03Regulated enterprise
A zero-secret platform for a regulated enterprise
Containerized APIs on Kubernetes with managed identity everywhere, end-to-end tracing, and pipeline templates teams reuse instead of reinventing.
- Sector
- Regulated enterprise
- JDO owned
- Platform engineering · APIs · Identity · Observability · CI/CD
- Stack
- Kubernetes (AKS) · Docker · .NET · Entra ID + 4 more
- Clientsinternal · public
- IngressTLS · routing
- API podsAKS · non-root
- Data & queuesmanaged identity
- Pipeline templatesbuild once · deploy many
- TracingOpenTelemetry → App Insights
01Challenge
Challenge
A large organization with strict security and audit requirements was moving workloads to the cloud. Each team ran its own pipelines, connection strings with passwords lived in config files, and when a request failed across three services nobody could say where. The platform had to be secure and observable by default without slowing delivery down.
02Approach
How it was built
- 01Containerized APIs as lean, multi-stage images running as non-root on Kubernetes (AKS).
- 02Replaced static credentials with Entra ID managed and workload identity for databases, queues, storage and cache.
- 03Instrumented services with OpenTelemetry so one trace follows a request across every hop into Application Insights.
- 04Built templated CI/CD pipelines: one image per build, with environment values applied at deploy time.
- 05Kept secrets out of manifests: plain settings live with the deployment, sensitive values in a secret store.
03Architecture
Decisions that hold the system up
No passwords or keys in code, config or pipelines.
A single environment-agnostic image promoted from dev to prod.
Distributed tracing and dependency telemetry on every service.
Hardened pods: non-root users and no privilege escalation.
04Outcomes
What changed
- Static credentials removed from the services in scope.
- Cross-service failures can be followed hop by hop instead of pieced together from scattered logs.
- New services onboard by reusing pipeline templates rather than writing their own.
- Security reviews got simpler: there are no app secrets left to rotate.
Stack
Details are anonymized and simplified to protect client confidentiality.
Next case study
Industrial manufacturing
A fast, findable web presence for an industrial manufacturer
Building something similar?
Tell me where it's stuck. You'll hear back from me directly.