Business opportunity
To fuel world-class innovation and provide citizens with valuable new services faster, at lower cost, one high-growth, tech-forward country is aspiring to an AI-native future. A deep understanding of what it takes to enable generative and agentic AI at scale led them to prioritize a crucial first step — an agile, flexible cloud infrastructure. All government ministries were encouraged to quickly pursue migration to public cloud.
The ministry of urban affairs was one of the first to embrace the opportunity. However, the leaders were concerned about privacy and security risks, given that they held volumes of sensitive data, including citizens’ names, addresses, personal details, and eligibility for public housing.
Technical challenge
The Ministry was running the majority of its core systems in a containerized environment on Red Hat OpenShift. For security purposes, these Kubernetes clusters were in an isolated, air-gapped on-premises environment, and the lack of direct internet access added complexity to management, maintenance and ongoing software upgrades.
Targeting smoother upgrades, higher availability and more consistent performance, they needed a partner to help with migration to a Kubernetes platform. IT leaders identified Amazon EKS Anywhere as a potential replacement for Red Hat OpenShift and a steppingstone to cloud. Making these technology changes would allow them to standardize on AWS-native Kubernetes, simplify operations, and integrate more easily with AWS services — but they lacked internal knowledge of the solution.
Our solution
Together, the Ministry and Kyndryl migrated from OpenShift to Amazon EKS Anywhere — an on-premises solution for simple management and operation of Kubernetes clusters.
After successfully running on EKS Anywhere for six months, the Ministry took Kyndryl’s recommendation to migrate to Amazon EKS Hybrid Nodes. This solution makes the control plane —the brain of the Kubernetes platform — a managed service on AWS, significantly reducing the administrative burden for the Ministry. The Ministry’s worker nodes — and the sensitive data they contain — remain on-premises, simplifying compliance.
As the Ministry migrates workloads to the public cloud, the most critical will go on EKS Hybrid Nodes, leaving almost zero on-premises infrastructure.
Kyndryl also streamlined operations for the Ministry’s IT team with a comprehensive GitOps CI/CD pipeline using ArgoCD. This enables the automated management of infrastructure and application updates, helping ensure that changes are consistently applied across all environments.
The joint team took an infrastructure-as-code (IaC) approach to the on-premises infrastructure, using Terraform to automate provisioning and management to ensure consistency and repeatability. This IaC approach also accelerates deployments, facilitates version control, and provides an auditable foundation for future expansions.
By moving from OpenShift to EKS Anywhere / EKS Hybrid Nodes, the Ministry gains:
- Operational consistency with AWS EKS used in the public cloud
- Native integration with AWS services for Identity and Access Management (IAM), observability, security and networking
- A simpler migration path to the AWS ecosystem in the future