Global InfraGlobal Infra Cloud

Getting Started

From requesting a tenant to provisioning your first resource — the full onboarding journey on Global Infra Cloud.

Edit

How onboarding works

Getting started on Global Infra involves three roles working in sequence:

RoleWhoWhat they do
Tenant OwnerThe architect or tech lead who sponsors the projectRequests the tenant, attends the onboarding committee, manages environment access rights
GGO OwnerTeam lead or line managerCreates user groups (GGO), adds and removes team members
Team MemberEvery engineer on the projectSets up personal access (VPN, workspace, Console) and provisions resources

For Tenant Owners

Pass the Architecture Review Board (ARB)

All cloud migrations require approval from the Architecture Review Board (ARB). The ARB validates your architecture against company standards and provides design support.

Submit your architecture for review — the ARB checks completion, compliance, and best practices.

Get approved and prepare for the Onboarding Committee

Once the ARB approves your request, contact the Global Infra team. They will:

  • Create a Jira ticket with all onboarding details (do not create this yourself — it will be rejected)
  • Invite your sponsoring architect to the GI Onboarding Committee, which meets every 2 weeks

The Onboarding Committee (GI management level) performs a final review to check coverage, suggest new services, verify cloud best practices, and plan capacity.

Have the following ready for the committee:

  • ARB Jira ticket
  • ARB Confluence page (with architecture diagram)
  • Tenant owner name(s)
  • Legal Entity Code (for billing)
  • Sizing estimates (compute, databases, storage)

Receive your tenant

Once the committee gives the green light, your tenant is created. You will receive:

  • Your tenant with sandbox, preproduction, and production environments
  • A dedicated Slack channel (#globalinfra-<tenantname>) where GI sends all communications
  • Access to the Console to manage your tenant’s access rights and assign roles to GGO groups

For Team Members

Once your tenant exists and your GGO owner has added you to a group, follow these steps to get up and running.

Get access

You need an OKTA user account and VPN access to connect to GI environments. Your GGO owner adds you to the group — you then set up NetBird for VPN connectivity.

Access & VPN guide

Configure your workspace

Set up your DNS, proxy settings, certificates, and SSH keys for your environment.

Workspace configuration

Sign in to the Console

Navigate to the Global Infra Cloud Console and sign in with your OKTA credentials. Select the tenant and environment you want to work with.

Environments & Git guide

Provision your first resource

Browse the service catalog, pick a service, and provision resources through the Console UI or via Terraform. Most resources are ready in minutes.

Service Catalog


Identity & Access Management

Global Infra uses a group-based IAM model. Permissions are never assigned to individual accounts — they are assigned to GGO groups via roles.

Key concepts

ConceptDescription
GGO (Global Group Organisational)A group of users matching an official organization structure. All members share the same roles and permissions.
GGO OwnerThe team lead or manager who manages group membership — adds/removes users via the Console.
Environment OwnerThe tenant owner who decides which GGO groups get which roles on each environment.
RoleA combination of platform (sandbox / preprod / prod), namespace, and privilege level.

Available roles

RoleDescription
sysadminFull server administration — build, erase, admin access, manage infra code
appsApplication support team
dbaDatabase administration (tenant-managed engines)
securitySecurity officer — server access and audit log review
operatorsLevel 1 support
netadminNetwork administrator — connectivity checks and config review

These roles apply when databases are provided by GI as Database as a Service. Each role includes the privileges of the ones below it.

RoleDescription
dbaas-admFull database operations including DDL (create tables, sequences, etc.)
dbaas-rwRead and write data (insert, update)
dbaas-roRead-only access (select)
RoleDescription
netonlyNetwork access to the environment without server access — useful for application admin portals
obsAccess to observability tools (telemetry, logs) without other permissions — for users depending on services outside their environment

A user must belong to exactly one GGO group. Only the GGO owner can manage membership, and only the environment owner can assign roles. These constraints ensure auditability and separation of duties.


On this page