Case study 03 · Engineering Lifecycle Services

Moving more than twelve applications from GCP to Azure with infrastructure as code

A two-month migration that introduced Pulumi, managed secrets with Doppler and Zero Trust access, and removed unused cloud resources along the way.

Partner
A multinational consultancy with more than 1,000 employees
Period
2 months
Photo: Joey Kyber on Unsplash
Applications migrated
12+
Python applications moved from GCP PaaS to Azure
Infrastructure as code
Pulumi
Every environment defined and deployed in code
Access control
Zero Trust
Cloudflare with Microsoft Entra ID

The challenge

The partner deployed to Google Cloud by hand, with no infrastructure as code, no complete record of its resources and secrets shared informally. Unused resources were adding cost and new environments were slow to set up.

What we built

An audit and cleanup, then a migration of more than twelve Python applications to Azure, managed through Pulumi. Secrets moved into Doppler through a custom Pulumi provider, Cloudflare Zero Trust with Microsoft Entra ID now protects access, and frontends on Vercel joined the same codebase.

What was delivered

  • Infrastructure defined as code and deployed through CI/CD
  • Secrets held in Doppler and injected at deploy time
  • New systems placed behind Zero Trust access through a Pulumi package

Partner background

Our partner is a multinational consultancy with more than 1,000 employees working across several regions for high-profile organizations. As it grew, it needed a more structured, secure and efficient way to manage the cloud resources behind the services it delivers.

The challenge

Fragmented cloud management

Resources on Google Cloud were created without a shared system for documentation and management, so it was hard to know what existed and why.

Informal secrets

API keys and credentials were shared informally, a risk that grew with the team.

Manual deployments

With no infrastructure as code and no specialist, every environment was set up by hand, which lengthened lead times for new projects.

Rising costs

Unused and redundant resources accumulated, with no clear view of what was driving spend.

Objectives

  • Manage infrastructure in code the existing team could read and maintain
  • Automate provisioning of new environments
  • Remove legacy deployments and unused resources to reduce cost
  • Replace informal secret sharing with central secrets management
  • Protect systems with identity-based access

Our role

CharCentric planned and carried out the audit, migration and new infrastructure setup over two months.

Scope and timeline

The project migrated more than twelve Python applications from a non-containerized GCP PaaS setup to Azure, managed through Pulumi. It was delivered in two months.

Migration phases over two months
Migration phases over two months

Approach

Infrastructure as code in familiar languages

Pulumi lets infrastructure be written in TypeScript and Python, languages the partner's developers already used, and supports both GCP and Azure, which made a controlled move between them possible.

Clean before moving

An audit identified redundant and unused resources first, so only what was needed was migrated.

Secrets and access by design

Secrets come from Doppler at deploy time, and Cloudflare Zero Trust with Microsoft Entra ID is applied to new infrastructure as it is created.

Implementation

Target architecture
Target architecture

Audit and cleanup

Redundant GCP resources were identified and removed, which reduced cloud usage and cost.

Backend and database migration

Core backend services and databases moved to Azure with minimal downtime, with Zero Trust access applied immediately.

Frontend integration

Frontends hosted on Vercel were brought into the Pulumi codebase, so all environments are managed in one place.

Secrets

A custom Doppler provider package, written in TypeScript, fetches secrets from Doppler's API and injects them into Pulumi deployments.

Automation

Pulumi Cloud is connected to the existing CI/CD pipelines, so infrastructure changes follow the same review and release path as application code.

Tools and technologies

ToolPurpose
Pulumi and Pulumi CloudInfrastructure as code and deployment automation
Microsoft AzureTarget cloud platform
DopplerCentral secrets management
Cloudflare Zero TrustIdentity-based access to systems
Microsoft Entra IDIdentity provider
VercelFrontend hosting, managed through Pulumi

What was delivered

Applications migrated
12+
Migration phases
4
Central secrets
Doppler
Delivery
2 months
  • All in-scope applications running on Azure under Pulumi management
  • Provisioning of new environments automated through Pulumi and CI/CD
  • Unused and redundant cloud resources removed before migration
  • Secrets managed centrally instead of shared informally

Why it matters

Most of the value in a cloud migration comes from what changes along the way: knowing what you run, defining it in code and controlling who can reach it. Done together, those changes make the next project faster and the estate cheaper to run.

If your organization is facing a similar challenge, we would be glad to discuss it.