A private, hybrid Azure platform for a utility company.

Cloudlit designed and implemented a secure, scalable Azure architecture for a leading utility organisation: a multi-tier network with site-to-site VPN, containerised microservices on Azure Container Apps, private data services and Azure Active Directory, integrating on-premises ERP systems with the cloud with zero public exposure of backend services.

Client
Leading utility company
Sector
Energy & Utilities · Azure
Platform
Azure Container Apps · Hybrid
07 / Case study

The challenge

  • A secure, reliable channel was needed between the on-premises data centre, including ERP systems, and Azure: encrypted, without exposing internal services to the public internet.
  • The existing system could not handle fluctuating workloads. During peak demand, performance degradation and latency affected users. A scalable microservices architecture was needed.
  • Sensitive operational and transactional data required strict access controls, with databases and storage never exposed publicly while remaining reachable by application services.
  • The platform had to integrate frontend applications, backend microservices, ERP systems and multiple data sources across environments.

Four secure communication patterns

Every flow in the platform follows one of four documented patterns, so there is no ambiguity about which paths exist and which are encrypted.

External

Public users reach the frontend only. Everything behind it is private.

VPN

Encrypted IPsec/IKEv2 tunnels carry all traffic between the on-premises ERP and Azure.

Logical

Microservices communicate with each other over private networking inside Azure Container Apps.

Database

Application services reach Cosmos DB, Blob Storage and Redis through Private Endpoints only.

What Cloudlit delivered

Secure hybrid network architecture

Azure Virtual Network with segmented gateway, application and data subnets. Site-to-site VPN between Azure VPN Gateway and the on-premises gateway, with all traffic inside encrypted IPsec tunnels.

Microservices-based application layer

Containerised applications on Azure Container Apps: a public-facing frontend and backend microservices handling order processing and integration logic over private networking.

Private data layer with zero public exposure

Azure Cosmos DB for transactional data, Blob Storage for unstructured data and Azure Cache for Redis, all behind Private Endpoints with traffic staying on the Azure backbone.

Identity and access management

Azure Active Directory for authentication, authorisation and RBAC. Managed Identities give services access to each other without credentials.

Optimised communication flows

Four secure patterns designed and documented: external, VPN, logical and database.

Security and compliance enhancements

Network isolation across tiers, encryption in transit and at rest, least-privilege NSG rules and Customer Managed Keys recommended for sensitive workloads.

Results

  • All backend and data services fully private with no public internet exposure, significantly reducing the attack surface.
  • Reliable encrypted connectivity between on-premises systems and Azure enables smooth data exchange with ERP systems.
  • Microservices with caching significantly reduced latency and improved responsiveness during peak loads.
  • Pay-as-you-go scaling of resources based on demand, reducing unnecessary infrastructure cost.
  • The platform is ready to scale, integrate new services and support additional workloads without major redesign.
More case studies

Other engagements.

Banking

AI platform inside a commercial bank's perimeter.

A commercial bank in Pakistan had a working AI pilot on hosted infrastructure and an approved business case, but production was blocked by risk, compliance and infrastructure. Cloudlit designed, built and operates the cloud and on-premise platform the bank's AI services run on, inside the bank's own perimeter.

Read the case study →
AI Workforce · AWS

Production-grade multi-region AWS platform.

A multi-region AWS platform for Teammates.ai covering infrastructure as code, automated pipelines, containers, security, GPU workloads, observability and disaster recovery.

Read the case study →
AI Platform · Sovereign

A sovereign infrastructure layer for an AI operating system.

Cloud infrastructure for wAI Industries' Alara OS using Red Hat OpenShift and Kubernetes, GPU and CPU pools, secure registries, sovereign on-premise deployment and managed operations. Cloudlit is Premium AI Delivery Partner to wAI Industries, providing the infrastructure layer for AI platform deployments in banking.

Read the case study →
Travel · Azure

Real-time flight deal alerts and bookings on Azure.

Cloudlit built a real-time flight deal notification and booking management system on Microsoft Azure for a travel startup: serverless functions, Amadeus travel APIs, SMS delivery and a central booking dashboard, with full observability and pay-for-what-you-use cost.

Read the case study →
AI & ML · AWS

A Dockerised, LLM-integrated crawling platform on AWS.

Cloudlit built a Dockerised web-crawling platform with Crawl4AI for a UAE startup, integrated with large language models to structure, summarise and enrich extracted content, so large-scale data collection and AI-powered analysis run without manual work.

Read the case study →
Asset management · Azure

IBM Maximo Application Suite automated on Azure OpenShift.

For a Netherlands-based firm operating across multiple industries, Cloudlit automated the deployment and lifecycle of IBM Maximo Application Suite on Azure Red Hat OpenShift: repeatable cluster provisioning with Ansible, licensing and storage handled as code, and CI/CD, monitoring and backup integrated for business-critical asset management.

Read the case study →

Bring us your hardest infrastructure problem.

Cloudlit brings architecture, platform engineering, security and operations together so enterprise teams can move from complexity to a controlled production environment.