CVE commitment
Give your developers the cloud experience without giving away your data.
On-premises PaaS and developer platforms for Nigerian banks
Tanzu Platform for Cloud Foundry, Cloud Foundry OSS, Korifi and Backstage, running on your Kubernetes and private cloud. Developers push code; the platform handles builds, routing, scaling and compliance inside Nigeria.
- Tanzu Platform for Cloud Foundry
- Cloud Foundry OSS
- Korifi
- Backstage
The technologies we cover
Products in this family

Tanzu Platform for Cloud Foundry
Commercial Cloud Foundry distribution with buildpacks, service brokers and lifecycle tooling for regulated estates.
Private cloudAir-gappedOfficial support
Cloud Foundry OSS
The open-source application platform behind cf push, deployed with BOSH on vSphere, OpenStack or KVM.
Private cloudAir-gappedOfficial support
Korifi
Cloud Foundry developer experience implemented natively on Kubernetes, without BOSH.
Private cloudAir-gappedOfficial support
Backstage
Open-source developer portal: software catalogue, golden-path templates and documentation in one place.
Private cloudAir-gappedOfficial support
Cloud Native Buildpacks
Reproducible container images built from source, with patched base layers and an SBOM for every build.
Private cloudAir-gappedOfficial support
Why it matters for data localisation
Where this family meets the CBN directive
When a bank moves its payment applications out of a foreign cloud to comply with the CBN directive before 1 January 2027, the risk is not only technical but organisational. Developers who have grown used to a platform-as-a-service on a hyperscaler will resist a return to tickets and hand-built servers, and shadow deployments abroad become a compliance exposure. An on-premises PaaS removes that pressure. With Cloud Foundry or Korifi on a Nigerian private cloud, a developer runs cf push and the platform builds the image, injects credentials, routes traffic and scales the application, all inside the national perimeter. The directive's scope, primary processing, databases, backups, IAM, encryption keys and audit logs, is satisfied by design: the platform's identity service is the bank's own, service credentials come from a broker that provisions databases on the local data layer, and every push, scale and bind is logged. Backstage adds the catalogue that a data-mapping exercise needs, because every service, owner and dependency is recorded where the regulator can see it. NuxFamily delivers the PaaS layer on top of its Kubernetes and virtualization families so that the whole stack has one owner.
The journey with NuxFamily
- 01Assess
- 02Design
- 03Build
- 04Migrate
- 05Operate
- 06Evolve
Every family is delivered through the same six-stage journey, with official 24×7 support and knowledge transfer built in.
Our expertise
Credentials, not adjectives
This team has run Cloud Foundry foundations for European banks and insurers since Pivotal Cloud Foundry, through the transition to Tanzu and to Kubernetes-native Korifi. We have operated platforms serving hundreds of developers with thousands of application instances, integrated them with HSM-backed credential stores and regulated CI/CD, and built Backstage portals that became the system of record for application ownership. The same platform engineering practice is now available in Nigeria.
Sectors
- Banking
- Insurance
- Retail
- Industry
10+
Years with these technologies
25+
Production deployments
2,500+ application instances on one Cloud Foundry foundation
Largest scale delivered
Official vendor support
Support tiers for this family
Essential
- Coverage
- 8×5, Nigeria business hours
- P1 response
- 4 h
- Corrective support for the Cloud Foundry or Korifi control plane, routers, cells and service brokers
- Access to the NuxFamily knowledge base and buildpack guidance
- Security patches for platform components, stemcells and buildpacks
Business
- Coverage
- 24×7
- P1 response
- 1 h
- Everything in Essential
- Proactive monitoring of platform health, capacity and application error rates
- Quarterly health checks including quota, broker and buildpack currency review
- Managed version lifecycle for the platform, buildpacks and Backstage plugins
Mission Critical
Most chosen- Coverage
- 24×7 with a named engineer
- P1 response
- 15 min
- Everything in Business
- Named platform engineer who knows your foundations and developer teams
- Architecture review and platform roadmap alignment
- Major upgrade support (for example Tanzu Platform major releases, Korifi and Kubernetes version steps)
- Support during CBN audits with platform logs and catalogue exports
Version policy
Response times and tier names are indicative and confirmed contractually.
Use cases
How it is used in a regulated bank
Use case 01
Self-service for the bank's development teams
A bank with twenty application teams wants each team to deploy without waiting on infrastructure tickets, while security keeps control of what runs in production. The path from cf push to a running service must be the same for every team, with quotas that stop one team from starving another and isolation that keeps the payment perimeter separate.
Technologies
- Tanzu Platform for Cloud Foundry
- Korifi
- Cloud Native Buildpacks
- Open Service Broker API
Expected outcome
Teams deploy in minutes without infrastructure tickets, and security keeps a single control point for images, credentials and routes. Platform quotas and isolation segments make the tenancy model visible to auditors.
Metric: Time from cf push to a running service under 5 minutes; onboarding of a new team in one day
- 1Onboard the team. Create the org and spaces with quotas and map the team's directory group to platform roles.
- 2cf push. The developer pushes source code; the platform detects the language and selects a buildpack.
- 3Build the image. A reproducible image is built from a patched base layer, with an SBOM recorded for the build.
- 4Bind services. The app binds to a database and a queue provisioned by brokers on the local data layer.
- 5Route and scale. The platform assigns a route, health-checks the instances and scales on demand within the quota.
- 6Isolate the payment tier. Payment apps land on an isolation segment with dedicated cells and network egress rules.
- 7Log and audit. Every push, scale and bind event is written to the audit stream and the SIEM.
Use case 02
Modernising core applications without a rewrite
Use case 03
Internal service catalogue
Reference architecture
What a compliant deployment looks like
Access
Platform
Data
Sites
Migration path
From where you are to a compliant platform
01
2-3 weeksAssess
Activities
- Inventory of applications, languages, frameworks and their cloud PaaS dependencies
- Developer workflow interviews and measurement of current lead time
- Choice between Tanzu Platform, Cloud Foundry OSS and Korifi based on estate and skills
- Classification of applications against the CBN scope
02
3-4 weeksDesign
Activities
- Foundation topology, isolation segments and quota model per org
- Buildpack set, base images and image signing policy
- Service broker catalogue and integration with the data platform
- Identity, secrets and audit log integration
03
4-6 weeksBuild
Activities
- Deploy the platform on the Kubernetes and virtualization foundation, including the air-gapped variant where required
- Deploy Backstage with the catalogue, golden-path templates and documentation
- Register brokers, configure isolation segments and integrate CI/CD
- Platform hardening, load test and developer pilot with two teams
04
6-10 weeksMigrate
Activities
- Onboard teams in waves with training and templates
- Push applications, bind local services and run in parallel with the cloud PaaS
- Traffic switch per application and decommissioning of the foreign platform
05
OngoingOperate
Activities
- 24×7 support, patching, buildpack and platform lifecycle
- Quarterly platform reviews with developer feedback
- Knowledge transfer to the bank's platform engineering team
FAQ
Questions architects ask us
Cloud Foundry remains the most complete cf push experience for teams that want to deploy code without managing containers, and it is maintained by the Cloud Foundry Foundation with commercial backing from Broadcom through Tanzu Platform. Korifi brings that same developer contract onto Kubernetes, so an institution can standardise on Kubernetes underneath while keeping the platform workflow. We support both paths and help you choose based on your estate.
The directive requires the processing environment, databases, backups, IAM, encryption keys and audit logs for payment data to be inside Nigeria with no foreign cloud dependency. A PaaS on a Nigerian private cloud keeps the build, runtime, credentials and audit stream within that perimeter, and brokered services keep data on the local data platform. The catalogue also gives you the application inventory a data-mapping exercise requires. This is context, not legal advice.
Tanzu Platform for Cloud Foundry is the commercial, vendor-supported distribution with additional tooling and certified integrations. Cloud Foundry OSS is the upstream project deployed with BOSH on your hypervisor. Korifi reimplements the Cloud Foundry API on Kubernetes without BOSH, which suits institutions already standardising on Kubernetes. All three give developers the same cf push workflow.
Yes. The PaaS is a paved road, not a wall. Teams with a container-native workflow deploy to the Kubernetes family directly, and Backstage presents both paths in the same catalogue with the same ownership and compliance metadata. The choice is made per application, not for the whole bank.
NuxFamily supports the platform control plane, runtime cells, routers, brokers, buildpacks and Backstage as deployed, with the response times of your tier. Where a Tanzu subscription exists we operate it and escalate to Broadcom when a fix requires vendor changes. The scope of L1-L3 responsibility is defined in the support agreement.
A rewrite replaces the whole system in one cutover and hides its risk until the end. The strangler pattern moves one capability at a time behind a routing facade, so each step is small, measurable and reversible. The monolith stays in service throughout, which matters when the deadline is fixed and the core cannot be paused.
Yes. Tanzu Platform, Cloud Foundry OSS and Korifi can be installed and updated from internal mirrors, and buildpacks and base images are delivered as signed bundles. Backstage plugins and documentation are hosted internally. No component requires outbound internet access at runtime.
Over two decades
Built by the team behind the platforms of Santander, ING, Bankinter, Mapfre and Inditex
More than twenty years designing, building and operating private clouds for institutions that cannot afford to fail, and a delivery model where we stay with you from assessment to operation.
See our track record20+
Years building private clouds
40+
Private clouds delivered
Talk to an architect about this family
Tell us where you are today and we will come back with a first view of the target architecture and the migration path.