Platform Engineering - Leveraging Tanzu Cloud Foundry to provide a platform to run mission-critical apps

From Overwhelmed and Reactive to Confident and Empowered with Secure, Reliable Global Operations

Client: Government - US DoD

About the Client (Government - US DoD)

Our U.S. Department of Defense (DoD) client needed a platform that could handle the scale, complexity, and security requirements of running mission-critical applications around the globe. Their teams were stuck in reactive firefighting, spending more time patching, deploying, and troubleshooting than innovating. The challenge was clear: modernize the way they worked, strengthen their security posture, and create a foundation where applications could thrive without compromise.

Outcomes

  • More than 10,000 users and 250 applications ran with 99.95%+ uptime across 13 global platforms
  • Security vulnerabilities were addressed in record time, with critical patches applied in under 48 hours
  • When problems did occur, recovery was fast: less than 30 minutes mean time to recovery (MTTR) per application
  • Teams could count on a steady cadence of bi-weekly OS image updates and 12+ production baseline upgrades every year
This wasn’t just incremental improvement; it was a profound transformation. Together, we created a highly reliable, secure, and resilient ecosystem where reliability and security are built into every layer, keeping pace with the mission-critical demands of a global defense organization.

Problem | Before working with us

Before this shift, the client’s operations were weighed down by inefficiency and risk. Teams worked in a constant state of reaction, struggling to keep up with issues instead of getting ahead of them. Security controls were unclear and outdated, leaving systems exposed.

Deployments and patching were manual, ticket-based, and error-prone, introducing delays and inconsistencies. Without source-controlled images, global sites drifted into configuration snowflaking, making it nearly impossible to maintain a consistent standard. Each location ran as a silo, duplicating effort and multiplying complexity.

Solution | After working with us

We helped flip the script by embedding a platform engineering mindset powered by Tanzu Cloud Foundry. The client shifted from reactive firefighting to proactive, consistent, and secure operations:

  • Infrastructure as code and configuration as code became the standard, ensuring every deployment was repeatable and reliable
  • Auditable security controls brought confidence and compliance to every environment
  • A hub-and-spoke model created global consistency, no matter the site
  • Automation handled updates, deployments, and patching, eliminating manual errors and wasted time
  • Proactive monitoring meant issues were caught before they escalated
  • Self-service capabilities empowered application teams to deliver faster without waiting on central operations

The result was a modern, scalable platform that let the client focus on delivering outcomes instead of managing technical debt. This investment in platform engineering has paid dividends not just in operational efficiency, but in enabling the organization to focus on their core mission knowing that security, reliability, and compliance are built-in foundations rather than afterthoughts.

Services Provided

Our partnership was more than just technology; it was about delivering the right expertise at the right time. We used flexible scoping to deliver what the customer needed throughout the engagement. This allowed our team to work on what’s most important to the client at any time. We do this as part of our Cloud Foundry Managed Service. Our Platform Engineering Services scope for this project included:

Platform-as-a-product

We brought a platform-as-a-product mindset to our services, treating the infrastructure and platform as customer-facing software for developers. By applying agile methodologies, we ensured platform teams were always focused on the most important priorities. Just as a product is never finished, the platform is a continuous journey of improvement and refinement.

Modern Compliance Architecture

Our compliance architects ensured that regulatory and security standards were consistently met. They guided the client through the Risk Management Framework (RMF) process, ultimately enabling a Continuous Authority to Operate (ATO), a critical achievement for operating in DoD regulated environments.

Deployment, SRE, and Consulting

Our team embedded as resident platform engineers and SREs, working shoulder-to-shoulder with the client. We not only deployed and operationalized the platform but also partnered closely to ensure their teams gained the knowledge and processes needed to sustain and evolve the platform for years to come.

How we worked together

We didn’t just deliver a solution and walk away. Instead, we worked as an extension of the client’s team. Together, we:

  • Immersed their staff in the work, ensuring every moment was a learning opportunity
  • Solved complex problems side-by-side, fostering collaboration and trust
  • Continuously educated and upskilled their teams, building long-term capability
  • Strengthened processes while reinforcing security, ensuring improvements stuck

This collaborative approach accelerated results and gave the DoD client ownership of the platform, ensuring a much quicker and higher return on investment.

Tech Stack Leveraged

Tanzu Application Service Kubernetes AWS GovCloud AWS Secret Cloud VCF Vault Harbor Gitlab Grafana Terraform Concourse