
Moving more than twelve applications from GCP to Azure with infrastructure as code
A two-month migration that introduced Pulumi, managed secrets with Doppler and Zero Trust access, and removed unused cloud resources along the way.
- Partner
- A multinational consultancy with more than 1,000 employees
- Period
- 2 months
- Applications migrated
- 12+
- Python applications moved from GCP PaaS to Azure
- Infrastructure as code
- Pulumi
- Every environment defined and deployed in code
- Access control
- Zero Trust
- Cloudflare with Microsoft Entra ID
The challenge
The partner deployed to Google Cloud by hand, with no infrastructure as code, no complete record of its resources and secrets shared informally. Unused resources were adding cost and new environments were slow to set up.
What we built
An audit and cleanup, then a migration of more than twelve Python applications to Azure, managed through Pulumi. Secrets moved into Doppler through a custom Pulumi provider, Cloudflare Zero Trust with Microsoft Entra ID now protects access, and frontends on Vercel joined the same codebase.
What was delivered
- Infrastructure defined as code and deployed through CI/CD
- Secrets held in Doppler and injected at deploy time
- New systems placed behind Zero Trust access through a Pulumi package
Partner background
Our partner is a multinational consultancy with more than 1,000 employees working across several regions for high-profile organizations. As it grew, it needed a more structured, secure and efficient way to manage the cloud resources behind the services it delivers.
The challenge
Fragmented cloud management
Resources on Google Cloud were created without a shared system for documentation and management, so it was hard to know what existed and why.
Informal secrets
API keys and credentials were shared informally, a risk that grew with the team.
Manual deployments
With no infrastructure as code and no specialist, every environment was set up by hand, which lengthened lead times for new projects.
Rising costs
Unused and redundant resources accumulated, with no clear view of what was driving spend.
Objectives
- Manage infrastructure in code the existing team could read and maintain
- Automate provisioning of new environments
- Remove legacy deployments and unused resources to reduce cost
- Replace informal secret sharing with central secrets management
- Protect systems with identity-based access
Our role
CharCentric planned and carried out the audit, migration and new infrastructure setup over two months.
Scope and timeline
The project migrated more than twelve Python applications from a non-containerized GCP PaaS setup to Azure, managed through Pulumi. It was delivered in two months.

Approach
Infrastructure as code in familiar languages
Pulumi lets infrastructure be written in TypeScript and Python, languages the partner's developers already used, and supports both GCP and Azure, which made a controlled move between them possible.
Clean before moving
An audit identified redundant and unused resources first, so only what was needed was migrated.
Secrets and access by design
Secrets come from Doppler at deploy time, and Cloudflare Zero Trust with Microsoft Entra ID is applied to new infrastructure as it is created.
Implementation

Audit and cleanup
Redundant GCP resources were identified and removed, which reduced cloud usage and cost.
Backend and database migration
Core backend services and databases moved to Azure with minimal downtime, with Zero Trust access applied immediately.
Frontend integration
Frontends hosted on Vercel were brought into the Pulumi codebase, so all environments are managed in one place.
Secrets
A custom Doppler provider package, written in TypeScript, fetches secrets from Doppler's API and injects them into Pulumi deployments.
Automation
Pulumi Cloud is connected to the existing CI/CD pipelines, so infrastructure changes follow the same review and release path as application code.
Tools and technologies
| Tool | Purpose |
|---|---|
| Pulumi and Pulumi Cloud | Infrastructure as code and deployment automation |
| Microsoft Azure | Target cloud platform |
| Doppler | Central secrets management |
| Cloudflare Zero Trust | Identity-based access to systems |
| Microsoft Entra ID | Identity provider |
| Vercel | Frontend hosting, managed through Pulumi |
What was delivered
- Applications migrated
- 12+
- Migration phases
- 4
- Central secrets
- Doppler
- Delivery
- 2 months
- All in-scope applications running on Azure under Pulumi management
- Provisioning of new environments automated through Pulumi and CI/CD
- Unused and redundant cloud resources removed before migration
- Secrets managed centrally instead of shared informally
Why it matters
Most of the value in a cloud migration comes from what changes along the way: knowing what you run, defining it in code and controlling who can reach it. Done together, those changes make the next project faster and the estate cheaper to run.
If your organization is facing a similar challenge, we would be glad to discuss it.