60
Customer configurations: managed from one repository.
A repeatable way for an application-security vendor to install and update its platform inside enterprise customers' own environments, from Amazon EKS to air-gapped data centres.
Application security SaaS · Client name withheld under NDA
Customer configurations: managed from one repository.
Target platform types: EKS, AKS, GKE, OpenShift, and VMs, including air-gapped.
A daily table of which version runs where.
Large enterprises wanted the product in their own accounts and networks, not as shared SaaS. Every install was a one-off, and every customer was different: Amazon EKS, Azure AKS, Google GKE, OpenShift, plain virtual machines, and sites with no internet access at all.
On customer AWS accounts the pipeline creates the cluster with eksctl and a scoped deployment role; on other platforms it targets the customer's existing cluster. Rook-Ceph provides storage where no cloud storage exists. A Kyverno policy injects the customer's CA bundle so the product works behind TLS-inspecting proxies. Datadog monitoring is wired in per customer.

Adding a customer is a pipeline run from a template instead of a project, and a daily table shows exactly which version each customer runs.
Pipeline documentation, the customer template, and the readiness checker, used by the vendor's DevOps team.
Planning something similar? Talk to an AWS partner in Armenia that has built it before.