Case Study

Designing a Scalable GKE Platform for a SaaS Application

How Buoyant Cloud helped a growing B2B SaaS company transform an early-stage Google Cloud setup into a secure, scalable, enterprise-ready GKE platform built for growth.

AT A GLANCE

Industry: B2B SaaS — Enterprise Software
Platform: Google Cloud (GKE, Terraform, Cloud Build, Artifact Registry, Secret Manager)
Services Delivered: GCP Architecture, Platform Engineering, DevSecOps
Location: Canada

Engagement led directly by Amit Malhotra, Principal GCP Architect at Buoyant Cloud Inc., Toronto.

 

The Business Problem

A fast-growing B2B SaaS company had built a product that was gaining traction — but its cloud platform had not evolved at the same pace.

What started as a functional startup environment was becoming a scaling liability.

As customer demand increased, the team began facing operational friction:

  • Infrastructure was largely manual and difficult to reproduce
  • Kubernetes deployments lacked standardization across environments
  • Security controls were inconsistent and difficult to validate
  • Release processes were becoming slower and riskier
  • Enterprise customer security reviews were exposing platform maturity gaps

The company was preparing for larger enterprise opportunities, but infrastructure maturity was starting to become a revenue blocker.

They needed a platform that could scale operationally, meet enterprise expectations, and reduce delivery risk — without slowing down product development.

A B2B SaaS Platform That Had Outgrown Its Infrastructure

A Canadian B2B SaaS company selling into enterprise markets across North America had built a product gaining traction — but the cloud platform underneath it had not kept pace.

The infrastructure had been built manually in the company’s early stages. Each environment was configured differently, deployments depended on a handful of engineers who understood the setup, and there was no Infrastructure as Code foundation to govern or reproduce what existed.

As the engineering team grew and enterprise opportunities increased, those early decisions were becoming operational and commercial liabilities.

New engineers took weeks to get productive. Production deployments relied on manual steps and tribal knowledge. Environment drift was creating inconsistencies across Development, Staging, and Production. And enterprise buyers were starting to ask difficult questions about security architecture, tenant isolation, IAM controls, and deployment governance.

The platform worked — but it was no longer built for the scale, operational maturity, or enterprise trust the company now needed.

What Needed to Change

Infrastructure drift was creating operational risk

Every environment had been provisioned manually, with no Terraform, no version control, and no repeatable provisioning model. This created inconsistency, reduced confidence in production changes, and increased recovery risk.

The Kubernetes platform wasn’t enterprise-ready

GKE had been adopted, but without the operational and security foundations required for multi-tenant SaaS workloads. Isolation, workload controls, and deployment governance were incomplete.

Deployments had become a business bottleneck

There was no CI/CD pipeline. Releases depended on individual engineers manually building and deploying workloads — slowing release cycles and increasing production risk.

Secrets and access controls were weak

Static service account keys and shared credentials created unnecessary exposure and made auditability difficult.

Enterprise sales were being slowed by security gaps

Customer procurement and security reviews were exposing gaps in documentation, controls, and architectural maturity — creating friction in revenue conversations.

The Platform Transformation

I designed and implemented a production-ready GKE platform foundation built for multi-tenant SaaS growth, enterprise security requirements, and operational scale — combining Infrastructure as Code, workload isolation, GitOps delivery, and security-by-default patterns.

Terraform foundation for repeatable infrastructure

All infrastructure was rebuilt into reusable Terraform modules covering GCP projects, VPC networking, GKE clusters, IAM, Artifact Registry, and Secret Manager. Separate Dev, Staging, and Production environments were provisioned from the same module library, eliminating environment drift and creating a fully reproducible platform foundation.

Enterprise-ready GKE architecture

The Kubernetes platform was redesigned around a regional GKE cluster architecture built for scale and isolation. Customer workloads were separated through namespace-per-tenant design, supported by dedicated node pools for platform services and application workloads, Pod Security Standards enforcement, resource quotas, and Network Policies to enforce workload boundaries and reduce noisy-neighbour risk.

Standardized application delivery with Helm and Argo CD

Application deployments were standardized using Helm charts to ensure consistency across environments, while Argo CD established a GitOps-based deployment model. This ensured all application changes were version-controlled, auditable, and automatically synchronized into GKE, improving deployment reliability and rollback safety.

Automated CI/CD with integrated DevSecOps controls

Cloud Build pipelines were implemented for container image builds, vulnerability scanning through Artifact Analysis, image signing, and promotion workflows. Combined with Binary Authorization policies, only approved and signed images could be deployed into production — introducing supply chain controls and reducing deployment risk.

Secure workload identity and centralized secrets management

Workload Identity replaced all static service account keys, removing long-lived credentials across the platform. Secret Manager was integrated for runtime access to database credentials, API keys, and certificates, improving auditability, reducing secret sprawl, and enabling automated rotation where supported.

Security documentation for enterprise procurement

Architecture and security documentation was created to directly support enterprise procurement reviews, covering IAM models, tenant isolation controls, audit logging, deployment governance, and deployment security controls — allowing the company to respond to enterprise security questionnaires with documented evidence rather than informal explanations.

Before vs After

BeforeAfter
Manually provisioned infrastructureFully Terraform-managed platform
Environment drift across Dev, Staging, ProdStandardized environments from shared modules
Manual deployments dependent on engineersAutomated CI/CD + GitOps delivery
Static service account keys and shared secretsWorkload Identity + Secret Manager
Limited workload isolationNamespace-based tenant separation
Weak answers to enterprise security reviewsDocumented, audit-ready architecture

What Changed After the Engagement

→ 100% of infrastructure version-controlled in Terraform
Zero static service account keys across all environments
45 minutes → 8 minutes deployment time reduction

Beyond the technical metrics:

  • Enterprise security questionnaires could now be answered with documented evidence instead of verbal assurances, reducing friction in procurement conversations
  • New engineers onboarded in days instead of weeks through self-service infrastructure and documented deployment workflows
  • Production deployment risk was significantly reduced through GitOps workflows, signed image enforcement, and automated promotion controls
  • Environment drift was eliminated across Development, Staging, and Production
  • Customer workloads were isolated through namespace boundaries and policy controls, improving platform scalability and operational safety
  • The platform met the security and operational baseline expected by enterprise customers and procurement teams

This type of engagement is common for B2B SaaS companies moving upmarket into enterprise accounts, preparing for SOC 2, or scaling beyond the infrastructure decisions made in their early growth stage.

If your GKE platform was built quickly and is now creating deployment risk, operational bottlenecks, or friction in customer security reviews, this is the kind of platform modernization work I typically lead.

Buoyant Cloud Inc
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.