EdenicEdenic
← Selected work

Cloud · Azure AKS · HomesUSA

Azure App Services → AKS, zero downtime.

HomesUSA, a US real-estate technology platform, had outgrown Azure App Services. An Edenic engineer moved the whole estate — 300+ resources, 30+ services — onto private AKS clusters with GitOps delivery and full observability, and cut over to production with zero downtime.

Azure AKSDockerHelmTerraformAzure DevOpsArgoCD (GitOps)NGINX Ingresscert-managerPrometheusGrafanaAzure Key VaultKEDAAzure CNICloudflare DNS
300+

Azure resources migrated

30+

services containerized

3

environments (dev/QA/prod)

0 min

downtime at cutover

Snapshot

Client

HomesUSA — a US real-estate technology platform, delivered by an Edenic DevOps engineer

Scope

300+ Azure resources and 30+ applications moved off Azure App Services onto AKS

Model

Private AKS clusters per environment, GitOps continuous delivery, infra as code

Outcome

Zero-downtime production cutover with a clean, documented handoff

The pain

  • App Services (PaaS) billed for reserved capacity regardless of real utilisation
  • Limited control over networking, scaling, and service-to-service traffic
  • Configuration drift between dev, QA, and production
  • Secrets scattered across per-app integrations with no unified access pattern

Objectives

  • Containerise every app onto AKS with per-environment parity
  • GitOps continuous delivery with instant, auditable rollback
  • Unify secrets and full-stack observability across all environments
  • Lock the network down — private clusters, private endpoints, VPN-only admin
Target architecture — overview

Ingress

Cloudflare DNS
NGINX Ingress
cert-manager TLS

Workloads · AKS

Frontend UIs
Backend APIs
KEDA-scaled jobs

Platform

Key Vault (CSI)
App Configuration
Private registry

Data

Azure SQL
Cosmos DB
Blob Storage
CI: Azure DevOps → registryCD: GitOps auto-sync + self-healObservability: Prometheus · Grafana · APMNetwork: private clusters · private endpoints · VPN-only

Migration roadmap

  1. Phase 0

    Assessment & planning

    Map every service, dependency, and network path; agree the target architecture and a risk register with a pre-planned cutover window.

  2. Phase 1

    AKS platform

    Private clusters per environment, Azure CNI pod networking, autoscaling node pools, provisioned via Terraform and pipelines.

  3. Phase 2

    Containerisation

    Docker images and per-environment Helm charts for 30+ services, with liveness/readiness probes and resource limits.

  4. Phase 3

    Data & network security

    Private endpoints and identity-based access to databases and storage; strict per-environment isolation.

  5. Phase 4

    CI/CD & observability

    CI builds to a private registry, GitOps CD with auto-sync and self-heal, Prometheus/Grafana plus APM and alerting.

  6. Phase 5

    Validation & cutover

    Load, failover, and TLS/routing tests, then a zero-downtime production cutover.

  7. Phase 6

    Docs & handoff

    Runbooks, rollback procedures, incident guides, and knowledge-transfer sessions with the in-house team.

Key takeaways

  • A zero-downtime cutover on a 300+ resource estate — the business never felt the migration
  • GitOps made every release auditable and every rollback one click
  • Environment parity ended the drift between dev, QA, and production
  • Autoscaling absorbed traffic spikes without paying for idle capacity

Have a migration that stalled?

This is the calibre of engineer Edenic sources, vets, and places. Talk to a founder.

Talk to a founder ↗