AWS Cloud Migration Architect / Kubernetes Consultant
Worldwide
AWS Cloud Migration Architect / Kubernetes Consultant Project Overview We are seeking a senior AWS Cloud Migration Architect and Kubernetes Consultant to assess our current dedicated-server infrastructure and lead the design and migration of our platform to AWS. Our current environment includes Kubernetes-based workloads and supporting databases, messaging, API management, identity, security, secrets management, caching, and observability components. The selected consultant will evaluate the current environment, design the target AWS architecture, determine which components should remain self-managed versus move to AWS-managed services, and develop and execute a phased migration plan. This is expected to be an initial 10–12 week consulting engagement, with the possibility of ongoing cloud operations, security, optimization, and architecture support. Engagement Structure The engagement will begin with a paid discovery and architecture phase. The remaining implementation and migration phases will proceed following review and approval of the proposed architecture, migration roadmap, timeline, and cost estimate. The consultant should be prepared to challenge existing assumptions and recommend the best long-term architecture rather than simply migrating the existing environment to AWS without modernization. The estimated timeline below is preliminary and may be adjusted based on the findings of the discovery phase. Phase 1 — Discovery and Assessment Estimated duration: 2 weeks Assess the current dedicated-server and Kubernetes environment. Inventory applications, services, databases, integrations, storage, networking, and dependencies. Review current security, backup, monitoring, deployment, and operational practices. Identify technical risks, migration constraints, and application dependencies. Develop current-state architecture documentation. Recommend the appropriate AWS services and target architecture. Compare AWS-managed services against self-managed deployment options. Prepare a preliminary AWS monthly cost estimate. Produce a phased migration roadmap, risk register, and implementation estimate. Phase 2 — AWS Foundation and Landing Zone Estimated duration: 2–3 weeks Design and implement the AWS account and environment structure. Configure networking, VPCs, subnets, routing, private connectivity, and security boundaries. Establish IAM, role-based access, identity federation, and least-privilege controls. Implement Amazon EKS and supporting Kubernetes services. Establish infrastructure as code using Terraform, CloudFormation, or AWS CDK. Configure container registries, image scanning, secrets management, logging, monitoring, and backup. Establish development, testing, staging, and production environments as appropriate. Implement or improve CI/CD pipelines. Phase 3 — Workload and Data Migration Estimated duration: 4–5 weeks Migrate Rancher or Kubernetes workloads to Amazon EKS. Migrate or modernize databases, messaging, API management, identity, caching, and observability components. Configure storage, load balancing, DNS, networking, encryption, and security controls. Validate application integrations and external dependencies. Perform database and data migration. Conduct performance, security, resilience, and recovery testing. Develop production cutover and rollback plans. Execute the production migration with minimal downtime and data-loss risk. Phase 4 — Stabilization and Knowledge Transfer Estimated duration: 1–2 weeks Monitor and stabilize the production environment. Resolve migration-related performance and reliability issues. Optimize AWS resources and infrastructure costs. Complete architecture diagrams and technical documentation. Deliver deployment, recovery, incident-response, and operational runbooks. Conduct backup restoration and failover testing. Provide knowledge-transfer sessions to the internal technical team. Deliver final recommendations for ongoing cloud operations and improvement. Key Objectives Assess the current infrastructure, applications, dependencies, security controls, and operational requirements. Design a secure, scalable, highly available, and cost-efficient AWS architecture. Migrate existing Rancher and Kubernetes workloads to Amazon EKS. Modernize appropriate components using AWS-managed services. Minimize downtime, operational risk, and data-loss risk. Establish infrastructure automation, monitoring, security, backup, and disaster recovery. Ensure the AWS environment supports SOC 2 controls and future compliance requirements. Establish clear operational ownership, documentation, and support procedures. Responsibilities Conduct a detailed technical assessment of the current infrastructure. Document applications, services, dependencies, databases, messaging, networking, storage, and security requirements. Develop current-state and target-state architecture diagrams. Design the AWS organization, account, environment, and network structure. Design and implement AWS infrastructure, including: Amazon EKS Amazon EC2 Amazon VPC AWS IAM Elastic Load Balancing Amazon Route 53 Amazon S3 Amazon EBS and EFS Amazon ECR Amazon RDS or Aurora AWS Backup Amazon CloudWatch AWS CloudTrail AWS Config AWS Secrets Manager or an approved equivalent Migrate Kubernetes workloads from Rancher or other on-premises Kubernetes environments to Amazon EKS. Evaluate whether Rancher should remain part of the target architecture or be replaced with native AWS and Kubernetes management tools. Build reusable infrastructure using Terraform, CloudFormation, or AWS CDK. Establish separate development, testing, staging, and production environments where appropriate. Implement or improve CI/CD pipelines for applications and infrastructure. Configure container image scanning, vulnerability management, secrets handling, and deployment controls. Design secure connectivity between AWS, internal users, external systems, customer environments, and any remaining infrastructure. Evaluate, migrate, or redesign supporting platforms, including: PostgreSQL MongoDB RabbitMQ Apache Kafka Redis or Garnet OpenSearch WSO2 OpenBao Identity and access-management platforms API gateways and API-management platforms Recommend AWS-managed alternatives when they provide meaningful improvements in reliability, security, scalability, operations, or cost. Implement centralized logging, monitoring, metrics, tracing, and alerting. Define service-level objectives, alert thresholds, escalation procedures, and operational ownership. Design Multi-AZ architectures, backup policies, disaster-recovery procedures, and failover processes. Define recovery-time objectives and recovery-point objectives for critical systems. Incorporate SOC 2-aligned controls, including: Access management Logging and monitoring Change management Encryption Backup and recovery Incident response Evidence retention Vulnerability management Develop detailed AWS cost estimates before implementation. Implement tagging, budgets, alerts, rightsizing, storage lifecycle policies, and ongoing cost controls. Produce migration plans, deployment procedures, rollback plans, runbooks, security documentation, and knowledge-transfer materials. Train and support the internal technical team during and after migration. Required Experience Significant hands-on experience designing and operating production AWS environments. Strong experience with Kubernetes and Amazon EKS. Demonstrated experience migrating production workloads from dedicated servers, private data centers, Rancher, or on-premises Kubernetes environments to AWS. Strong knowledge of AWS networking, including: VPCs Public and private subnets Routing NAT gateways Security groups Network ACLs Private endpoints VPNs Load balancers Strong knowledge of AWS IAM, least-privilege access, role-based access control, service accounts, and identity federation. Experience with infrastructure as code using Terraform, CloudFormation, or AWS CDK. Experience designing CI/CD pipelines for containerized applications. Experience with Docker, container registries, image security, and Kubernetes deployment strategies. Experience operating PostgreSQL and at least one NoSQL database in production. Experience with messaging or event-streaming platforms such as RabbitMQ or Kafka. Experience with centralized logging, monitoring, metrics, tracing, and alerting. Strong understanding of encryption, secrets management, backup, disaster recovery, high availability, and business continuity. Ability to troubleshoot complex application, Kubernetes, network, database, and AWS infrastructure issues. Strong architecture, documentation, communication, and knowledge-transfer skills. Ability to clearly explain recommendations, alternatives, risks, costs, and tradeoffs to technical and executive stakeholders. Preferred Qualifications AWS Solutions Architect Professional, AWS DevOps Engineer Professional, or equivalent AWS certification. Certified Kubernetes Administrator, Certified Kubernetes Application Developer, or equivalent Kubernetes certification. Experience designing AWS environments that support SOC 2 audits. Experience with AWS Organizations, Control Tower, Security Hub, GuardDuty, Inspector, Config, CloudTrail, and centralized security logging. Experience planning and executing low-downtime or zero-downtime production migrations. Familiarity with: OpenSearch WSO2 OpenBao RabbitMQ Apache Kafka PostgreSQL MongoDB Redis Garnet Experience with AWS-managed services such as: Amazon Aurora or Amazon RDS Amazon DocumentDB Amazon MSK Amazon MQ Amazon ElastiCache Amazon OpenSearch Service Amazon Managed Service for Prometheus Amazon Managed Grafana Expected Deliverables Architecture and Planning Current-state infrastructure assessment Application and dependency inventory Security and operational gap assessment Current-state and target-state architecture diagrams AWS account and network design AWS service recommendations Managed-service versus self-managed comparison Preliminary monthly AWS cost estimate Migration risk register Migration roadmap with phases, priorities, dependencies, and timeline Detailed implementation estimate following discovery AWS Platform Implementation AWS account and environment structure VPC and network architecture IAM and access-control framework Amazon EKS implementation Infrastructure-as-code repositories CI/CD framework Logging, monitoring, and alerting Security controls and secrets management Backup and disaster-recovery configuration Development, staging, and production environments Migration and Validation Workload migration Database and data migration Integration validation Performance and load testing Security testing Backup and recovery testing Failover testing Production cutover plan Rollback plan Post-migration validation Documentation and Knowledge Transfer Final architecture diagrams Infrastructure documentation Deployment and rollback procedures Operational runbooks Incident-response procedures Backup and disaster-recovery runbooks Cost-management recommendations Knowledge-transfer sessions Recommendations for ongoing support and operational ownership Estimated Engagement Expected duration: Approximately 10–12 weeks Estimated consulting effort: Approximately 250–350 hours Engagement type: Consulting contract, with the possibility of extension Initial commitment: Paid two-week discovery and architecture phase Continuation: Remaining phases subject to approval of the architecture, migration roadmap, timeline, and implementation estimate The exact duration and level of effort may be adjusted based on the complexity, quality, and documentation of the current environment. Proposal Requirements Please include the following in your proposal: Examples of similar AWS and Amazon EKS migrations you personally led. A description of the scale and complexity of those environments. Your specific role in architecture, implementation, migration, and ongoing operations. Experience migrating Rancher-managed Kubernetes environments. Experience with PostgreSQL, MongoDB, RabbitMQ, Kafka, WSO2, OpenSearch, and secrets-management platforms. Your recommended approach for assessing and migrating our environment. Your approach to minimizing downtime, data-loss risk, and operational disruption. Your approach to SOC 2-aligned AWS architecture and operational controls. Your approach to AWS cost estimation and optimization. An example architecture diagram, migration plan, or runbook with confidential information removed. Relevant AWS and Kubernetes certifications. Your availability during the anticipated 10–12 week engagement. Your hourly rate, weekly availability, and proposed engagement structure. Any assumptions or information required to provide an accurate implementation estimate. Consultant Selection Process Shortlisted consultants may be asked to participate in a technical interview covering: A previous AWS or EKS migration they personally led. Kubernetes architecture and troubleshooting. AWS networking and IAM design. Database and data-migration strategy. Backup, disaster recovery, and failover design. SOC 2-related cloud controls. Cost estimation and optimization. Migration sequencing, validation, cutover, and rollback planning.
- More than 30 hrs/weekHourly
- 3-6 monthsDuration
- ExpertExperience Level
$35.00
-
$65.00
Hourly- Remote Job
- Ongoing projectProject Type
Skills and Expertise
Activity on this job
- Proposals:20 to 50
- Last viewed by client:6 days ago
- Interviewing:3
- Invites sent:0
- Unanswered invites:0
About the client
- United States12:37 AM
Explore similar jobs on Upwork
How it works
Create your free profileHighlight your skills and experience, show your portfolio, and set your ideal pay rate.
Work the way you wantApply for jobs, create easy-to-by projects, or access exclusive opportunities that come to you.
Get paid securelyFrom contract to payment, we help you work safely and get paid securely.
About Upwork
- 4.9/5(Average rating of clients by professionals)
- G2 2021#1 freelance platform
- 49,000+Signed contract every week
- $2.3BFreelancers earned on Upwork in 2020
Find the best freelance jobs
Growing your career is as easy as creating a free profile and finding work like this that fits your skills.
Trusted by