Skip to content
All work

03Regulated enterprise

A zero-secret platform for a regulated enterprise

Containerized APIs on Kubernetes with managed identity everywhere, end-to-end tracing, and pipeline templates teams reuse instead of reinventing.

Sector
Regulated enterprise
JDO owned
Platform engineering · APIs · Identity · Observability · CI/CD
Stack
Kubernetes (AKS) · Docker · .NET · Entra ID + 4 more
Fig. 01System sketch
  1. Clientsinternal · public
  2. IngressTLS · routing
  3. API podsAKS · non-root
  4. Data & queuesmanaged identity
  • Pipeline templatesbuild once · deploy many
  • TracingOpenTelemetry → App Insights

01Challenge

Challenge

A large organization with strict security and audit requirements was moving workloads to the cloud. Each team ran its own pipelines, connection strings with passwords lived in config files, and when a request failed across three services nobody could say where. The platform had to be secure and observable by default without slowing delivery down.

02Approach

How it was built

  1. 01Containerized APIs as lean, multi-stage images running as non-root on Kubernetes (AKS).
  2. 02Replaced static credentials with Entra ID managed and workload identity for databases, queues, storage and cache.
  3. 03Instrumented services with OpenTelemetry so one trace follows a request across every hop into Application Insights.
  4. 04Built templated CI/CD pipelines: one image per build, with environment values applied at deploy time.
  5. 05Kept secrets out of manifests: plain settings live with the deployment, sensitive values in a secret store.

03Architecture

Decisions that hold the system up

  • No passwords or keys in code, config or pipelines.

  • A single environment-agnostic image promoted from dev to prod.

  • Distributed tracing and dependency telemetry on every service.

  • Hardened pods: non-root users and no privilege escalation.

04Outcomes

What changed

  • Static credentials removed from the services in scope.
  • Cross-service failures can be followed hop by hop instead of pieced together from scattered logs.
  • New services onboard by reusing pipeline templates rather than writing their own.
  • Security reviews got simpler: there are no app secrets left to rotate.

Stack

Kubernetes (AKS)Docker.NETEntra IDManaged identityOpenTelemetryApplication InsightsPipeline templates

Details are anonymized and simplified to protect client confidentiality.