Case studies/Government Cloud
Public sector · Sovereign private cloud · Romania
Government Cloud
A sovereign private cloud for a critical segment of Romanian public administration — over 500 servers across four Tier IV data centres, built end to end on the Red Hat ecosystem.

01The challenge
A private cloud for critical public services
The client needed a highly available, secure and scalable private cloud infrastructure for a critical segment of Romanian public administration — services that cannot be interrupted and data that cannot leave the country.
Four pillars drove every architectural decision. They were not treated as separate requirements but as a single set of constraints: any component that failed one of them was ruled out.
02Scale of the project
Production infrastructure,
at national scale.
Network fabric: Spine-Leaf, VXLAN, MP-BGP EVPN · full-mesh connectivity between all sites · high-availability, low-latency network · each site built to the same component plan.
03Geographic distribution
Two active-active primary sites, two recovery sites
The infrastructure spans four geographically separated data centres. DC1 and DC2 are active-active primary sites running full Production and Test clusters. DC3 and DC4 are disaster-recovery sites, built to the same plan.
DC1
DC2
DC3
DC4
Every site follows the same component plan — spine-leaf fabric, high-speed storage fabric, redundant Ceph storage, backup replicated between centres.
04Cloud architecture
One deployment unit, replicated four times
Select a level to zoom in. The diagrams show the reference architecture model — not the actual internal implementation of the project.
Four sites, full mesh connectivity
Each data centre talks directly to the other three. This removes single points of failure and enables failover and workload mobility between sites.
The same architecture, at every site
A single data centre is the standardised deployment unit, reused across all sites. Consistency simplifies operations, scaling and disaster recovery.
The control layer of the platform
The management plane runs on OpenShift and controls, automates and operates everything across the platform — both PaaS and IaaS. It hosts no business workloads.
Where the applications run
The PaaS cluster is the execution layer: containerised applications, microservices and cloud-native workloads, with horizontal scaling and high availability.
Virtual machines and infrastructure
The IaaS layer delivers virtual machines, software-defined networking and infrastructure services — suited to legacy workloads, stateful systems and VM-based applications.
05Technology stack
100% Red Hat, from metal to application
The entire solution runs on the Red Hat ecosystem. One vendor for the operating system, virtualisation, containers, storage, identity and lifecycle management — a single support chain for a platform that cannot go down.
Enterprise Kubernetes on RHEL CoreOS, with the CRI-O runtime and operator-driven lifecycle management. Hosts both containerised workloads and the OpenStack control plane.
A major architectural shift: the OpenStack control plane runs natively as pods on OpenShift, managed by Kubernetes operators, while the data plane runs on bare metal.
The layer everything else depends on: unified storage, central authentication, subscription and content lifecycle, and a hardened operating system.
06Delivery
What it took, across all four sites
The project was not only a platform problem. It meant procurement, logistics, physical installation and integration — run in parallel across four locations, from nothing to production-ready in months rather than years.



07Confidentiality note
We do not disclose specific names, locations, or the actual internal technology architecture of the project.
The diagrams and figures on this page describe the reference architecture model and the publicly communicable scale of the engagement.