Cloud Intelligence™Cloud Intelligence™

This page is also available in Deutsch, Español, Français, Italiano, 日本語, and Português.

Software Projects accelerates a complex IBM-to-AWS migration with DoiT

How DoiT guided Software Projects, a global software services company, through AWS MAP, consolidating two IBM Cloud regions into one AWS footprint, with the full application topology preserved end to end.

Cloud Intelligence™
Software Projects

Meet Software Projects

Software Projects is a software services organization running a mixed production and non-production environment that had historically been hosted on IBM Cloud Infrastructure. As part of a broader cloud strategy, the organization engaged DoiT to migrate its workloads to AWS under the AWS Migration Acceleration Program (MAP), with DoiT delivering all three MAP phases: Assess, Mobilize, and Modernize.

The Challenge

Software Projects needed to move a live, multi-tier environment off IBM Cloud Infrastructure and onto AWS while keeping both environments securely connected throughout the transition. That created several intertwined problems DoiT needed to solve at once:

  • No reliable private network path between IBM Cloud Infrastructure and AWS - an existing self-managed, open-source site-to-site VPN worked in one direction only.
  • Limited internal networking expertise on the Software Projects' side, and no clear precedent for connecting IBM Classic Infrastructure to AWS at the scale required.
  • A need for accurate, granular cost forecasting (storage, compute, and discounting options) to plan the migration budget before workloads moved.
  • A requirement to keep production stable and monitorable throughout the transition, with fast root-cause response if issues arose.
  • Once migrated, a need to keep cloud security tooling right-sized so spend stayed proportional to actual risk and workload footprint.

The Solution

The Environment: A Four-Tier, Dual-Site Architecture

Before migration, the team at Software Projects ran a single, well-defined architecture in two IBM Cloud regions, sized for resilience: a larger primary site and a smaller secondary site. Each site followed the same four-tier pattern:

  • Load balancing: a small fleet of HAProxy instances fronting production, development, and tracking traffic separately.
  • Application: web and tracking servers, a scheduled-job runner, a code-quality (SonarQube) server, and a VPN gateway (present on the primary site only).
  • Container orchestration: self-managed Docker Swarm clusters, run as separate production and development clusters on the primary site and a single cluster on the secondary site.
  • Data: a MySQL primary/replica pair alongside a three-node Cassandra cluster, replicated at both sites.

DoiT's migration plan called for a faithful, 1:1 lift-and-shift of this topology into a single AWS VPC in us-east-1 — keeping the same 24-node and 16-node footprints, but distributing them across multiple Availability Zones within one AWS Region instead of two independent, geographically separate IBM Cloud regions. The table below shows how the tier-by-tier composition carried over unchanged:

media

These counts held constant on both sides of the cutover — the same 24 and 16 nodes, in the same tier-by-tier proportions, simply relocated. That discipline mattered: it meant the Software Projects inherited an environment on AWS that behaved identically to the one their team already knew, while DoiT quietly removed a layer of infrastructure complexity by collapsing two data-center regions into a single AWS Region spread across multiple Availability Zones. It also set up the Modernize phase cleanly, since the roadmap already called for retiring the self-managed Docker Swarm clusters in favor of a managed container platform once the environment was stable on AWS.

The Approach: AWS MAP, Delivered End to End

DoiT ran the engagement across the three AWS MAP phases, with each phase building the technical and financial foundation for the next - delivered end to end by DoiT's Forward Deployment Engineering team.

media

1. Assess: Building a Defensible Migration Budget

Before any workload moved, the team at Software Projects needed a clear, per-service view of what AWS storage and compute would cost. DoiT built a detailed cost breakdown covering EBS and EFS — modeling monthly storage, IOPS, and throughput costs across volume types and storage classes — so Software Projects could forecast short- and medium-term spend for its migration roadmap. DoiT also worked through discounting strategy for the Software Projects' database compute, comparing DoiT Flexsave (a discounted Compute Savings Plan-equivalent with no upfront commitment) against standard and convertible Reserved Instance pricing, and explained the tradeoffs of each in the context of a possible future move to a managed database service.

2. Mobilize: Solving Cross-Cloud Connectivity

Connectivity between IBM Cloud and AWS was the critical path for the entire migration, and it did not have an out-of-the-box answer. DoiT ran a structured evaluation of options — AWS Direct Connect, a dedicated IBM Direct Link circuit, virtual router appliances, and a lightweight mesh VPN — weighing cost, stability, and setup complexity for each:

  • Assessed AWS Direct Connect and IBM Direct Link Dedicated (including BGP, IP range, and billing constraints) as a dedicated-circuit option.
  • Piloted a mesh VPN overlay as a fast, zero-cost fallback while longer-term options were evaluated.
  • Guided Software Projects through deploying and tuning a virtual router appliance on the IBM side, including VLAN routing behavior and Layer 2 troubleshooting with IBM support.
  • Helped Software Projects move from IBM Classic Infrastructure to IBM VPC to gain more flexible networking, then stood up an IPSec site-to-site VPN between IBM VPC and an AWS VPC.
  • Diagnosed and resolved a subnet-overlap and routing gap between IBM Classic and AWS by allocating a dedicated, non-overlapping IP range and adjusting static routes — the fix that finally unblocked bidirectional traffic between all three environments.

The result was a stable, verified private network path connecting IBM Classic Infrastructure, IBM VPC, and AWS — the foundation that let the team at Software Projects move workloads on their own timeline without losing connectivity back to systems still running on IBM.

Keeping Production Healthy Through the Transition

During the migration window, DoiT also provided rapid operational support on the AWS side. In one case, an EC2 instance lost SSM connectivity unexpectedly with no SSH fallback available. DoiT used console-output diagnostics to identify the root cause — the root volume had run out of disk space, which prevented the SSM agent from starting — and provided a step-by-step remediation plan (volume expansion and filesystem resize) along with proactive CloudWatch disk-utilization alarms and SNS notifications to prevent recurrence, with particular attention to protecting production systems from the same failure mode.

3. Modernize: Containers and Continuous Cost Optimization

With the migration complete, the engagement moved into the Modernize phase. Software Projects' production and development stacks were still running on self-managed Docker Swarm clusters — functional, but carrying the operational overhead of manually patched managers and workers. DoiT is now helping the team at Software Projects retire those Swarm clusters in favor of a managed container platform on AWS (Amazon EKS), building directly on the consolidated, multi-AZ VPC foundation established during Mobilize rather than re-architecting from scratch.

As part of that same modernization push, DoiT is keeping cloud spend disciplined while the environment evolves. Using DCI Insights, DoiT reviewed the Software Projects' AWS Detective and GuardDuty configuration and found that security tooling costs had grown to a significant share of overall spend, driven primarily by high-volume flow-log ingestion rather than by security value delivered. DoiT quantified the tradeoffs — including which high-severity finding types depended on which data sources — and gave Software Projects a clear, evidence-based set of options for right-sizing security coverage without losing the highest-value detections. This same disciplined, evidence-first approach is carrying forward into the containerization work: right-sized from the start, rather than optimized after the fact.

The Solution: Powered by DoiT Cloud Intelligence (DCI)

Alongside the hands-on engineering, Software Projects leveraged several DoiT Cloud Intelligence (DCI) capabilities throughout the engagement — pairing an experienced delivery team with self-serve visibility into their own AWS environment:

media

The last two capabilities are active day to day: as the team at Software Projects modernizes onto containers, DCI AWS Intelligence and DCI Datadog Insights give them continuous visibility into total cloud and observability spend, rather than waiting for a monthly bill to surface an issue.

Results

  • 2 AWS MAP phases delivered: Assess, Mobilize, Modernize
  • 40 Servers migrated 1:1, preserving the full four-tier topology
  • 2→1 IBM Cloud regions consolidated into a single AWS VPC across multiple AZs

Connecting IBM and AWS privately was the piece we needed to get right, and we wanted to move faster on it than we could on our own. DoiT worked through the options with us, found the subnet overlap that was breaking the routing, and made it stable. That unblocked everything else.

DevOps Lead, Software Projects

Outcomes

  • Established the first working private network path between IBM Cloud Infrastructure and AWS, after earlier self-managed attempts had failed in one direction.
  • Migrated all 40 servers, the full four-tier load balancing, application, orchestration, and data topology, to AWS with the tier-by-tier composition unchanged, so the team inherited a familiar environment on day one.
  • Consolidated two geographically separate IBM Cloud regions into a single AWS VPC spanning multiple Availability Zones, simplifying the network and operational footprint without sacrificing the resilience of a dual-site design.
  • Gave Software Projects a granular, defensible cost model for storage and compute ahead of migration, reducing budget surprises during the move.
  • Resolved a production-impacting SSM outage with clear root cause and left Software Projects with proactive monitoring to catch the same failure earlier next time.
  • Delivered all three AWS MAP phases — Assess, Mobilize, and Modernize — under one continuous engagement, carrying migration context forward instead of resetting it at each phase boundary.
  • Positioned the customer to retire self-managed Docker Swarm clusters in favor of a managed container platform, with security and cost posture already right-sized before the next phase begins.
  • Left the customer with self-serve visibility into their own environment — DCI Cloud Diagrams for infrastructure mapping, and DCI AWS Intelligence and DCI Datadog Insights for continuous cloud and observability spend tracking.

Looking Ahead

Software Projects' AWS environment is now the stable foundation for its next phase of modernization. DoiT continues to partner with the customer as it moves workloads onto containers, applying the same combination of technical delivery and ongoing cost discipline that carried the migration from initial assessment through to a fully connected, production-ready AWS environment.

Learn more about Cloud Diagram and Cloud Intelligence

Accelerate your optimization

Visualize your cloud infrastructure in real time, find what your provider can't, fix it on your terms.

More customer stories

Shasta Cloud

Crystal-clear visibility into cloud spend at the workload and tenant level

Days
Time to first cost insights after install
Days
From install to powerful cost reporting
Workload & tenant
Granularity of cost visibility
Finlex

Finlex cuts cloud costs 50% and ships production AI with DoiT

Over 65%
reduction in cloud infrastructure costs from 2024 - present
40%
cost savings achieved through improved visibility and efficient AI architecture
Hippo

Turning cloud costs into team action at Hippo

Minutes
Time to integrate Attribute™ with AWS
Business unit
Level of cost accountability achieved
Island

Island gains true cost-per-customer visibility, without tagging

$5B
Company valuation
Days
Time to first insights
0
Tags required
Claroty

Claroty unlocks precise customer cost attribution with Attribute™

1,000+
Customers protected worldwide
Days
Time to first granular cost reports
Zero
Disruption to operations during deployment
SaaS Leader

How Customer-Level Cost Attribution Enables Value-Based AI Pricing

$1.3M
in negative-margin revenue surfaced
~360
unprofitable accounts identified
$1.3M
in aggregate losses surfaced
Salt Security

Salt Security standardizes COGS measurement to optimize margins and pricing

1
Source of truth for COGS
1
Standardized source of truth for COGS across CFO and DevOps
0
Code or tagging changes required to integrate Attribute™

What they say

Software Projects

Connecting IBM and AWS privately was the piece we needed to get right, and we wanted to move faster on it than we could on our own. DoiT worked through the options with us, found the subnet overlap that was breaking the routing, and made it stable. That unblocked everything else.

DevOps Lead, Software Projects

Shasta Cloud

Attribute™'s platform is truly unique. We now have crystal-clear visibility into our cloud spend at the workload and tenant level, and that insight has already led to actionable savings and powerful insights as we further scale our service.

Paul White, VP of Engineering, Shasta Cloud

Flooid

We have worked with DoiT for many years, and there has been an increasing number of capabilities and features in DoiT Cloud Intelligence. We've embedded features such as Cloud Analytics and Reports in our own FinOps processes, it's become core to what we do.

Martin Lee, Director of Operations

Finlex

DoiT gave us the confidence to move from experimentation to production. They helped us understand the right way to build AI for the real world.

Milad Rezazadeh, CTO

Hippo

Attribute™'s cost grouping technology took our cost visibility and allocation to a whole new level. Now, our teams are fully accountable for their budgets, significantly improving our cloud efficiency and helping us minimize unnecessary costs.

Eli Zilbershtein, Head of DevOps, Hippo

Island

You can't tag a customer in a multi-tenant environment. Attribute™ finally shows us what each customer costs and what's driving those costs.

Omri Cohen, Director of Engineering, Platform

Claroty

Attribute™'s data is truly unmatched. No other solution on the market could deliver the precise customer cost and usage profiles we needed in such a complex infrastructure. Within weeks, the data from Attribute™ transformed our understanding of cost structures, influencing key strategic decisions in pricing, renegotiations, and market positioning.

Jonathan Langer, COO, Claroty

Salt Security

Attribute™ simplified tracking customer costs in our multi-tenant environments. Customer cost measurement is now clear and standardized, and finance gets the business context they need. Integration was quick and required no changes.

Kfir Lippmann, CFO, Salt Security

PropertyGuru

Attribute™ translates complex cloud bills into actionable, business-centric insights that empower our engineering teams to take true ownership of their costs.

Balamurugan Mohandossgandhi, Head of IT and Infrastructure, PropertyGuru

Accrete AI

This has let us get a better idea of what our cost of goods sold really is. It's not every day you come across something that delivers value as quickly as yours did for us. I was seeing useful insights inside the POC, and we had only deployed it to a couple of real clusters.

Jason Moore, Principal DevOps Engineer, Accrete AI

Akamai

Eliminating the need to tag thousands of resources has freed up my team and we've invested our efforts in enhancing our platform significantly.

Ziv Sivan, VP of Engineering

OneFootball

PerfectScale by DoiT has become an important part of how we optimize Kubernetes at scale at OneFootball. It gives our platform team the visibility, automation, resiliency insights, and confidence we need to balance cost efficiency with production readiness, especially as we prepare for major global football moments like the 2026 FIFA World Cup.

Andrea Benfatto, Platform/Cloud Runtime Engineering Manager

Raptive

Cloudflow's new RDS End of Life alerts have allowed us to be more proactive on keeping our database instances up-to-date. The new solution gives us internal visibility ahead of time so that we can prepare for upgrades, instead of having to upgrade under pressure while incurring extended support costs.

Jon Fairbanks, Site Reliability Engineering Manager

Your cloud bill shouldn't be a mystery

Let us show you what ships this week.