Home / Case Studies / Platform engineering
Platform engineering

An EKS platform that scales data jobs from the queue.

Terragrunt-built AWS accounts and Amazon EKS for an ad-tech identity platform, with Karpenter for nodes, KEDA jobs driven by Amazon SQS, and Argo CD rolling out new images automatically.

Ad tech · Client name withheld under NDA

6

Clusters on the same code: four development regions and two production clusters.

2

AWS accounts: guarded against cross-account mistakes.

Batch jobs

Started from SQS queue depth, not schedules.

Amazon EKSAmazon SQSTerragruntKarpenterKEDAArgo CDHelmExternal SecretsGitHub ActionsAmazon CloudWatch

The challenge

The platform runs data-science batch jobs, such as IP-change processing, clustering, grouping, and email sanitising, that arrive in bursts. Fixed node groups were either idle or short of capacity, and environments needed to be reproducible across accounts and regions.

The constraints

  • Two AWS accounts, development and production, that must never be confused.
  • No long-lived cloud credentials in CI.
  • Secrets must stay encrypted in Git.

Decisions & tradeoffs

  • Terragrunt with the account, environment, and region hierarchy, and an allowed-account guard in every generated provider.
  • Two stacks per environment, infrastructure and Kubernetes commons, linked by a dependency.
  • Karpenter with consolidation and a mix of spot and on-demand capacity, keeping Cluster Autoscaler only as a disabled fallback.
  • KEDA ScaledJobs that start workers from SQS queue depth instead of schedules.
  • Argo CD with Image Updater: new semver tags in ECR are picked up and written back to Git.

The implementation

GitHub Actions deploys through AWS OIDC roles, so CI holds no keys. Secrets use SOPS with KMS through helm-secrets and External Secrets with Secrets Manager. Argo CD signs in through GitHub SSO, logs go to CloudWatch through Fluent Bit, and production nodes run an endpoint security sensor.

GitHub Actions pushes images to ECR and applies Terragrunt across two AWS accounts; Argo CD with Image Updater deploys new tags to EKS from the eks-ops repo; KEDA starts jobs from SQS queue depth; Karpenter adds nodes; Secrets Manager feeds External Secrets.
Ad-tech EKS platform. Highlighted: the image delivery path.

Outcomes

Batch capacity now follows the queue, and the same code grew the platform from one development region to four, plus two production clusters.

Handover & ongoing ownership

The Terragrunt and Argo CD repositories with their conventions, maintained by the client's engineers.

Planning something similar? Talk to an AWS partner in Armenia that has built it before.

What’s next for
your business?

Let’s talk