Helping Cobalt Move from Heroku to Kubernetes on Google Cloud
- Three-day architecture workshop series with Cobalt and Google
- Approach for moving PostgreSQL and Redis off Heroku
- Secrets management with Cloud KMS and HashiCorp Vault
- Private GKE clusters, Cloud Build, and access control with Terraform
- Customer
- Cobalt
- Year
- Topics
- Cloud, Gcp, Kubernetes, Security
In 2019, Cobalt Labs, Inc. (Cobalt.io) was moving its platform from Heroku to Kubernetes on Google Kubernetes Engine (GKE). Cobalt’s engineers were running the migration themselves.
Working with Google, Sakura Sky ran a series of architecture workshops for Cobalt, delivered by two Google Cloud certified Sakura Sky engineers: a Professional Cloud Architect and a Professional Data Engineer. Today this kind of work is part of our Cloud practice.
What we did
The workshops took place at Cobalt’s offices in Berlin from 11 to 13 September 2019.
- Workshop 1: the problem and the environment. A review of Cobalt’s Heroku and Google Cloud environments, its concerns, and the outcomes it wanted. Together we set the agenda for the next two days.
- Workshop 2: data and secrets. How to move Cobalt’s PostgreSQL and Redis data stores off Heroku, including PostgreSQL to Cloud SQL. How to manage secrets with Cloud KMS and HashiCorp Vault. An audit of Cobalt’s environment against Google Cloud best practice.
- Workshop 3: build, network, and access. Cloud Build for builds and deployment, private GKE clusters with Cloud NAT, and role-based access control (RBAC) linked to G Suite and managed with Terraform.
Outcomes
By the end of the series, Cobalt’s web applications and APIs were running on GKE, in separate production, QA, and staging environments. Cobalt also had an agreed approach for its remaining data migration, secrets management, and access control.
If you are moving off a platform-as-a-service, contact us.