The Azure Cloud Foundations for MIRRI’s Citizen Document Platform
From a partially‑deployed, at‑risk build to a production‑ready, code‑first Azure platform – delivered alongside systems integrator DXC in 6 months.
Client
MIRRI (via DXC)
Industry
Government
Environment
Microsoft Azure
Challenge
Production-first greenfield cloud foundation delivery
Timeline
6 months to production-ready
The Client
MIRRI, via DXC
MIRRI runs a government platform that generates official documents for citizens living abroad, delivered as part of an EU‑funded programme through systems integrator DXC. By the time Plectrum was engaged, DXC had started the platform’s Azure infrastructure build. Plectrum stepped in alongside them, and together the two teams got the environments to the stable, complete state the programme needed.
Test and production milestones were already at risk, and for an EU‑funded government contract, missed milestones meant real contractual penalties – not just delay.
The Challenge
Started, but Not Stable
One Partial Environment
Only one environment was partially deployed, with no workloads actually running.
IaC Coverage Gaps
Infrastructure as code covered less than half of the platform’s real footprint.
No Edge or CI/CD
Azure Front Door and CI/CD pipelines were entirely absent from the build.
Duplicated Helm Charts
Charts were duplicated per environment and per app despite sharing 99% of their content.
The Delivery
In Numbers
~ 90%
Cut new environment setup time.
0
Azure subscriptions under a secure model with just-in-time access.
0
Services (11 per environment) migrated to AKS.
~ 100%
Of infrastructure managed as code.
In Technology
In Detail
Fix the Foundation, Not the Symptoms
Rebuilt the infrastructure as a single repeatable Terraform blueprint that could stamp out dev, test, and production consistently.
One Helm Chart, Not Four
Consolidated duplicated per-environment, per-app charts into a single standardized chart, removing a class of configuration drift.
Security Built In, Not Bolted On
Azure Front Door, WAF, managed certificates, Key Vault secrets, and OIDC-based CI/CD were designed in from the start.
Infrastructure & Environments
- Terraform-based infrastructure with reusable modules and Terraform Cloud configuration
- Dev, test, and production provisioned from a single repeatable blueprint
- 4 environments delivered: dev, test, prod, and shared (AFD, LAW, AKV, ACR)
Application Platform
- Full workload migration to Azure AKS with high availability and autoscaling
- Unified Helm charts across all environments and applications
- 33 services (11 per environment) moved to AKS
Network & Edge Security
- Azure Front Door with managed certificates and WAF across all public endpoints
- Detection mode enabled, with readiness to switch to Prevention
- ~12 public endpoints protected, with path-based routing rules
Data & Secrets
- Managed MySQL database with backup policies across all Azure VMs
- Centralized secrets and configuration via Azure Key Vault
- Keycloak and Domibus access restrictions
Delivery & Observability
- GitHub Actions CI/CD using OIDC — no long-lived credentials
- ArgoCD for GitOps-based deployment into AKS
- Fluent Bit and Fluentd log shipping to Log Analytics Workspace
Handover
- A clear operating model for the internal team to run independently
- Documented, code-first platform with no configuration drift
- Plectrum available as an ongoing technical partner
The Outcome
From an At-Risk Build to a Production-Ready Government Platform
In six months, Plectrum took the platform from a partially-deployed, at-risk build to a production-ready Azure foundation running four full environments, with ~100% of infrastructure defined as code and every public endpoint protected behind Azure WAF and managed certificates.
Speed
New environment setup time cut by more than 90% – a pipeline run, not a manual rebuild.
Audit
Every change ships through GitHub Actions and ArgoCD’s GitOps pipeline – no long-lived credentials in the loop.
Focus
33 services running on AKS across dev, test, and production, with CI/CD and GitOps end to end.
Trust
A documented, code-first platform MIRRI and DXC’s team can run independently.
The Client Reference
“We brought Plectrum in to complement our own DevOps capacity and, above all, for their hands-on Azure expertise – AKS, Azure Front Door, and GitOps with ArgoCD – which was exactly where we needed depth. Working closely with our engineer, their one-to-two person team lifted the platform to a production-ready, code-first state. A knowledgeable, reliable partner we’d gladly work with again.”

