A secure operations room with engineers at workstations under low amber light
Strategic KM / UK Ministry of Defence

Ministry of Defence: Secure Kubernetes PaaS for Classified Environments

A production secure Kubernetes PaaS built to strict Ministry of Defence security requirements for private data centers handling classified information.

Client Strategic KM / UK Ministry of Defence
Completed
Technologies & Services
KubernetesGovernment SecurityPrivate Cloud InfrastructureEvent-Driven ArchitecturePythonText Analysis

Project Goals

Create compliant platform-as-a-service solution meeting unique Ministry of Defence security and implementation requirements, build scalable event-driven text extraction and analysis pipeline for classified documents, deliver production-grade Kubernetes infrastructure for air-gapped private data centers, and win competitive government tender process.

The Problem

The UK Ministry of Defence needed to process classified documents at scale, and standard cloud services were off the table for obvious reasons. What it needed was a secure Kubernetes PaaS that could run entirely inside its own data centers.

Government work isn't easy to win, especially for a startup up against established defense contractors.

The requirements were strict: air-gapped data centers, security built to Ministry of Defence standards, production reliability and scalable text analysis, all with no internet access.

And before any of that, we had to win the tender.

Making the Case

Government tenders are demanding. They come with dense documentation, specific requirements and established competitors with existing relationships.

We took a different approach. Instead of promising what we'd build, we built a working prototype first, a proof of concept that showed exactly what the platform would do.

It had a Kubernetes cluster running in isolation, sample applications deploying automatically, a text extraction pipeline processing real documents and monitoring dashboards showing live metrics.

We documented everything. That included security compliance point by point, architecture diagrams explaining every decision, deployment procedures, risk assessments and cost breakdowns.

Where other bids relied on slides, we showed working code.

Result: government funding awarded.

What We Built

We built a platform-as-a-service for classified environments. Think of Heroku, but for defense infrastructure.

The Kubernetes Platform

We built production-grade infrastructure from scratch, with a multi-master setup for high availability, worker nodes for applications, persistent storage and network isolation, all automated.

Developers could deploy applications without managing servers. They had Git-based workflows, automated builds and self-service provisioning, just like a modern cloud platform, except air-gapped.

The catch is that no internet means you can't "just download it." Every dependency had to be packaged in advance, and every update had to be applied by hand.

Security Everywhere

Security was built into every layer. Network segmentation isolated workloads, data was encrypted at rest and in transit, and access was role-based. Every action was written to an audit log, and administrators used multi-factor authentication.

All of it was documented, auditable and compliant with Ministry of Defence standards.

Text Analysis Pipeline

The proof of concept became production: event-driven document processing at scale. Documents arrived through queue-based ingestion, Python services extracted the text, OCR handled scanned pages, and natural language processing and search indexing made the content usable.

The pipeline scales horizontally, tolerates faults and processes documents in parallel.

Air-Gap Deployment

Operating without internet access changes everything. You can't pull Docker images from Docker Hub, install packages from npm or PyPI, or download security updates automatically.

So we built offline workflows for everything: a private container registry, pre-downloaded dependencies, manual update procedures and thorough documentation for the operations team.

Everything deploys from local resources, with no external dependencies at any point.

The Technical Approach

Infrastructure as Code

Cluster configurations, network policies and application deployments were all defined as code and kept under version control.

That meant the entire platform could be rebuilt from scratch, and we tested that it could, rather than assuming it.

Operational Tooling

The operators needed visibility. We gave them centralized logging across the cluster, metrics collection and visualization, alerting, and backup and disaster recovery procedures.

These were operations tools rather than developer tools, made for the people keeping the platform running.

Event-Driven Processing

The text analysis pipeline was built on queues and workers. Documents land in the queue, workers pick them up and process them, results are stored, and the worker pool scales automatically with queue depth.

Whether there's one worker or many, the code and process are the same. Workers are added when the queue is busy and removed when it's idle.

The Results

Successfully awarded government funding. As a startup competing with established defense IT contractors, we made the case with working code and won the funding.

Security compliance for classified data. The platform met the Ministry of Defence's mandatory requirements for handling classified data.

Production Kubernetes PaaS deployment. This was production infrastructure running real workloads, well beyond a prototype or demo.

Scalable async text analysis pipeline. Document processing that used to need manual work now runs automatically and scales with demand.

What We Learned

Government work requires rigor. It takes meticulous documentation, complete requirements mapping and proof of capability, and you can't hand-wave anything. If you do that work, though, a startup can compete with much larger firms.

Security must be designed in. You can't bolt this level of security onto an existing platform; it has to be part of the foundation. Every architectural decision considered security first.

An air gap changes everything. The habit of "just download it" doesn't apply, and workflows that seem simple become complex. The constraint forces better practice, though. When you can't download a fix on demand, you build things carefully from the start.

Kubernetes was the right bet. This was before widespread adoption. Betting on Kubernetes early gave us deep experience by the time it became the industry standard.

Proof beats promises. Building a working prototype cost more upfront, but it made the case in a way slides couldn't have.

The hardest part wasn't the technology. It was navigating government procurement while delivering something that met the Ministry's real needs, and we did both.


Need secure platform infrastructure or government-compliant solutions? Let's talk →

See more complex technical projects View case studies →

Like what you see?

Tell us what you're building and we'll tell you how we'd approach it.

Start a project