Skip to main content

Deployment · Environment choice

Choose the boundary.Keep command.

Run L2H in the environment your organization controls—from operational commercial cloud and IL5 GovCloud to on-prem and disconnected deployment patterns.

YOUR CLOUDON-PREMPRIVATE & AIR-GAPPED PATTERNS

ENVIRONMENT DECISION

01

Connected

OPERATIONAL

AWS · Azure

02

Federal

IL5 IN PRODUCTION

GovCloud

03

Restricted

DEPLOYMENT PATTERN

On-prem · Private

Decision matrix

Match the environment to the operating constraint.

Start with the boundary, connectivity, and authorization posture. The matrix keeps those decisions visible without exposing implementation internals.
ENVIRONMENTBEST FITPOSTURECONTROL NOTE
AWS

Commercial and enterprise teams standardized on AWS

Operational

Customer-hosted commercial deployment

Azure

Commercial and enterprise teams standardized on Microsoft cloud

Operational

Customer-hosted commercial deployment

GovCloud

Federal and defense environments operating at IL5

IL5 in production

Accreditation is held by the deploying customer or sponsor

Kubernetes

Organizations standardizing deployment across infrastructure

Portable pattern

Designed to fit customer-managed environments

On-prem

Customer-controlled data centers and restricted networks

Controlled pattern

Supports connected or disconnected deployment designs

Private routing

Environments requiring private endpoints and tighter boundaries

High-assurance pattern

Designed for restricted and classified-ready architectures

Three decisions

The right deployment startswith the operating boundary.

DECISION 01

Where must the platform run?

Choose the cloud, on-prem environment, or restricted boundary your organization already operates and approves.

DECISION 02

How connected can the environment be?

Use a standard connected deployment, private routing, or an air-gapped pattern according to mission and network constraints.

DECISION 03

Who owns authorization?

The deploying customer or sponsoring agency owns accreditation and authorizes the system inside its operating environment.

COMMERCIAL

Connected cloud

Operational on AWS and Azure for commercial and enterprise deployments.

FEDERAL

GovCloud

IL5 in production on GovCloud, within the customer or sponsor authorization boundary.

HIGH ASSURANCE

Private or disconnected

Air-gapped, classified-ready, and IL6+ deployment patterns designed for customer-controlled environments.

Capability and deployment-pattern language does not represent an accreditation. Authorization remains with the deploying customer or sponsoring agency.

Customer-controlled operations

Your environment sets the rules.

Deployment aligns to the identity, network, access, audit, and operational controls the customer already manages.

  • Customer-selected cloud or on-prem environment
  • Customer-controlled identity and access boundary
  • Private-routing and disconnected deployment patterns
  • Commercial AWS and Azure operational today
  • Federal IL5 in production on GovCloud
  • Customer or sponsor retains accreditation responsibility

Map your boundary

Choose the environment before the architecture.

Bring your cloud, network, and authorization constraints to a deployment walkthrough.