Skip to content

Moving a production platform from GCP to AWS

For a cybersecurity company, I led the move of several production applications from Google Kubernetes Engine to Amazon EKS, including databases, object storage and encrypted customer data.

Client
Cybersecurity company
Role
Lead engineer
Year
2026

The challenge#

The client's products ran across several Google Kubernetes Engine clusters, with Cloud SQL databases, Cloud Storage buckets and customer secrets protected by a key-management service. The business wanted everything on AWS, next to the rest of their platform, without losing data and without a long outage.

What I did#

I led the migration from discovery to cutover. I mapped every component and dependency, agreed what to retire instead of moving, and rebuilt the applications as namespaces on the client's existing EKS clusters using their Terraform module patterns. Supporting services came across too: Vault, Istio, Argo CD and Argo Workflows, logging and error tracking.

The hardest part was the data. One application stored customer fields encrypted under keys that lived in the old cloud. I wrote a re-encryption job that decrypted each value with the old key and encrypted it with the new one, then verified that nothing was left unconverted and that every customer's data decrypted correctly on AWS.

How it works#

Each application moved through dev and then production with a written runbook. The production cutover followed a fixed order: take a database snapshot as the rollback point, lower DNS cache times, pause background workers on the old side, copy databases and buckets with byte-level checks, re-encrypt secrets, bring the new services up, then point old addresses at new ones with permanent redirects.

Results#

  • Every application went live on AWS in one planned cutover, with health checks green and zero restarts.
  • Every encrypted field was converted and verified, with none left behind.
  • The old cloud was scaled to zero and kept as a fallback until decommissioning.
  • The team that runs the platform received a DevOps and SRE guide written for them.

What I learned#

A migration is mostly a data project with some Kubernetes attached. The rehearsal on dev, the rollback snapshot and the boring checklist were what made the production cutover uneventful.

Have a project in mind?

Share your goals, timeline and any constraints, whether you need it built or want expert advice. I read every message myself, as the engineer who would build it, and reply with a clear view on approach, scope and next steps.

Hire me