Terraform Landing Zone & VPC Peering
Set up AWS Organizations with dedicated Accounts for staging, compliance, and production. Deployed encrypted multi-AZ transit gateways and Direct Connect.
Replatforming 80 core banking and ledger services to AWS with shadow dual-write cutover, multi-AZ Aurora PostgreSQL, and automated rollback guardrails.
The client processed over $40M daily across a legacy colocation data centre. Deployments were monthly 6-hour night shifts prone to rollbacks. Any transaction drop would breach strict banking SLAs and risk financial penalties.
Payment settlement endpoints had to stay live without dropping inflight transactions or generating duplicate debits during the cutover window.
All data in transit and at rest required dedicated KMS customer-managed encryption keys with strict IAM least-privilege boundaries.
Rather than a risky "big bang" migration, we implemented a phased shadow dual-write pattern:
Set up AWS Organizations with dedicated Accounts for staging, compliance, and production. Deployed encrypted multi-AZ transit gateways and Direct Connect.
Built an event-driven replication layer using AWS DMS and Kafka to mirror all live transactions to Amazon Aurora with sub-10ms divergence monitoring.
Shifted user traffic 5% → 25% → 100% over 48 hours with continuous automated anomaly detection and immediate fallback paths.