A bank in Eastern Europe wanted its internal teams to get environments and managed services the way they would from a public cloud — a button, not a ticket — without anything leaving the bank. We delivered a full self-service private cloud that integrates with the bank’s own Keycloak and its existing Ceph storage, with per-tenant RBAC, self-managed network access, backup policy and threshold alerting. Three months from the start of integration to production.
About the project
The client is a bank running its own infrastructure for its own engineering, data and product teams. The pressure was internal rather than commercial: teams wanted environments, databases and services on demand, and everything they wanted had to be requested, approved and provisioned by hand. Delivery slowed at the infrastructure queue, and the infrastructure team spent its time on repetitive provisioning rather than on the platform.
Nothing could leave the bank, and nothing could route around the bank’s existing controls — identity, storage, audit and backup were already governed and already audited. A cloud that ignored them would have been a second control plane to defend in front of a regulator, which is worse than the problem it solves.
Goals and objectives
- Give internal teams a full cloud experience — managed services and ready environments provisioned on demand.
- Make ordering simple enough that it does not need a runbook, and reporting simple enough that resource usage per service and per user is one click.
- Let teams manage their own network access — firewall rules, load balancers, ACLs — inside their tenant boundary.
- Put backup and restore under managed policy rather than tribal knowledge.
- Give monitoring both a global and a per-tenant view, with threshold alerts over Telegram and SMTP.
- Integrate with what the bank already runs: Keycloak for identity, RBAC globally and per tenant, external Ceph for storage.
Proposed solution
A self-service cloud platform, delivered as a product and integrated into the bank’s existing controls rather than beside them.
Platform components. Managed services launched from a button; monitoring plus an audit trail of user actions; a public API for programmatic use of the cloud; a web interface for everyone else; and a billing interface that produces resource-usage reports per service and per user — internal chargeback rather than invoicing, but the same machinery.
Tenancy as the control boundary. Each team gets a tenant with its own quotas, its own RBAC, its own network policy and its own monitoring thresholds. What a team can do inside its tenant it does without asking; what crosses the boundary stays with central engineering. That line is what makes self-service acceptable in a regulated organisation.
Integration, not replacement.
- Keycloak — the bank’s own instance stays authoritative; the platform maps existing groups and roles onto platform roles.
- Ceph — the bank’s existing external cluster serves as storage, with its own capacity planning and operational history intact.
- RBAC — enforced globally and inside each tenant, consistent with how access is already reviewed.
Results and current state
- A working cloud-service management platform, in production three months after integration began.
- The bank’s existing Keycloak integrated with group and role mapping onto platform roles — one identity, one review process.
- The bank’s existing external Ceph integrated as platform storage.
- Teams manage network access, backups and monitoring thresholds inside their own tenants; central engineering handles the boundaries.
- Training and accompaniment for the bank’s team, with L3 support behind them.
Why this case matters
Self-service that a regulator can live with
Freedom inside the tenant, control at the boundary. Teams stop queueing for firewall rules without anyone losing the audit trail.
Existing identity and storage stay
Keycloak and Ceph were already governed, already audited, already capacity-planned. The platform integrated with them instead of standing up rivals.
Three months, because it is a product
The work was integration with the bank's processes, not building a cloud from parts. That is the whole difference in the timeline.
Usage reporting from day one
Per-service and per-user consumption in one click — the number an internal platform is asked for the moment it becomes popular.
This case study is published in anonymized form (Tier-3 evidence): the customer is described by profile, not by name. A customer reference is available under NDA on request — talk to Ænix sales.
Ænix is the team behind Cozystack — a CNCF project (Sandbox today; Incubating expected late summer 2026), Apache 2.0. Ænix commercializes it as Ænix Platform, as three platforms on one engine — Public Cloud, Private Cloud and AI — that combine rather than exclude each other.