Architecture model

Start from requirements and threats, identify trust boundaries, define control objectives and then choose technologies. Architecture should explain not only what is deployed, but why.

Requirements → Threats → Boundaries → Controls → Technology → Operations

Design principle

Prefer simple boundaries, least privilege, observable controls and reversible decisions. A technically elegant design that cannot be operated securely is not a complete architecture.