85
Services: delivered by Argo CD from charts and values in Git.
We moved an application-security vendor from hand-maintained Terraform to Terragrunt with one AWS account per environment, Argo CD delivery, and autoscaling built for bursty scanning workloads.
Application security SaaS · Client name withheld under NDA
Services: delivered by Argo CD from charts and values in Git.
Scanner tools: scaled from queue depth by KEDA.
Karpenter node pools: one per workload role, spot where safe.
The platform scans customers' code and cloud for security issues. Each environment was a separate plain-Terraform deployment, development and staging shared an AWS account, and releases ran from CI scripts with promotions done by automated merge requests.
The workload is unusual: 94 scanner tools, about 70 of them language-specific variants, that sit idle and then all start at once when customers connect repositories.
Infrastructure units cover the VPC, an optional NAT instance to cut data-transfer cost, Secrets Manager, and EKS with access entries; a second layer installs metrics-server, ingress, the AWS Load Balancer Controller, Argo CD, the FSx CSI driver, and Karpenter.
Secrets are created per environment in AWS Secrets Manager and synced into the cluster by External Secrets. A Kyverno policy injects corporate CA bundles into the product's pods, for customers whose networks inspect TLS. Developers can also spin up an ephemeral environment per pull request.

Each environment is isolated in its own account, a new one is a set of files and an apply, and scanning capacity follows the work instead of being provisioned for the peak. The team no longer runs its own storage cluster for the SaaS.
Runbooks for the Terragrunt layout, node pools, and storage, with the platform maintained by the vendor's DevOps team.
Planning something similar? Talk to an AWS partner in Armenia that has built it before.