Case studies/Government Cloud

Public sector · Sovereign private cloud · Romania

Government Cloud

A sovereign private cloud for a critical segment of Romanian public administration — over 500 servers across four Tier IV data centres, built end to end on the Red Hat ecosystem.

ClientPublic sector, Romania
RoleArchitecture & delivery
PlatformRed Hat OpenShift + OpenStack
Footprint4 Tier IV data centres
StatusIn production
Government Cloud data centre

01The challenge

A private cloud for critical public services

The client needed a highly available, secure and scalable private cloud infrastructure for a critical segment of Romanian public administration — services that cannot be interrupted and data that cannot leave the country.

Four pillars drove every architectural decision. They were not treated as separate requirements but as a single set of constraints: any component that failed one of them was ruled out.

P1 High availability & redundancy No single point of failure at site, fabric or cluster level.
P2 Virtualisation & containerisation Virtual machines and containers on the same platform, with a shared control plane.
P3 Security & compliance Central identity, mTLS between services, encryption at rest, SELinux enforcing.
P4 Multi-DC distribution Four full-mesh interconnected sites, with geographic failover and disaster recovery.

02Scale of the project

Production infrastructure,
at national scale.

500+
Physical servers
80+
Storage systems
300+
Network devices
4
Tier IV data centres

Network fabric: Spine-Leaf, VXLAN, MP-BGP EVPN · full-mesh connectivity between all sites · high-availability, low-latency network · each site built to the same component plan.

03Geographic distribution

Two active-active primary sites, two recovery sites

The infrastructure spans four geographically separated data centres. DC1 and DC2 are active-active primary sites running full Production and Test clusters. DC3 and DC4 are disaster-recovery sites, built to the same plan.

Primary

DC1

Production + TestManagement clusterPaaS + IaaS clusters
Primary

DC2

Production + TestManagement clusterPaaS + IaaS clusters
DR site

DC3

Production + TestManagement clusterPaaS + IaaS clusters
DR site

DC4

Production + TestManagement clusterPaaS + IaaS clusters

Every site follows the same component plan — spine-leaf fabric, high-speed storage fabric, redundant Ceph storage, backup replicated between centres.

04Cloud architecture

One deployment unit, replicated four times

Select a level to zoom in. The diagrams show the reference architecture model — not the actual internal implementation of the project.

Four sites, full mesh connectivity

Each data centre talks directly to the other three. This removes single points of failure and enables failover and workload mobility between sites.

EnvironmentTest and Production, mirrored at every site
ClustersManagement, PaaS (OpenShift), IaaS (OpenStack)
StorageRed Hat Ceph Storage + backup
NetworkSeparate network fabric and storage fabric

05Technology stack

100% Red Hat, from metal to application

The entire solution runs on the Red Hat ecosystem. One vendor for the operating system, virtualisation, containers, storage, identity and lifecycle management — a single support chain for a platform that cannot go down.

Red Hat OpenShift PaaS layer

Enterprise Kubernetes on RHEL CoreOS, with the CRI-O runtime and operator-driven lifecycle management. Hosts both containerised workloads and the OpenStack control plane.

Container Platform
OCP 4.17+ · Kubernetes 1.30+
OpenShift Data Foundation
RBD · CephFS · RGW / S3
OpenShift GitOps
Argo CD
Service Mesh
Istio · Envoy · Kiali
Red Hat OpenStack Services on OpenShift IaaS layer · RHOSO 18

A major architectural shift: the OpenStack control plane runs natively as pods on OpenShift, managed by Kubernetes operators, while the data plane runs on bare metal.

Nova · Compute
Neutron · Networking
Cinder · Block
Glance · Image
Keystone · Identity
Horizon · Dashboard
Heat · Orchestration
Barbican · Key management
Foundation Storage · identity · lifecycle · OS

The layer everything else depends on: unified storage, central authentication, subscription and content lifecycle, and a hardened operating system.

Red Hat Ceph Storage
Ceph 7 · RBD · CephFS · RGW
Red Hat build of Keycloak
RHBK 26.x · OIDC · SAML · OAuth 2.0
Red Hat Satellite
Satellite 6.16 · Capsule per DC
Red Hat Enterprise Linux
RHEL 9.x · RHCOS

06Delivery

What it took, across all four sites

The project was not only a platform problem. It meant procurement, logistics, physical installation and integration — run in parallel across four locations, from nothing to production-ready in months rather than years.

Meet client requirements
Design the architecture
Solve infrastructure pitfalls
Place hardware orders
Manage delivery lead times
Negotiate with vendors
Install hardware in four locations
Build the networks
Deploy the platforms
Documentation and runbooks
Hardware installation
Network build
Platform deployment

07Confidentiality note

We do not disclose specific names, locations, or the actual internal technology architecture of the project.

The diagrams and figures on this page describe the reference architecture model and the publicly communicable scale of the engagement.

08Next step

Building sovereign infrastructure?

We designed and delivered one of the largest private clouds in Central and Eastern Europe. If you are evaluating a multi-DC platform, a migration programme or the modernisation of critical infrastructure, we can help.

Connect with us →