Systems

  • Landing zone
  • Pharmacy benefits
  • Express Scripts
  • superseded
  • Engineer on the platform team — argued against it, then built the deploy path
  • years
  • Pivotal Cloud Foundry, Jenkins, Kubernetes, OpenShift, Amazon EKS
  • 5 min read

The vendor pitch that wins the approval doesn't cancel the specialist bill.

What was on fire

Nothing was down. This was a platform decision, and I was on the losing side of it. In the first year of the custom Jenkins build, the pipeline was deploying everything from on-prem .NET stacks to on-prem Kubernetes to on-prem Pivotal Cloud Foundry. Then everybody decided we were going to shift all of it to PCF.

engraving of a cutaway iron lever lock with its case opened to show the stacked levers, the bolt, and the coil spring, a key turned in the keyhole at the front
I told the people deciding, at the time, that PCF was not the right way to go. It was vendor lock-in. Kubernetes was starting to get big, it was backed by Google, and it was clearly going to be the obvious direction of the industry. Go with that and do it right from the beginning. The burn came years later, at the unwind — the migration entry is the invoice.

Constraint set

The people who decided PCF were the long-timers. We were the newcomers on the platform team, and it was a very political place. The workforce had been hired to write Java and solve business problems, not to own the infrastructure underneath, so an argument about needing specialists had an audience.

There was a pattern underneath the decision that a lot of large organizations follow: have a vendor do it, so you don’t have to worry about long-term support or build internal knowledge on how to run the thing. Just call the vendor and they’ll fix it. That was the mindset until the acquisition. I didn’t win the argument against it.

System diagram

Custom Jenkins the pipeline .NET, on-prem Kubernetes, on-prem PCF, on-prem first year PCF, the standard I argued for Kubernetes and lost, then built the on-ramp anyway the acquisition the last few years OpenShift, on-prem EKS, on AWS both Kubernetes
Fig. 01 — Three deploy targets collapsed to one vendor platform in the first year. The estate runs on Kubernetes now, in two flavors — the direction I argued for, one platform generation late.

Fig. 01 · pinch or scroll to zoom · drag to pan

Architecture decisions

  1. The pitch that won: a vendor stands it up. Kubernetes was difficult to learn, and we would need specialized people to get it up and running. PCF meant a vendor came in and did it for us, with a nice UI on top. That is a real argument for a workforce hired to write Java, and it was the easiest way to get approval from executive leadership. Salespeople pitch to leadership, and the people on the ground are left picking up the mess when things go sideways.
  2. My dissent: bet on the industry’s direction. Kubernetes, backed by Google, was clearly where the industry was going, and that is what it turned out to be. Going with the obvious direction versus PCF was a no-brainer to me then and still is. I’ll concede one thing the record shows: PCF then was its own runtime, not Kubernetes underneath, and Kubernetes’ own installer was still labeled not-for-production a year on. The direction was right. The room didn’t buy it.
  3. Their motive, granted. What they really wanted was to keep everything within the same ecosystem as their Spring Boot stack. Fine, I get it.
  4. Build the on-ramp anyway. Once the decision went against me, my part was taking existing software and figuring out how to bundle it to run inside PCF, then upgrading the Jenkins pipeline to deploy there and building the ecosystem around it.

The comparison the years produced is short enough to read as a ledger.

The pitch What the ground saw
Kubernetes needs specialists; a vendor stands PCF up for us We ended up with our own specialist anyway
Call the vendor and they’ll fix it The vendor carried upgrades and patches. When it broke in our environment, the vendor didn’t fix it; our specialist did
Keep everything in the Spring Boot ecosystem Granted

Not again: don’t let the pitch that convinces leadership stand in for the plan for when it breaks.

Recovery / operate path

The vendor did carry the platform’s own lifecycle — upgrades, keeping it current, patches — so there was no internal team for that, and that half of the pitch held. The other half didn’t. When PCF broke in our environment, the vendor didn’t actually fix it. We ended up having our own specialist at the end of the day, which is the specialist the Kubernetes objection was supposed to save us.

The platform was decided within my first year there. It ran until Cigna bought the company, and kept going for a couple of years afterward. The takeover by OpenShift and EKS has been in flight for a few years now. I’m keeping those spans vague on purpose.

No cost figure for the PCF years exists on this page. I can’t say who ran the foundation day to day beyond “our own specialist,” and I’m not publishing a count of the applications that lived on it.

What changed after

The acquisition changed the mantra. Cigna’s mindset was that vendors are great, but teams need to understand their stacks end to end, and that is the doctrine the estate runs on now. PCF is completely retired. What couldn’t move to AWS landed on OpenShift; what could landed on EKS or went cloud-native. Both are Kubernetes.

I’d make the same call again on the direction. I built the on-ramp for the one that won, and it’s the past at this point.

Anonymization notes

The client ships by name; the people do not. The people who decided PCF are described only as long-tenured staff; no one is named, and nothing is said about where anyone went afterward. The timeline is deliberately vague: “the first year,” “past the acquisition,” “a few years” — no calendar years, by my choice. Product names stay: Pivotal Cloud Foundry, Kubernetes, OpenShift, Amazon EKS, Jenkins.

Who this is for

  • A platform team about to lose a vendor-versus-open-standard argument to the room upstairs.
  • Leadership scoring a platform pitch by whether it needs specialists, before asking who gets paged when the vendor doesn’t fix it.
  • Anyone who argued for the industry’s direction, lost, and now has to build the on-ramp for what won.
  • A team whose vendor platform will outlive the company that chose it, right up to the next acquisition.

Related systems

More systems

Start

Tell me what’s stuck

I’ll tell you in about a day whether I’m the right person. The first conversation is fit, not a free architecture review.