UNDER CONFIDENTIALITY AGREEMENT
Kubernetes modernization at a European insurer
Phased migration of 6 production environments to hybrid Kubernetes (on-premise + AWS EKS) with GitOps and observability, maintaining 99.9% availability.
Sector
Insurance · International insurer (Europe)
Technology stack
Kubernetes, RKE2, Rancher Fleet, AWS EKS, GitOps, Prometheus, Grafana, Loki
Project scope
- · Deployment of RKE2 + Rancher on-premise and extension to AWS EKS
- · Adoption of GitOps with Rancher Fleet for environment promotion
- · Full observability with Prometheus, Grafana and Loki
- · Progressive migration with no service interruption to the end client
Measurable impact
- · 99.9% availability throughout the migration
- · 6 environments migrated in controlled phases
- · Final hybrid architecture (on-premise RKE2 + AWS EKS)
Context
An international insurer with operations in Europe needed to migrate the core of its applications to a container platform without stopping service to its policyholders. Six production environments, each with its own dependencies, had to move from traditional infrastructure to hybrid Kubernetes: RKE2 with Rancher on-premise and an extension to AWS EKS.
The main constraint was operational rather than technical: the migration had to coexist with daily activity (underwriting, claims, closes) while keeping services available throughout the transition.
The challenge
The starting point combined three limitations that are common in the sector:
- Manual, poorly traceable deployments across environments, with a risk of configuration drift between development, pre-production and production.
- No shared observability layer: each environment was monitored with different tools.
- The need to scale in the cloud without losing control of the critical systems that had to stay on-premise.
Phased approach
We applied the same phased method we use in banking for hybrid Kubernetes platforms, adapted to the insurer's operating calendar.
-
01
Analysis and design
Workload inventory, definition of the hybrid architecture and sizing of the six environments.
-
02
On-premise deployment
RKE2 and Rancher as the orchestration base, validating the least critical services first.
-
03
Extension to AWS EKS
AWS clusters integrated with the on-premise platform through hybrid connectivity and a single management console.
-
04
GitOps with Rancher Fleet
Declarative promotion between environments: every change versioned, reviewed and reproducible.
-
05
Observability
Prometheus, Grafana and Loki for metrics, alerts and centralised logs across all environments.
-
06
Progressive migration
Environment by environment, with functional validation and a rollback window at each phase, with no interruption of service to the end customer.
Architecture and strategy
The final architecture is hybrid: RKE2 on-premise for the systems that must stay in the insurer's data centre and AWS EKS for the workloads that benefit from cloud elasticity, orchestrated from a single console. GitOps with Rancher Fleet governs promotion between environments and the observability layer is shared by all of them.
Measurable results
Results at the end of the migration:
| Indicator | Before | After |
|---|---|---|
| Availability during the migration | Continuity target | 99.9% |
| Production environments migrated | Traditional infrastructure | 6, in controlled phases |
| Architecture | On-premise silos | Hybrid: RKE2 on-premise + AWS EKS |
| Promotion between environments | Manual | Declarative GitOps (Rancher Fleet) |
Aggregated figures, anonymised under a non-disclosure agreement. Source: Vermont Solutions projects.
Lessons that carry over
- Migrating environment by environment, starting with the least critical, reduces risk and builds confidence for the following phases.
- A single console for on-premise and cloud avoids duplicating teams and procedures.
- GitOps turns every deployment into auditable evidence, something the supervisor values as much as the operations team does.
Regulatory framework
Public cloud use at a European insurer is governed as the outsourcing of a critical service.
- DORA (Art. 28): ICT third-party risk, reversibility and observability of the hybrid platform.
- Solvency II: continuity of the processes that feed supervisory reporting throughout the migration.
Frequently asked questions
Which stack was used?
Kubernetes with RKE2 and Rancher on-premise, AWS EKS, GitOps with Rancher Fleet and observability with Prometheus, Grafana and Loki.
Was service to policyholders interrupted?
No. The migration ran environment by environment with functional validation and a rollback window, keeping 99.9% availability.
Why keep part of the platform on-premise?
Because certain systems had to stay in the insurer's data centre for control and outsourcing requirements. The hybrid platform scales on AWS without giving up that control.
Can I know the insurer and the full figures?
The case is anonymised under a non-disclosure agreement. Architecture details and full figures are shared after signing an NDA.
Related content
Last updated: 2026-09-12
Full figures and architecture are shared upon NDA signing.
Request detail under NDA →