Case study 1 · AWS-compatible private cloud · MIT
Twinfra (formerly vCloud)
Your AWS twin, on your own infrastructure. Same CLI, same SDKs, same templates. Switch anytime.
The problem
Enterprises want AWS-style services on their own hardware for sovereignty, cost or edge sites, and they want to move workloads back to AWS without rewriting them. The existing options are either AGPL-licensed, emulators with no real infrastructure behind them, or private clouds with their own APIs.
The approach
- 01AWS API as the contract. A regional gateway checks AWS signatures (SigV4) and IAM policies. The AWS CLI, SDKs and CloudFormation work unchanged, and switching to AWS means changing one profile.
- 02Real infrastructure underneath, all Kubernetes-native: KubeVirt for EC2, CloudNativePG for RDS, Knative for Lambda in Go, and Prometheus with OpenSearch for CloudWatch. Less-used services are emulated and labelled as such.
- 03Measured compatibility. One test suite runs against real AWS and against Twinfra, and every API operation is scored Match, Partial or Missing.
- 04Licence-clean. Twinfra's own code is MIT, and every dependency is permissively licensed and checked in CI.
- 05Regions with disaster-recovery partners. Each production region has a partner cluster (for example
cairo-1withcairo-2), with asynchronous replication and a tested failover runbook.
flowchart TB
C["AWS CLI · AWS SDKs<br/>CloudFormation · console"]
A["Real AWS"]
C -->|"Twinfra profile"| G
C -.->|"AWS profile: the switch"| A
subgraph R["Twinfra region · e.g. cairo-1, DR partner cairo-2"]
G["API gateway (Go)<br/>SigV4 · IAM policy · audit"]
I["IAM · STS<br/>accounts"]
S["Service handlers<br/>EC2 · Lambda · RDS<br/>CloudWatch · CloudFormation · EKS"]
N["AWS-compatible servers<br/>SeaweedFS for S3<br/>ExtendDB for DynamoDB"]
E["MiniStack<br/>long tail · Emulated"]
P["Platform API<br/>Crossplane claims"]
B["KubeVirt · Knative<br/>CloudNativePG · OpenBao<br/>Prometheus · OpenSearch"]
G --> I & S & N & E
S --> P --> B
endEnterprise-architecture view
A product goal, a capability catalog mapping each AWS service to its on-prem implementation, a phased roadmap, decision records and a definition of done. It is the same discipline I apply to client programmes.
Sovereign edge
Traffic is scrubbed globally but decrypted, processed and logged only inside the serving region. Where a CDN cannot decrypt in-country, it scrubs at layer 4 with TLS passthrough, and TLS, the web application firewall and logs stay in-region.
Status today, stated honestly
The lab platform runs on a single node:
- Cilium default-deny networking and Argo CD GitOps with drift self-healing;
- PostgreSQL 18 with pgvector;
- a Keycloak-secured console with PKCE and MFA, behind an APISIX gateway.
The AWS API layer is the next phase. Repository →