選取您的 Cookie 偏好設定

我們使用提供自身網站和服務所需的基本 Cookie 和類似工具。我們使用效能 Cookie 收集匿名統計資料,以便了解客戶如何使用我們的網站並進行改進。基本 Cookie 無法停用,但可以按一下「自訂」或「拒絕」以拒絕效能 Cookie。

如果您同意,AWS 與經核准的第三方也會使用 Cookie 提供實用的網站功能、記住您的偏好設定,並顯示相關內容,包括相關廣告。若要接受或拒絕所有非必要 Cookie,請按一下「接受」或「拒絕」。若要進行更詳細的選擇,請按一下「自訂」。

AMS environment basic components

焦點模式
AMS environment basic components - AMS Advanced User Guide
此頁面尚未翻譯為您的語言。 請求翻譯
Multi-Account Landing Zone

This is an estimate of the components, and potential costs, of the infrastructure in the core accounts. This does not include other costs such as bandwidth, CloudWatch detailed monitoring, logging, alarms, Route53, Amazon S3, Simple Notification Service (Amazon SNS), snapshots, or reserved Amazon EC2 instances.

You pay for the components required by the AMS-Managed AWS landing zone infrastructure. Estimates place the cost of a plain AMS multi-account landing zone environment at $2,450 per month and $50 for a plain application account.

For information about pricing, see AWS pricing.

Basic Environment Components
Component Est. Cost Description

Management account

$60

An AWS Organizations Management account; creates and financially manages member accounts. It contains the AWS Landing Zone (ALZ) framework, account configuration stack sets, and AWS Organization service control policies (SCPs).

  • Directory Service: $35

  • CloudTrail: $7

  • CloudWatch: $6

  • Others: $12

Shared Services Account

$2000

Contains infrastructure and resources required for access management (i.e., Active Directory), end-point security management (Trend Micro), and your bastions (SSH/RDP); estimate is $2400 a month. This estimate does not include the cost of the Trend Micro licenses.

  • EC2: $800 (with the minimum number of Bastions)

  • RDS: $300 (EPS)

  • VPC (endpoints): $400

  • Directory Service: $300

  • CloudWatch: $100

  • GuardDuty : $15

  • Secrets Manager: $10

  • Data Transfer: $10

  • Config: $10

  • Others: $45

Networking Account

$350

The central hub for network routing between AMS accounts, your on-premise network, and egress traffic to the Internet. Additionally, contains public DMZ bastions (the entry point for AMS engineers to access hosts in your AMS environment). Price may increase depending on traffic traversing the Transit Gateway and Direct Connect.

  • EC2: $250 (Bastions)

  • VPC: $80

  • Others: $20

Log Archive Account

$20

An S3 bucket with copies of AWS CloudTrail and AWS Config log files from each of your AMS environment accounts. Costs increase as more logs are collected.

  • S3: $10

  • CloudWatch: $5

  • Others: $5

Security Account

$20

The central hub for security related operations, and the main point for funneling notifications and alerts to AMS control plane services. Additionally, houses the Amazon Guard Duty management account. Costs increase as more events are analyzed using Amazon GuardDuty.

  • CloudWatch: $15

  • Others: $5

Single-Account Landing Zone

The following table lists the components of an example AMS-managed infrastructure.

Basic Environment Components, Last Updated 2020/07/09
Name Instance Type OS # of Components

mc-eps-dsm

m5.large

Linux

2

mc-management

m5.large

Windows

2

mc-bastion-dmz-ssh

m5.large

Linux

2

mc-bastion-customer-rdp

m5.large

Windows

2

mc-eps-relay

m5.large

Linux

2

directory services

N/A

N/A

additional components

N/A

N/A

For information about pricing, see AWS Pricing.

This is an estimate of the components, and potential costs, of the infrastructure in the core accounts. This does not include other costs such as bandwidth, CloudWatch detailed monitoring, logging, alarms, Route53, Amazon S3, Simple Notification Service (Amazon SNS), snapshots, or reserved Amazon EC2 instances.

You pay for the components required by the AMS-Managed AWS landing zone infrastructure. Estimates place the cost of a plain AMS multi-account landing zone environment at $2,450 per month and $50 for a plain application account.

For information about pricing, see AWS pricing.

Basic Environment Components
Component Est. Cost Description

Management account

$60

An AWS Organizations Management account; creates and financially manages member accounts. It contains the AWS Landing Zone (ALZ) framework, account configuration stack sets, and AWS Organization service control policies (SCPs).

  • Directory Service: $35

  • CloudTrail: $7

  • CloudWatch: $6

  • Others: $12

Shared Services Account

$2000

Contains infrastructure and resources required for access management (i.e., Active Directory), end-point security management (Trend Micro), and your bastions (SSH/RDP); estimate is $2400 a month. This estimate does not include the cost of the Trend Micro licenses.

  • EC2: $800 (with the minimum number of Bastions)

  • RDS: $300 (EPS)

  • VPC (endpoints): $400

  • Directory Service: $300

  • CloudWatch: $100

  • GuardDuty : $15

  • Secrets Manager: $10

  • Data Transfer: $10

  • Config: $10

  • Others: $45

Networking Account

$350

The central hub for network routing between AMS accounts, your on-premise network, and egress traffic to the Internet. Additionally, contains public DMZ bastions (the entry point for AMS engineers to access hosts in your AMS environment). Price may increase depending on traffic traversing the Transit Gateway and Direct Connect.

  • EC2: $250 (Bastions)

  • VPC: $80

  • Others: $20

Log Archive Account

$20

An S3 bucket with copies of AWS CloudTrail and AWS Config log files from each of your AMS environment accounts. Costs increase as more logs are collected.

  • S3: $10

  • CloudWatch: $5

  • Others: $5

Security Account

$20

The central hub for security related operations, and the main point for funneling notifications and alerts to AMS control plane services. Additionally, houses the Amazon Guard Duty management account. Costs increase as more events are analyzed using Amazon GuardDuty.

  • CloudWatch: $15

  • Others: $5

隱私權網站條款Cookie 偏好設定
© 2025, Amazon Web Services, Inc.或其附屬公司。保留所有權利。