Skip to content
CBN data localisation deadline, 1 Jan 2027: 99d 00h 31m left.Talk to us
NuxFamily

Banking · A top-5 Spanish retail bank

Moving a retail bank's core workloads from public cloud to a private cloud, without downtime

The bank needed to bring several hundred workloads back from a hyperscaler into its own data centres under a regulatory deadline. NuxFamily designed the target platform, ran the migration in waves and handed over operations to the bank's team.

  • 0

    Minutes of unplanned downtime across nine migration waves

  • −38 %

    Infrastructure run cost versus the public-cloud baseline

  • 7 months

    From platform build to final cut-over, ahead of the deadline

The challenge

The challenge

The bank had grown a significant estate on a foreign public cloud: customer-facing channels, batch processing and a number of payment-adjacent services. A supervisory requirement to keep processing and administrative functions within its own jurisdiction gave the bank fourteen months to repatriate the estate. The internal team had strong application knowledge but had not operated a private cloud at that scale.

The main constraint was availability. Channels could not be interrupted during business hours and the payment services had a recovery time objective measured in minutes. Any migration plan had to include a tested rollback for every wave, and every change had to be traceable for the supervisor.

A secondary constraint was cost. The bank did not want to reproduce public-cloud spend on-premises, so the platform had to offer self-service, automation and capacity planning from day one.

The architecture

The architecture

The foundation is a VMware vSphere private cloud across two data centres in an active-active configuration, with NSX for network segmentation and S3-compatible object storage for backups and unstructured data. Capacity was sized from the real inventory rather than from public-cloud invoices, which reduced the initial footprint.

Containerised workloads run on OpenShift clusters per environment, deployed with GitOps and integrated with the bank's identity provider and secrets management. Legacy virtual machines were migrated as-is into vSphere and scheduled for later modernisation, so the deadline did not depend on refactoring.

Stateful services moved to PostgreSQL clusters managed with Patroni, with synchronous replication between sites and point-in-time recovery to the object store. Messaging moved from managed cloud queues to Apache Kafka running on the same platform.

Migration ran in nine waves over seven months. Each wave had a dependency map, a data synchronisation window, a cut-over runbook and a rehearsed rollback. Observability, patching and lifecycle management were in place before the first production wave.

Technologies

  • VMware vSphere
  • NSX
  • OpenShift
  • PostgreSQL
  • Patroni
  • Apache Kafka
  • S3-compatible object storage
  • GitOps
The rollback plans were the reason we could sign off each wave. We used them once, and they worked.
Head of Infrastructure, retail bank

Your institution could be the next case

Tell us about your platform and regulatory timeline; we will show you which of these patterns applies.

No mailing lists, no automated follow-ups. We reply personally within one working day.