The Terraform "Lift & Shift" Playbook: Migrating 200 Apps to Multi-Cloud with Terraform

The Terraform "Lift & Shift" Playbook: Migrating 200 Apps to Multi-Cloud with Terraform

Source: YouTube · Cloud Security Podcast · published Nov 6, 2025 · 15:32

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

The speaker details the migration of 200 applications from data centers to AWS and Azure using a one-year lift-and-shift strategy, emphasizing the use of ECS Fargate for serverless container execution to avoid the overhead of managing VMs or Kubernetes clusters 0:00.

Key Takeaways:
• Running Docker containers on VMs in production is inefficient and unnecessary 0:00.
• Kubernetes was rejected due to insufficient resources and management overhead at the time 0:07.
• ECS Fargate was selected to run containers serverlessly, eliminating infrastructure management 0:18.
• The project involved migrating 200 applications to public clouds like AWS and Azure to terminate data center leases 0:30.
• A one-year timeline with a lift-and-shift approach was used to empty data centers quickly 0:33.

This approach highlights the strategic shift toward managed cloud services and automation to reduce operational complexity and accelerate large-scale migrations.

Sources:

  • 0:00 Explanation of why running Docker on VMs in production is unnecessary.
  • 0:07 Reasons for avoiding Kubernetes due to lack of resources and management burden.
  • 0:18 Selection of ECS Fargate as the serverless solution for container execution.
  • 0:30 Overview of the migration from data centers to AWS and Azure.
  • 0:33 Details on the one-year timeline and lift-and-shift strategy for 200 applications.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

It make no sense to run a docker container on a virtual machine in production. No way we would do that. Regarding Kubernetes, at that time there was no resources to manage a Kubernetes cluster. There was no good reason to try to use Kubernetes. >> How did that fit into serverless? >> We use ECS Fargate. >> Okay. Okay. >> And with this one, we can run containers without having to manage any underlying infrastructure. What was the project about and where were you migrating from to where? >> We decided that we would migrate out of these data centers and move all public clouds like AWS and Azure. The first idea was to perform the migration within one year. >> It's 200 applications one year. >> We decided for a lift and shift approach. The idea is we needed to empty our data center as fast as p…