Rabobank’s Kubernetes Scale: Three Landing Zones, One Standard
Rabobank serves close to 9 million customers and finances farmers globally. That scale is reflected in its Kubernetes footprint: 147 AKS clusters and 473 Azure Container Apps on Azure, just over 40 EKS clusters on AWS, and roughly 12 OpenShift clusters on-premises. Historically, teams created and operated their own clusters independently. As the platform offering matured, architecture mandated tighter control over cluster creation. The container platform team, Qup, now manages all three landing zones and standardizes the experience across them.
Why Banking Regulations Forced Security-First Defaults
Rabobank operates under Dutch National Bank and European Central Bank requirements. Missing a control risks regulatory fines and loss of the banking license. Security cannot simply be claimed: internal and external auditors demand evidence. Every deployment passes security, compliance, and operational checks. Risk owners must be assigned to any deviation, and deviations must go through formal risk acceptance. MFA, encryption, threat detection, and network segmentation are all verified. That is why the team cannot ship directly to production without a documented approval trail.
Cluster-as-a-Service: Choosing Isolation Over Cost Efficiency
The team evaluated namespace-as-a-service first. Shared clusters reduce idle compute and lower cost, but they could not satisfy Rabobank’s firewall rules enforced at the node and network level. Tenant B must be provably unable to reach Tenant A’s APIs or private endpoints. The solution was cluster-as-a-service: each tenant receives a dedicated cluster in its own virtual network on Azure, or its own AWS account on EKS. AWS account-level isolation removes the need for complex IAM or resource-based policies on every resource a tenant creates.
Pipeline Security and the ArgoCD Compliance Bridge
Every pipeline runs three tasks: code quality scanning with Kubescape, vulnerability scanning with Checkmarx, and secret detection. Renovate tracks dependencies and base images, generating 20-plus updates on first run and 5-10 weekly thereafter. One team member rotates weekly responsibility for reviewing those updates, prioritizing any that fix a vulnerability. ArgoCD was newer to the bank. Compliance rules required every production change to have a registered IT change task beforehand. The team built a lightweight pipeline that creates the change task, cuts a new git tag, and lets ArgoCD watch the tag rather than the main branch.
Kyverno Policies: Guardrails That Start Conversations
Kyverno defines what tenants may and may not do inside their cluster. Outside those boundaries, tenants get near-admin access. Policy violations surface through the internal developer portal, Nexa (built on Backstage), as a dashboard that also reaches the tenant’s business stakeholders. One concrete example: pulling images from Docker Hub is blocked. Tenants must use curated registries approved by the bank. The team treats each policy dispute as an opportunity to understand what applications actually need, then adjusts the platform offering while keeping security standards in place.
Provisioning Time Cut from 54 Days to 4 Hours
Before Qup existed, a squad provisioning its own Kubernetes cluster spent roughly 54 working days on setup. The managed platform brings that to four hours: submit a request through Nexa, get it approved, run a Terraform-backed pipeline that takes about an hour, and receive a cluster registered in the IT service management tool with access already configured. The demo showed a tenant filling in application name, squad, environment, and AD group, then watching ArgoCD pick up the new cluster automatically. The prior approach was expensive and often insecure because teams lacked full awareness of the bank’s security standards.
Notable Quotes
if we miss a control uh we could have huge regulatory fines and even losing our uh banking license. Beatrice Forslund · ▶ 04:00
we’ve really saved a lot of hours in uh delivering a production ready cluster from day one to our tenants. As you can see, it is uh reduced from uh 54 days in the past like close to half a year of work uh like a five day work week to uh half a day or four hours only Koshin Verberne · ▶ 20:58
constraints and restrictions of your platform help you to create the right dialogue and the right conversations with your tenants to further learn and understand what the needs of your tenants are Koshin Verberne · ▶ 25:08
Key Takeaways
- Cluster-as-a-service with VNet or AWS account isolation satisfies bank-grade network separation without complex IAM policies.
- Provisioning time dropped from 54 days to 4 hours after the platform team automated Terraform, approvals, and ITSM registration.
- A lightweight pipeline bridging ArgoCD to an IT change management tool keeps GitOps intact while meeting compliance audit requirements.
About the Speaker(s)
Beatrice Forslund is a DevOps Engineer at Rabobank. She began her career as an OpenShift developer before joining the dedicated AKS platform team, where she has worked for over a year. She is also a Kubestronaut, and this talk was her first at KubeCon.
Koshin Verberne is a DevOps Engineer at Rabobank with six years of cloud engineering experience, primarily on AWS. He joined the container platform team in mid-2025, bringing a background in networking and cloud governance to the Kubernetes platform build-out.