), AWS CloudTrail and Service Control Policies; VPC networking with public/private subnets, NAT, Transit Gateway, VPC Peering, Wireguard VPN and encrypted AWS Systems Manager Session Manager access; a battle-hardened Amazon EKS setup supporting self-managed, EKS-managed and AWS Fargate node groups with spot instances for up to ~60% EC2 cost savings; and a rich ArgoCD-managed addon ecosystem including cluster-autoscaler, Karpenter, external-dns, cert-manager, metrics-server, External Secrets, Vector, Linkerd, Argo Rollouts, Crossplane, KEDA and the EFS/EBS CSI drivers.
LARA also delivers data services using Amazon RDS / Aurora, Amazon ElastiCache, Amazon Redshift, Amazon EFS and Amazon S3; messaging and streaming via Amazon MSK (Kafka), Amazon SQS/SNS and RabbitMQ; full observability with Amazon CloudWatch, Prometheus, Thanos, Grafana, Loki, Tempo and Amazon OpenSearch Service; advanced networking with Amazon CloudFront and Amazon Route 53; and GitOps continuous deployment using ArgoCD, Argo Rollouts, Amazon ECR and self-hosted GitLab CI / GitHub Actions runners. Security and compliance are built-in across all layers: workload isolation, fine-grained IAM, encryption in-transit and at-rest, automated infrastructure scans and SAST checks.
The engagement is delivered by certified AWS architects and DevOps engineers (AWS Solutions Architect Professional, DevOps Engineer Professional, Security Specialty and more). Co-funding is available through AWS programs such as MAP, Activate and POA. The service relates to and integrates with the following AWS services: Amazon EKS, Amazon EC2, Amazon VPC, AWS Organizations, AWS IAM Identity Center, Amazon RDS / Aurora, Amazon ElastiCache, Amazon Redshift, Amazon S3, Amazon EFS, Amazon MSK, Amazon SQS, Amazon SNS, Amazon CloudWatch, Amazon OpenSearch Service, Amazon Route 53, Amazon CloudFront, AWS Secrets Manager, AWS Systems Manager, AWS CloudTrail, AWS KMS and Amazon ECR.
Highlights
- Complete AWS landing zone in weeks, not months — multi-account AWS Organization, VPC networking, battle-hardened Amazon EKS, observability, databases and GitOps CI/CD delivered as fully customizable Infrastructure as Code that you own.
- Built and operated by AWS Advanced Tier Services Partner and back-to-back Consulting Partner of the Year 2024 & 2025 CEE — certified architects, AWS best practices and proven delivery across banking, SaaS, gaming and insurance workloads.
- Modular addon ecosystem on Amazon EKS — ArgoCD, Karpenter, cluster-autoscaler, external-dns, cert-manager, External Secrets, Linkerd, Crossplane, KEDA and more — with spot-instance support cutting EC2 costs by up to ~60%.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Pricing
Custom pricing options
How can we make this page better?
Legal
Content disclaimer
Resources
Support
Vendor support
Labyrinth Labs provides expert support for all LARA engagements, delivered by certified AWS architects and DevOps engineers.
Contact channels: • Email: contact@lablabs.io • Phone: +421 221 020 694 • Web: https://lablabs.io • Schedule an intro call: https://calendar.app.google/PY5SSfSMuk3VvBZeA
Standard engagement includes scoping and assessment, architecture design, IaC implementation, deployment, knowledge transfer and post-launch hand-over. Ongoing managed services and expert consulting are available on request, with SLAs agreed per customer based on workload criticality.