Unlock the full power of AWS with Remāngu

Platform + services for high‑performance, security‑sensitive teams.

Client

Kistler

Service Type

AWS Professional Services, IM/OM, Security Optimization

Industry

Engineering & manufacturing

Services & Tech

Amazon Cloudfront, AWS WAF, AWS EKS, AWS Route53, Terraform, External-DNS, AWS Load balancer controller, AWS NLB, AWS ACM

Intro

Kistler needed to improve both the security and speed of their microservices‑based system without disrupting existing services. The solution added Amazon CloudFront and AWS WAF, kept end‑to‑end TLS from clients through CloudFront to the ALB and backend services, fit into their Kubernetes platform on AWS EKS, handled many subdomains, and was rolled out without downtime.

About the client

Kistler is a Switzerland‑based company known for making high‑precision measurement systems and sensors. Their digital platform supports a microservices‑based system.

Challenge

Add DDoS protection and improve performance without breaking existing services. Requirements:

  • Add DDoS protection with minimal service impact
  • Preserve end‑to‑end SSL/TLS encryption between all service layers
  • Support strict authentication
  • Fit cleanly into the existing Kubernetes‑based infrastructure (AWS EKS)
  • Work across multiple environments
  • Avoid downtime for critical services during migration
  • Improve DNS and SSL certificate management, especially across many subdomains
  • Keep operations stable and secure at all times

Solution

Revolgy worked with Kistler from planning and setup to launch and support. The core was Amazon CloudFront to handle web traffic and AWS WAF to block attacks and filter traffic by region. The design ensured end‑to‑end TLS encryption from clients through CloudFront, to the ALB, and down to backend services.

To connect the new setup with the existing platform, the team used a combination of AWS tools for security, traffic routing, and automation, integrating with the Kubernetes‑based system. Changes were introduced step by step, with testing to keep things safe. Because production had to stay online at all times, the migration was planned carefully to avoid any downtime.

Results

  • Stronger DDoS protection using AWS WAF
  • Geo‑blocking to restrict access by region
  • Smooth integration with Kubernetes
  • End‑to‑end TLS encryption across all layers
  • Easier management of DNS and certificates
  • Clear monitoring and alerting
  • Robust and flexible WAF rules
  • Final migration to production completed without any downtime

The team continues to support Kistler as they build on this foundation.

Tell us your challenge. We’re here to help.

Subscribe to receive the latest blog posts to your inbox every week.

Contact us

Related posts

Read more examples of successful cooperations.

No items found.

Ready to deploy your solution?

Talk to our AWS experts to find the perfect solution for your specific requirements and get deployed within days, not months.