A private cloud inside a bank

Self-service environments for internal teams, three months to production

Private cloud Bank · regulated Keycloak · RBAC External Ceph Self-service

A bank in Eastern Europe wanted its internal teams to get environments and managed services the way they would from a public cloud — a button, not a ticket — without anything leaving the bank. We delivered a full self-service private cloud that integrates with the bank’s own Keycloak and its existing Ceph storage, with per-tenant RBAC, self-managed network access, backup policy and threshold alerting. Three months from the start of integration to production.

3 months
from the start of integration to production
Existing Keycloak
kept as the identity source, with group and role mapping onto platform roles
Per tenant
RBAC, network rules, backup policy, monitoring thresholds and usage reports

About the project

The client is a bank running its own infrastructure for its own engineering, data and product teams. The pressure was internal rather than commercial: teams wanted environments, databases and services on demand, and everything they wanted had to be requested, approved and provisioned by hand. Delivery slowed at the infrastructure queue, and the infrastructure team spent its time on repetitive provisioning rather than on the platform.

Nothing could leave the bank, and nothing could route around the bank’s existing controls — identity, storage, audit and backup were already governed and already audited. A cloud that ignored them would have been a second control plane to defend in front of a regulator, which is worse than the problem it solves.

Goals and objectives

  • Give internal teams a full cloud experience — managed services and ready environments provisioned on demand.
  • Make ordering simple enough that it does not need a runbook, and reporting simple enough that resource usage per service and per user is one click.
  • Let teams manage their own network access — firewall rules, load balancers, ACLs — inside their tenant boundary.
  • Put backup and restore under managed policy rather than tribal knowledge.
  • Give monitoring both a global and a per-tenant view, with threshold alerts over Telegram and SMTP.
  • Integrate with what the bank already runs: Keycloak for identity, RBAC globally and per tenant, external Ceph for storage.

Proposed solution

A self-service cloud platform, delivered as a product and integrated into the bank’s existing controls rather than beside them.

Platform components. Managed services launched from a button; monitoring plus an audit trail of user actions; a public API for programmatic use of the cloud; a web interface for everyone else; and a billing interface that produces resource-usage reports per service and per user — internal chargeback rather than invoicing, but the same machinery.

Tenancy as the control boundary. Each team gets a tenant with its own quotas, its own RBAC, its own network policy and its own monitoring thresholds. What a team can do inside its tenant it does without asking; what crosses the boundary stays with central engineering. That line is what makes self-service acceptable in a regulated organisation.

Integration, not replacement.

  • Keycloak — the bank’s own instance stays authoritative; the platform maps existing groups and roles onto platform roles.
  • Ceph — the bank’s existing external cluster serves as storage, with its own capacity planning and operational history intact.
  • RBAC — enforced globally and inside each tenant, consistent with how access is already reviewed.
Bank private cloud: internal teams enter through a web console or the public API; the platform enforces per-tenant RBAC, quotas, network policy (firewall, load balancer, ACL), backup policy and threshold monitoring; identity comes from the bank's existing Keycloak with group and role mapping, storage from the bank's external Ceph cluster; usage reports feed internal chargeback1200 × 640

Results and current state

  • A working cloud-service management platform, in production three months after integration began.
  • The bank’s existing Keycloak integrated with group and role mapping onto platform roles — one identity, one review process.
  • The bank’s existing external Ceph integrated as platform storage.
  • Teams manage network access, backups and monitoring thresholds inside their own tenants; central engineering handles the boundaries.
  • Training and accompaniment for the bank’s team, with L3 support behind them.

Why this case matters

Self-service that a regulator can live with

Freedom inside the tenant, control at the boundary. Teams stop queueing for firewall rules without anyone losing the audit trail.

Existing identity and storage stay

Keycloak and Ceph were already governed, already audited, already capacity-planned. The platform integrated with them instead of standing up rivals.

Three months, because it is a product

The work was integration with the bank's processes, not building a cloud from parts. That is the whole difference in the timeline.

Usage reporting from day one

Per-service and per-user consumption in one click — the number an internal platform is asked for the moment it becomes popular.


This case study is published in anonymized form (Tier-3 evidence): the customer is described by profile, not by name. A customer reference is available under NDA on request — talk to Ænix sales.

Ænix is the team behind Cozystack — a CNCF project (Sandbox today; Incubating expected late summer 2026), Apache 2.0. Ænix commercializes it as Ænix Platform, as three platforms on one engine — Public Cloud, Private Cloud and AI — that combine rather than exclude each other.

Frequently asked questions

Did the bank have to adopt a new identity system?

No. The bank’s existing Keycloak stayed the source of truth and the platform integrated with it, mapping the bank’s groups and roles onto platform roles. Nobody got a second set of credentials, and joiner-mover-leaver processes kept working the way audit already understood them.

Who manages network access inside a tenant?

The teams themselves. Firewall rules, load balancers and ACLs are theirs to manage within the boundary of their own tenant. That was an explicit requirement: self-service that still requires a ticket for a firewall rule is not self-service, and central network engineering did not want to be in that queue.

What about backups and monitoring?

Both are part of the platform rather than adjacent tools. Backup and restore rules are managed as policy. Monitoring is configurable globally and per tenant, with threshold-based alerting delivered over Telegram and SMTP, so a team watches its own services without waiting for a central dashboard change.

Was existing storage reused?

Yes — the platform integrates with the bank’s external Ceph cluster. Storage the organisation already owns, operates and has capacity planning for does not need to be rebuilt to stand up a cloud on top of it.

How long did it take?

Three months from the start of integration to production. The short path came from the platform being a product rather than a bespoke build: the work was integration with the bank’s identity, storage and processes, not construction of a cloud from parts.

Ready to talk?

Book a 30-minute discovery call — no commitment. We confirm fit, the right platform, and the next steps.