Skip to content

Migrating a SaaS platform to the Scaleway sovereign cloud

Full SaaS migration from Vercel and Railway to Scaleway: Kapsule Kubernetes cluster, ArgoCD GitOps, Terraform/Terragrunt and a secured private network.

EXP-02Sovereign cloud
Client
SkipCall
Role
DevOps / Cloud Architect
Period
Nov 2025 → present
Status
Ongoing
Stack
ScalewayKubernetes (Kapsule)TerraformTerragruntArgoCDGateway APIExternal SecretsCert ManagerPostgreSQLCockpit

100%

of infrastructure as code

2

US PaaS providers replaced

Context

SkipCall ran its SaaS platform on Vercel and Railway, two US-based PaaS providers. To regain control over its data and costs, the company decided to repatriate its entire infrastructure to Scaleway, the French sovereign cloud.

I designed the target architecture, then drove the migration end to end: from the first Terraform module to the production cutover, with a security-audited architecture as a hard requirement.

Scaleway cloud architecture

  • Production-ready managed Kubernetes cluster (Kapsule), hardened and monitored.
  • Private network with VPN access: no unnecessary exposure surface.
  • S3-compatible Object Storage and managed PostgreSQL instances.
  • Centralized secrets management with External Secrets Operator.

GitOps and continuous delivery

  • ArgoCD as the single source of truth for every deployment.
  • Gateway API for routing (replaces the deprecated Ingress).
  • Automated TLS certificates with Cert Manager.
  • Monitoring, logs and alerting centralized in Cockpit.

Infrastructure as Code

  • Terraform and Terragrunt for DRY multi-environment management.
  • Reusable modules and strict environment separation.

Results

  • Platform fully moved off US PaaS providers, now hosted on a French cloud.
  • Security-audited Kubernetes architecture, 100% described as Infrastructure as Code.
  • GitOps continuous delivery: teams deploy without manual intervention.

A context close to yours?

Every engagement starts with a conversation about your existing setup and constraints.