cms.teleglobals.com

AWS Cloud Migration: From Contabo Cloud to a Secure AWS Environment for a Digital Publishing Platform 

Executive Summary 

Teleglobal migrated a digital publishing platform from Contabo Cloud to Amazon Web Services. The client needed better security, scalability, and visibility than Contabo could provide. Teleglobal, an AWS Advanced Consulting Partner, designed a secure cloud architecture for the Mumbai region and ran the migration across Development and Production environments. All data was encrypted at rest and in transit, IAM access followed least-privilege principles, and CloudWatch monitoring was active across all services post go-live. 

Contabo Cloud to AWS Cloud Migration

About the Client

The client is a digital publishing company in India running a content platform for a growing audience. Their infrastructure was hosted on Contabo Cloud, which had worked during the early stages but was not built for the security, scalability, and monitoring the platform now required. There was no formal encryption, no centralised access control, and no structured monitoring. The decision to migrate to AWS was driven by the need for a cloud provider that could support the next stage of the business. 

Why the Platform Needed to Move from Contabo Cloud to AWS

Contabo Cloud had served the company during its early growth, but as the platform scaled, four problems made migration to AWS necessary. 

  1. Limited security controls – No encryption for data at rest or in transit, no centralised identity management, and no web application firewall. The platform was exposed to risks that would grow with scale. 
  1. No structured monitoring – Without logging, alerting, or dashboards, the team had no visibility into infrastructure health, application performance, or security events. 
  1. Scalability constraints – Contabo could not scale compute resources on demand. Handling traffic spikes required manual planning, and the platform had limited room to grow. 
  1. Informal credential management – Application secrets, API keys, and credentials were stored without a structured system, creating a security and compliance risk. 

The client needed a cloud migration partner that could handle the move from Contabo to AWS without disrupting the live platform.

Challenges on Contabo cloud and AWS Solutions

How Teleglobal Ran the AWS Cloud Migration

Teleglobal designed and ran a phased cloud migration from Contabo Cloud to AWS Asia Pacific (Mumbai). The engagement covered architecture design, AWS environment setup, application deployment, security hardening, and go-live across Development and Production environments. 

I. Assessment and AWS Architecture Design

The engagement started by mapping the existing Contabo environment: application modules, server details, storage needs, and access requirements. A target AWS architecture was designed covering VPC networking, EC2 compute, S3 storage, load balancing, WAF, and security services. The migration plan, cost estimate, and rollback approach were agreed with the client before work began. 

II. AWS VPC and Infrastructure Setup

A custom VPC was set up in the Mumbai region with public and private subnets, Internet Gateway, NAT Gateway, and route tables. Security Groups and Network ACLs were configured using least-privilege rules. AWS IAM was set up with users, groups, roles, and policies mapped to each team’s needs. OpenVPN was configured so the team could access private resources without exposing workloads to the public internet. 

III. EC2 Migration, Storage, and Application Deployment 

Application workloads were moved from Contabo Cloud to EC2 instances in private subnets, each configured with security groups and IAM roles. Production and staging instances were separated within the private subnet structure. An Application Load Balancer was deployed in the public subnet to distribute traffic. AWS WAF was connected to the ALB to protect against web attacks. Three S3 buckets were set up for application data, backups, and logs, all encrypted using AWS KMS. 

IV. AWS Security Architecture and Key Management 

AWS KMS was set up for centralised encryption key management across S3 and other resources. AWS Secrets Manager replaced informal credential storage, keeping application secrets, API keys, and configuration values secure. MFA was enforced for all IAM users, and role-based access was applied across EC2 and S3 to restrict access to only the people and systems that needed it. 

V. CloudWatch Monitoring, Validation, and Go-Live 

Amazon CloudWatch was set up with logs, metrics, alarms, and dashboards for EC2, ALB, WAF, and networking components. Security validation covered IAM, Security Groups, NACLs, and WAF rules. Testing was done with the client before go-live. DNS cutover and the final production switch were completed, and full infrastructure documentation was handed over. 

AWS Services Used in This Cloud Migration 

AWS Service Role in This Migration 
Amazon VPC Isolated network with public and private subnets 
Amazon EC2 Compute for production and staging application modules 
Application Load Balancer Traffic distribution across EC2 instances 
AWS WAF Web application firewall at the ALB layer 
NAT Gateway Controlled internet access for private subnet resources 
OpenVPN Secure admin and developer access without public exposure 
Amazon S3 (3 Buckets) Application data, backups, and logs 
AWS KMS Centralised encryption key management 
AWS Secrets Manager Secure storage of credentials and application secrets 
AWS IAM Identity and access with least-privilege policies 
Amazon CloudWatch Monitoring, logging, alarms, and dashboards 

AWS Services

Business Impact of the AWS Cloud Migration

  • Both Development and Production environments were migrated and validated, with all data encrypted at rest and in transit. 
  • CloudWatch dashboards and alerts were set up across all services, giving the team full infrastructure visibility with performance monitoring in place. 
  • All credentials were moved from informal storage to AWS Secrets Manager, with IAM roles and least-privilege policies applied across all services. 
  • The platform can now scale compute on demand, removing the main constraint that Contabo Cloud had placed on growth. 
  • Security improved across the board: encryption enforced, IAM tightened, audit logs active, and WAF protecting the application layer. 
Business Impact of the AWS Cloud Migration

Bottom Line

This AWS cloud migration case study documents how a digital publishing platform moved from Contabo Cloud to a production-grade AWS environment through a structured, phased migration. Every step was validated with the client before go-live, and the platform stayed up throughout the process. 

The new environment is secure, monitored, and built to scale with the business. As an AWS Advanced Consulting Partner, Teleglobal handles every cloud migration from the initial scoping call through to final documentation and handover.  


Frequently Asked Questions

1. What is a cloud-to-cloud migration? 

A cloud-to-cloud migration moves workloads from one cloud provider to another, such as Contabo to AWS. It involves re-architecting the infrastructure on the target platform, migrating data and applications, and configuring security, networking, and monitoring to match the new provider’s best practices. 

2. Why would a company migrate from Contabo Cloud to AWS? 

Companies typically move from Contabo to AWS to gain access to better security controls, centralised identity management, encryption services, scalable compute, and monitoring tools like CloudWatch. AWS also offers a much broader service catalogue and a larger certified partner network for ongoing support. 

3. How long does a cloud-to-cloud migration to AWS take? 

The duration depends on the number of workloads, application complexity, and security requirements. A focused migration for a small to mid-sized platform typically completes within a few weeks when planned and phased properly. 

4. What AWS services are most important in a cloud migration? 

The core services for most AWS cloud migrations include Amazon VPC for networking, EC2 for compute, S3 for storage, IAM for access control, KMS for encryption, and CloudWatch for monitoring. Additional services like ALB, WAF, and Secrets Manager are added based on security and performance needs. 

5. Do I need an AWS partner to run a cloud migration? 

While it is possible to run a migration internally, working with a certified AWS partner like Teleglobal reduces risk. An AWS Advanced Consulting Partner brings structured migration methodology, security expertise, and post-migration support that internal teams often lack. 

6. What is the difference between on-premises to AWS and cloud-to-cloud migration? 

On-premises to AWS migration moves workloads from physical hardware to the cloud. Cloud-to-cloud migration moves workloads from one cloud provider to another. Both follow a similar phased approach, but cloud-to-cloud migrations often move faster because the workloads are already virtualised.