Application security & delivery — Romania

Protecting applications at scale.

A single application-security and delivery layer for one of Romania’s most-used public platforms — 100+ legacy and cloud-native applications protected across two data centres, built end to end on F5.

100+Applications
protected
2Data centres
+ cloud
F5BIG-IP ® NGINX
platform
ANAF application security and delivery hero with public servants, digital services and data center infrastructure

01The challenge

One security layer for a mixed application estate

ANAF’s citizen-facing services run on a mixed estate — established legacy applications alongside modern, cloud-native workloads on Kubernetes. Both are exposed to the public at scale, and both are under continuous attack.

The mandate was a single application-security and delivery layer that protects everything, old and new, without rebuilding the applications behind it. Four constraints shaped every decision.

P1 One posture, every app Legacy and cloud-native applications protected to the same standard, behind the same controls.
P2 Always on, two sites Global load balancing and failover between DC1 and DC2, with a 3rd-party cloud in the same fabric.
P3 Access at the edge Authentication and access policy enforced before traffic reaches an application.
P4 Kubernetes & API native Modern ingress and an API gateway for containerised workloads and published APIs.

02Scale

Public-facing services,
under constant attack.

150,000+
Platform users
500,000
Accesses per day
1.5M
Attacks prevented daily
100+
Applications protected

Traffic is steered to the healthy site by global load balancing, inspected by the web application firewall, and routed to legacy or cloud-native backends across two data centres.

03The F5 platform

Five F5 modules, one delivery and security layer

The entire application-security and delivery layer is F5 — one vendor from the global load balancer to the Kubernetes ingress, a single control and support chain for services that cannot go down.

F5 BIG-IP WAF Web application firewall

Signature- and behaviour-based protection for every published application; the layer that turns back roughly 1.5 million attacks a day before they reach an app.

F5 BIG-IP LTM Local traffic manager

Load balancing and application routing across the server pools at each site, for both legacy and containerised backends.

F5 BIG-IP APM Access policy manager

Authentication and access control at the edge, integrated with the identity layer.

F5 BIG-IP DNS Global server load balancing

Directs users to the healthy data centre and fails traffic over between DC1 and DC2.

F5 NGINX API gateway & ingress

API Gateway with JWT validation and NGINX Ingress Controller with App Protect in front of the Kubernetes clusters; governed through NGINX Management Suite and a Developer Portal.

04Architecture

One reference model, mirrored across two sites

The diagram shows the reference architecture model — not the actual internal implementation. Traffic enters through F5 DNS, is balanced by LTM, inspected by the WAF and NGINX App Protect, and routed through the NGINX API gateway and ingress into the Kubernetes clusters, legacy servers and virtualized infrastructure across both sites.

Frontend / IngressF5 DNS (GSLB) → LTM → BIG-IP WAF & NGINX App Protect, mirrored at DC1 and DC2
API & KubernetesNGINX API Gateway (JWT validation) + NGINX Ingress Controller (App Protect) → OpenShift and OKD clusters
Backend / InfraKubernetes workloads, legacy servers and virtualized servers, across DC1, DC2 and a 3rd-party cloud
SubstrateEvery F5 module on VELOS chassis clusters

05Substrate

From VIPRION to VELOS

All F5 modules were consolidated onto VELOS — F5’s chassis platform running on F5OS — replacing the previous VIPRION estate. Each BIG-IP instance runs as an isolated tenant on shared, redundant hardware.

Tenant isolationEach BIG-IP instance runs as its own isolated tenant on the chassis.
Independent scaling & lifecycleCapacity and upgrades handled per tenant, on shared redundant hardware.
Maintenance without user-facing downtimeRolling upgrades, backed by failover between the two sites.

06Integrations

Security logging, identity and API management

The platform is wired into the wider operations stack.

Security logging → GraylogEvery F5 module streams security and traffic telemetry to Graylog for correlation, alerting and audit.
IdentityAPM and the NGINX gateway integrate with Keycloak for edge authentication and JWT validation.
ManagementF5 BIG-IQ centralises BIG-IP configuration and compliance; NGINX Management Suite and the Developer Portal govern the API estate.

07Confidentiality note

We do not disclose specific names, locations, or the actual internal technology architecture of the project.

The diagram and figures on this page describe the reference architecture model and the publicly communicable scale of the engagement.

08Next step

Protecting critical public applications?

We designed, integrated and delivered the application-security and delivery layer for one of Romania’s most-used public platforms. If you are protecting a mixed estate of legacy and cloud-native applications — across multiple sites, at public scale — we can help.

Connect with us →