Case Study: Satellite Provider

How Expert Thinking helped one of the world’s leading satellite operators make their development process more transparent, robust and efficient.

Requirements

Aerospace is an industry with high demands and the design, build and operation of satellites is one of its most complex challenges. The sector is increasingly competitive, with ever-increasing customer expectations across shipping, agriculture, aviation and government. A competitive edge requires operators to design, build, and deploy ever more effective software to deliver more specialised, reliable, and economical services.

The value of satellites is ultimately realised on the ground, through the software platforms that process their data. To achieve this, the development process must balance integrity, security and speed, enabled by the right internal developer platform (IDP). While new features and speed of deployment are key, the consequences of downtime or security breaches could be severe, with data that is influencing real-world decisions on issues including the climate crisis and national security.

One of the key players in this sector engaged Expert Thinking to create a new Internal Developer Platform on AWS to help maintain its leading position in the industry and prepare it for the next stage of growth.

The company’s requirements were:

Observability

On a platform supporting multiple critical applications, strong observability was essential to detect issues early, understand system behaviour and support rapid resolution of incidents.

Cost visibility

With a significant investment in software development and improvement, it was key that the budgets were used efficiently and that potential savings could be identified easily.

Efficiency and quality of life

Inconsistencies across environments had resulted in inefficiencies that were frustrating for both developers and infrastructure teams, causing unnecessary stress and additional tasks.

NIST 800-171 compliance

With numerous engagements with US and other government customers, the company relied on its compliance with the NIST 800-171 standard, and the developer platform had to eliminate any risks to that status.

Export controls

With the sensitivity of much of the customer’s work, it was important that data could be restricted to the appropriate region and user set. 

Streamlining

To increase business agility and rapidly accommodate new customers in new regions, often with complex security requirements, the development platform needed to be portable, customisable, and scalable.

The Criteria

The key success factors for the project were:

  • Speed of deployment
    In a fast-moving sector, there was no time for a lengthy project, and it was vital that the new platform could be operational quickly, without disruption to the development team’s work.
  • Fitness for purpose
    In a highly specialised industry, it was important that the new platform could be developed in sympathy with the customer’s unique needs, to ensure the team’s specific requirements were met.
  • Economy
    While a very high quality of work was required, the budget for this project was tight, with no scope for waste or overrun.
gender equality

Our Solution

Expert Thinking designed, built and deployed an IDP platform as a managed PaaS on AWS expanding on their existing AWS Organisation. The new platform was built with Amazon Elastic Kubernetes Service (EKS) as the core application runtime, providing a consistent and secure execution environment for workloads.
Satellite provider case study

Figure 1OU Heirachy allows SCPs to be applied to appropriate accounts. AWS Config compliance pack helps detect non-compliant infrastructure.

Security and compliance alignment were embedded into the platform design. Fine grained Amazon Identity and Access Management (IAM) roles, Kubernetes service accounts and least privilege policies control access at every layer, while AWS Organizations Service Control Policies (SCPs) enforce organisation-wide guardrails to prevent non-compliant actions.
Satellite provider case study

Figure 2 – Shared public subnet means all ingress/egress is enough AWS Network Firewall. SCP prevents NAT Gateway creation in spoke accounts.

AWS Network Firewall supported NIST 800-171 compliance, by providing enforceable network controls and detailed visibility into network activity. AWS Network Firewall enables centrally managed, stateful inspection and filtering of traffic, enforcing approved communications paths and blocking unauthorised or potentially malicious traffic. Firewall logs and Amazon Virtual Private Cloud (VPC) flow logs help ensure that evidence of data flows is stored, helping meet NIST audit requirements.

Satellite provider case study

Figure 3 Logs metrics, traces and cost data made available in centralised location with fine grained access control achieved using Self Hosted Grafana Enterprise.

Observability is a core capability of the platform. Logs, metrics and traces are collected across the stack, from applications, infrastructure and traffic. Logs are consolidated using Amazon OpenSearch Service, whilst Mimir and Tempo store metrics and traces, all of which can be visualised and alerted on from Grafana, aiding both operations and compliance requirements.

By building such controls into the platform itself, compliance becomes a default property of every deployed application, rather than a manual per-project effort.

In addition to compliance, the new IDP was built so that even major new business requirements can be affected quickly, with changes that previously would have taken months now achievable in days thanks to configurable Terraform modules. This includes onboarding customers in new regions or updating customer workflows, with the new system designed to make it easy to ensure isolation between customer workloads – a vital attribute for customers in the government and security sectors.

The Benefits

  • Key Benefit 1: Visibility and observability
    The new IDP’s observability stack draws together logs, traces and metrics from all the various testing, staging and production environments and consolidates them to provide ‘single pane of glass’ visibility of the whole operation. This enables engineering teams to quickly detect anomalies, assess impact and respond to incidents in a controlled and reliable manner.
  • Key Benefit 2: Compliance and security
    The new IDP enforces compliance with the vital NIST 800-171 standard, ensuring the company’s place as one of the first choices for government, defence and security contracts, in the US and elsewhere. Having this compliance built into the platform reduces the operational burden on both development and infrastructure teams by providing predefined security guardrails that ensure workloads are designed, deployed and operated in line with NIST 800—171 by default.
  • Key Benefit 3: Streamlining and efficiency
    Well defined reusable Terraform modules, along with CICD templates mean that developers working on the new IDP can push code from their local machines to testing, to staging, and then to production, with a single, secure and integrated process. This means development velocity is increased, and timelines are far more predictable. Developers have access to a registry of pre-approved and pre-tested modules within the platform, allowing them to quickly access and use proven code, propagating best practices and raising quality incrementally across the team.

Talk to the
cloud experts.

Whether you are considering using cloud for the first time or have already embraced it, you need to work with a specialist – contact us today.