Driving Kobble's DevSecOps Transformation for Banking-as-a-Service

Banking-grade security and scalable cloud infrastructure on AWS.

VirtueCloud architected a Zero-Trust AWS platform for Kobble, leveraging Amazon EKS on AWS Graviton, Infrastructure as Code, DevSecOps automation, and centralized observability to deliver a secure, highly available, and scalable Banking-as-a-Service solution.

6 min read
Driving Kobble's DevSecOps Transformation for Banking-as-a-Service

Challenge

Kobble is an Australian Banking-as-a-Service (BaaS) platform that enables businesses to launch embedded financial products including payment cards, digital wallets, accounts, and payment services. As the platform expanded and onboarded additional fintech customers, it required a highly secure, scalable, and automated cloud platform capable of supporting both Kubernetes-based microservices and serverless workloads. Key challenges included: - Managing infrastructure across multiple AWS accounts and environments - Maintaining strict security and governance requirements for financial workloads - Standardizing Kubernetes deployments across engineering teams - Supporting both containerized and serverless architectures - Strengthening deployment security and access management - Improving platform observability and operational visibility - Accelerating feature delivery while maintaining reliability and compliance The objective was to establish a cloud-native operating model that would support rapid product innovation, secure customer onboarding, and long-term platform scalability.

Solution

1

VirtueCloud partnered with Kobble to modernize its AWS platform through Kubernetes platform engineering, Infrastructure as Code, DevSecOps automation, cloud governance, and centralized observability.

2

Amazon EKS was implemented as the foundation for containerized workloads, while Terraform and CloudFormation standardized infrastructure provisioning and lifecycle management.

3

The platform was further enhanced through secure CI/CD pipelines, centralized identity management, workload isolation, monitoring, and event-driven serverless architectures.

Core Architecture & Components

Cloud-Native Platform

  • •Amazon EKS for Kubernetes-based workloads
  • •Multi-account AWS environment architecture
  • •Namespace isolation for multi-tenant applications
  • •Service mesh and secure workload communications

Infrastructure Automation

  • •Reusable Terraform modules
  • •Infrastructure as Code standardization
  • •CloudFormation deployments via Serverless Framework
  • •Automated environment provisioning

DevSecOps & CI/CD

  • •GitHub Actions deployment automation
  • •OIDC federation with AWS STS
  • •Elimination of long-lived AWS credentials
  • •Automated deployment pipelines

Identity & Governance

  • •Least-privilege IAM architecture
  • •AWS IAM Identity Center integration
  • •Cross-account role assumption
  • •Environment-level access segregation

Application Stack

LayerTechnology
Container PlatformAmazon EKS
Container ServicesAmazon ECS
Serverless ComputeAWS Lambda
API LayerAmazon API Gateway
DatabaseAmazon RDS
MessagingAmazon SQS
Event ProcessingAmazon EventBridge
Identity & AccessAWS IAM + IAM Identity Center
InfrastructureTerraform + CloudFormation
MonitoringDatadog + CloudWatch
DevOpsGitHub Actions + OIDC

Smart Workflow Automation

1. Secure Infrastructure Provisioning

Terraform modules automate infrastructure deployment and management across development, staging, and production environments, ensuring consistency and governance.

2. Kubernetes Workload Management

Amazon EKS hosts containerized microservices with namespace isolation, secure secret management, and IAM Roles for Service Accounts (IRSA) to improve workload security.

3. Secure Deployment Automation

GitHub Actions workflows leverage OIDC federation and AWS STS to securely deploy workloads without relying on long-lived AWS access keys.

4. Centralized Identity & Governance

AWS IAM Identity Center provides secure developer access while role-based permissions and environment segregation policies enforce governance controls.

5. Event-Driven Business Processing

AWS Lambda, Amazon SQS, and Amazon EventBridge enable scalable event-driven workflows and support business-critical financial services operations.

6. Monitoring & Operational Excellence

Datadog and CloudWatch provide centralized monitoring, alerting, logging, and infrastructure visibility to support proactive operations management.

Infrastructure Optimization

Security & Governance

  • OIDC-based deployment authentication
  • Least-privilege IAM controls
  • IRSA implementation for Kubernetes workloads
  • Environment-level access segregation
  • Centralized identity management

Performance & Scalability

  • Amazon EKS container orchestration
  • Multi-account AWS architecture
  • Microservices-based application design
  • Scalable event-driven processing

Operational Excellence

  • Terraform-driven infrastructure automation
  • GitHub Actions CI/CD pipelines
  • Centralized monitoring and observability
  • Automated infrastructure management

Objectives & Key Results

Objective 1: Strengthen platform security

01

OIDC-based authentication

02

Least-privilege IAM controls

03

Secure workload isolation

04

Centralized identity governance

Objective 2: Standardize infrastructure operations

01

Reusable Terraform modules

02

Infrastructure as Code adoption

03

Consistent environment management

Objective 3: Improve deployment efficiency

01

Automated CI/CD pipelines

02

Reduced manual deployment effort

03

Improved release consistency

Objective 4: Enhance operational visibility

01

Datadog observability platform

02

Centralized logging and alerting

03

Proactive issue detection

Business Impact

OIDC, IAM, IRSA, and governance controls
Security
Terraform-based standardization
Infrastructure Consistency
Automated CI/CD workflows
Deployment Efficiency
Centralized Datadog monitoring
Observability
Cloud-native Kubernetes architecture
Scalability
Automated and governed platform operations
Operational Excellence

Project Outcome

VirtueCloud successfully transformed Kobble's AWS platform into a secure, scalable, and cloud-native Banking-as-a-Service environment. Through Kubernetes operations, Infrastructure as Code, DevSecOps automation, and centralized governance, Kobble gained a modern cloud foundation capable of supporting rapid product innovation, secure financial services operations, and long-term growth.

Future Roadmap

Future enhancements include advanced platform observability, automated compliance reporting, FinOps optimization, infrastructure drift detection, enhanced security automation, and expanded multi-region resilience capabilities.