Infrastructure Modernisation with Kubernetes
A major Spanish banking institution needed to modernise its critical infrastructure towards a hybrid container architecture, without interrupting production services.
Challenge
Legacy infrastructure with critical services that could not be stopped. Need to modernise towards containers and cloud while keeping the banking platform fully operational.
Solution
Phased deployment with RKE2 and on-premise Rancher, extension to AWS EKS, GitOps adoption with Rancher Fleet and full observability with Prometheus, Grafana and Loki.
Technologies
- Kubernetes / RKE2 / Rancher
- AWS EKS, ALB, RDS, S3
- GitOps / Helm / Kustomize
- Prometheus / Grafana / Loki
Context
A large Spanish bank started from a fragmented infrastructure environment, with manual processes that limited operational agility, the ability to scale on demand and the resilience of its critical services. With HPC workloads and systems essential to the business, it needed a robust, more flexible and automated technology base.
Five objectives were agreed with the client: modernise the infrastructure with a unified orchestration platform, guarantee high availability for critical systems, enable automatic scaling without oversizing, improve end-to-end observability and traceability, and increase the security of the environment while reducing operational errors.
The challenge
Before the modernisation started, the organisation faced three technical and operational limitations:
- A fragmented, hard-to-scale environment: difficulty operating on-premise and cloud as one, with limits on scaling services dynamically.
- Manual processes with high operational dependence: slow deployments (up to 45 minutes), error-prone and with low traceability, creating bottlenecks and unnecessary resource consumption.
- No visibility or resilience in critical services: no observability tooling and an architecture exposed to failures that compromised the stability of key systems.
Phased approach
The modernisation followed a progressive approach designed not to interrupt the business's critical services. The platform was built on Kubernetes as the central orchestration layer, in six clearly defined stages.
-
01
Analysis and design
Workload assessment, architecture definition, technology selection and initial sizing.
-
02
Proof of concept
Initial on-premise deployment with RKE2 and Rancher, validating HPC environments and essential services.
-
03
Extension to AWS
Clusters on AWS (EKS and RKE2 on EC2), integrating services such as ALB, RDS and S3 with hybrid connectivity.
-
04
Automation and CI/CD
GitOps with Rancher Fleet and declarative deployments with Helm and Kustomize.
-
05
Observability and traceability
Prometheus, Grafana and Loki for monitoring, alerting and centralised logs.
-
06
Production and support
Full migration of services, functional validation, go-live and continuous operational support.
Architecture and strategy
The strategy was designed around the sector's three needs: continuity, scalability and control. A hybrid architecture combines on-premise and cloud environments orchestrated from a single management console, which kept control without giving up the ability to scale dynamically.
Adopting GitOps and CI/CD tooling removed manual tasks, reduced errors and made deployment cycles faster and more predictable. Continuous monitoring and real-time alerts were essential to guarantee traceability, performance and compliance.
Measurable results
Choosing Kubernetes as the technology base was no accident: its ability to orchestrate containers efficiently, scale automatically with load and adapt to hybrid environments made it the answer to the project's challenges. Main results after implementation:
| Indicator | Before | After |
|---|---|---|
| Deployment time | ~45 minutes | ~3-5 minutes (≈ −90%) |
| Service availability | 95% | > 99.99% (+4.95 points) |
| Scalability | Manual | Automatic, dynamic |
| Operating cost | High | Optimised (≈ −30%) |
| Response time (web/API) | 200-300 ms | 50-120 ms (≈ −60%) |
Aggregated figures, anonymised under a non-disclosure agreement. Source: Vermont Solutions projects.
Lessons that carry over
- Dependence on manual processes was removed, reducing errors and increasing delivery speed.
- Operational visibility improved, with more control, security and resource optimisation.
- An agile, resilient platform ready for variable workloads, including HPC research projects, was enabled.
- DevSecOps and Cloud Native good practices became easier to follow: an adaptable base to scale innovation, reduce operating costs and respond quickly to new business needs.
Regulatory framework
In banking, resilience and observability are not extras: they are regulatory requirements. The platform was designed with that framework in mind.
- DORA (Art. 28): the AWS extension is governed as ICT third-party risk, with deployment traceability, rollback capability and end-to-end observability.
- NIS2: network and information security in an essential sector; segmentation, access control and real-time alerts.
- Business continuity: availability above 99.99% and reproducible declarative deployments as evidence for the supervisor.
Frequently asked questions
Were banking services interrupted during the migration?
No. The migration was phased, starting with an on-premise proof of concept and then extending to AWS, with functional validation at each stage. The six environments were migrated while keeping 99.9% availability during the transition.
Why a hybrid platform (RKE2 on-premise + EKS) rather than cloud only?
Because the bank needed to keep control of its critical systems on-premise while scaling on AWS for variable workloads. A single management console orchestrates both environments.
What role does GitOps play in a regulated environment?
Every change is versioned, reviewed and auditable. Declarative deployments with Rancher Fleet, Helm and Kustomize went from 45 manual minutes to 3-5 reproducible minutes, with full traceability.
Can I know the institution and the full figures?
The case is anonymised under a non-disclosure agreement. Architecture details and full figures are shared after signing an NDA.
Related content
Last updated: 2026-09-12