Simplileap logo

// Case study

Moving production EC2 from public subnet to private NAT, zero downtime

An insurtech API shed its public instance IP using ALB fronting, NAT Gateway egress, and a staged ENI cutover with no customer-facing outage.

InsurtechCloud security migration5 weeksBangalore delivery

A digital insurtech policy API on a single public-subnet EC2 with SSH open to the world and direct application port exposure. A security audit mandated private subnet placement behind ALB within 30 days without scheduled downtime.

Zero

Customer-facing 5xx

During migration window

Eliminated

Public instance IPs

Attack surface reduced

10%

Traffic validation ramp

ALB weighted forward to private targets

Passed

Compliance scan

Next quarterly review

Delivered by Deepak Pathak · Published March 20, 2025 · 10 min read

Client context

An insurtech policy API ran on a single t3.large EC2 in a public subnet, SSH open to 0.0.0.0/0, application port exposed directly, RDS reachable only via security group referencing that instance's elastic IP. Security audit mandated private subnet placement behind ALB within 30 days, without scheduled downtime.

Delivery notes

Target: EC2 in private subnet across two AZs; NAT Gateway for outbound webhooks and third-party APIs; ALB terminates TLS; Session Manager replaces SSH; RDS security group allows only app SG.

Rollback plan: keep public instance stopped but not terminated for 72 hours; Terraform state pinned; runbook tested in game-day drill.

The challenge

Problems: hardcoded public IP in a partner allowlist, required coordinated whitelist update; Let's Encrypt HTTP-01 challenge broke when we removed direct 443 to instance, moved to DNS-01 via Route 53; background workers called external KYC API with IP-based rate limits, NAT Gateway elastic IP pre-registered with vendor.

Our approach

Cutover technique: launch parallel instances in private subnet registered to new target group; ALB weighted forward 10% traffic; validate webhooks and cron via SSM port-forward logs; drain public instance connections over 300s; de-register public target; update Route 53 alias to ALB only.

Results & impact

Outcome: zero customer-facing 5xx during migration window; attack surface reduced, no public instance IPs; compliance scan passed next quarterly review. Engagement referenced as digital insurtech API, name withheld.

← Back to case studies

// Verified entity

Simplileap Digital LLP

// Recognition

Featured in QuickNode Feature Fridays

CIN

AAU-8582

Startup India

DIPP83124

Founded

November 2020

Office

Residency Rd, Bengaluru, India

Ready to scope your next initiative?

Share your goals with our Bangalore team. We respond within one business day with a clear path from discovery to delivery.