Skip to main content
Vermont Solutions

UNDER CONFIDENTIALITY AGREEMENT

Kubernetes modernization at a European insurer

Phased migration of 6 production environments to hybrid Kubernetes (on-premise + AWS EKS) with GitOps and observability, maintaining 99.9% availability.

Sector

Insurance · International insurer (Europe)

Technology stack

Kubernetes, RKE2, Rancher Fleet, AWS EKS, GitOps, Prometheus, Grafana, Loki

Project scope

  • · Deployment of RKE2 + Rancher on-premise and extension to AWS EKS
  • · Adoption of GitOps with Rancher Fleet for environment promotion
  • · Full observability with Prometheus, Grafana and Loki
  • · Progressive migration with no service interruption to the end client

Measurable impact

  • · 99.9% availability throughout the migration
  • · 6 environments migrated in controlled phases
  • · Final hybrid architecture (on-premise RKE2 + AWS EKS)

Context

An international insurer with operations in Europe needed to migrate the core of its applications to a container platform without stopping service to its policyholders. Six production environments, each with its own dependencies, had to move from traditional infrastructure to hybrid Kubernetes: RKE2 with Rancher on-premise and an extension to AWS EKS.

The main constraint was operational rather than technical: the migration had to coexist with daily activity (underwriting, claims, closes) while keeping services available throughout the transition.

The challenge

The starting point combined three limitations that are common in the sector:

  • Manual, poorly traceable deployments across environments, with a risk of configuration drift between development, pre-production and production.
  • No shared observability layer: each environment was monitored with different tools.
  • The need to scale in the cloud without losing control of the critical systems that had to stay on-premise.

Phased approach

We applied the same phased method we use in banking for hybrid Kubernetes platforms, adapted to the insurer's operating calendar.

  1. 01

    Analysis and design

    Workload inventory, definition of the hybrid architecture and sizing of the six environments.

  2. 02

    On-premise deployment

    RKE2 and Rancher as the orchestration base, validating the least critical services first.

  3. 03

    Extension to AWS EKS

    AWS clusters integrated with the on-premise platform through hybrid connectivity and a single management console.

  4. 04

    GitOps with Rancher Fleet

    Declarative promotion between environments: every change versioned, reviewed and reproducible.

  5. 05

    Observability

    Prometheus, Grafana and Loki for metrics, alerts and centralised logs across all environments.

  6. 06

    Progressive migration

    Environment by environment, with functional validation and a rollback window at each phase, with no interruption of service to the end customer.

Architecture and strategy

The final architecture is hybrid: RKE2 on-premise for the systems that must stay in the insurer's data centre and AWS EKS for the workloads that benefit from cloud elasticity, orchestrated from a single console. GitOps with Rancher Fleet governs promotion between environments and the observability layer is shared by all of them.

Measurable results

Results at the end of the migration:

Indicator Before After
Availability during the migration Continuity target 99.9%
Production environments migrated Traditional infrastructure 6, in controlled phases
Architecture On-premise silos Hybrid: RKE2 on-premise + AWS EKS
Promotion between environments Manual Declarative GitOps (Rancher Fleet)

Aggregated figures, anonymised under a non-disclosure agreement. Source: Vermont Solutions projects.

Lessons that carry over

  • Migrating environment by environment, starting with the least critical, reduces risk and builds confidence for the following phases.
  • A single console for on-premise and cloud avoids duplicating teams and procedures.
  • GitOps turns every deployment into auditable evidence, something the supervisor values as much as the operations team does.

Regulatory framework

Public cloud use at a European insurer is governed as the outsourcing of a critical service.

  • DORA (Art. 28): ICT third-party risk, reversibility and observability of the hybrid platform.
  • Solvency II: continuity of the processes that feed supervisory reporting throughout the migration.

Frequently asked questions

Which stack was used?

Kubernetes with RKE2 and Rancher on-premise, AWS EKS, GitOps with Rancher Fleet and observability with Prometheus, Grafana and Loki.

Was service to policyholders interrupted?

No. The migration ran environment by environment with functional validation and a rollback window, keeping 99.9% availability.

Why keep part of the platform on-premise?

Because certain systems had to stay in the insurer's data centre for control and outsourcing requirements. The hybrid platform scales on AWS without giving up that control.

Can I know the insurer and the full figures?

The case is anonymised under a non-disclosure agreement. Architecture details and full figures are shared after signing an NDA.

Last updated: 2026-09-12

Full figures and architecture are shared upon NDA signing.

Request detail under NDA →