Success Story

Over 3 years as Heru's DevOps team: from Porter to a self-owned AWS/EKS platform with GitOps and EKS always supported (1.22 → 1.29)

Heru is a Mexican tax-tech fintech: it automates compliance with Mexico's SAT to make tax life easier for thousands of taxpayers and companies. For more than three years (Oct 2021 – May 2025) Craftech acted as its extended DevOps team on AWS, taking the platform from a limited Porter-based architecture to a self-owned EKS infrastructure with IaC, GitOps, autoscaling and CI/CD.

EKS 1.22 → 1.29, never out of support Fintech / Tax technology (tax-tech) Oct 2021 – May 2025 (~3.5 years, continuous DevOps Team, Squad 2)
ModernizacionFinOps

Challenge

Deployments were not automated and any change took a long time. The architecture ran on Porter, a limited service that did not follow best practices, and secrets were handled inside the charts with no versioning. The customer's own API Gateway did not scale. There was no environment/account separation, no infrastructure versioning and no cost control.

Solution

Craftech acted as Heru's extended DevOps team: it migrated Porter to a self-owned multi-account EKS architecture (dev/mgt/prod) with VPN and Terraform IaC, implemented GitOps with ArgoCD and autoscaling with Karpenter, and optimized CI/CD with integrated tests and self-hosted runners. It migrated the customer's own API Gateway to AWS API Gateway, centralized secrets in Vault and set up observability with OpenTelemetry and a service mesh. On the database side it migrated to Aurora, upgraded PostgreSQL and hardened RDS, IAM and SSO. It added cost reduction with nightly shutdown of non-production environments and kept the cluster always current with sustained EKS upgrades (1.22 → 1.29). When Heru decided to move its stack to GCP, Craftech executed an orderly wind-down, decommissioning all AWS infrastructure.

Results

Deployments went from a slow, manual process to a CI/CD pipeline with tests that cut the time and risk of every change. The platform was modernized and standardized: a self-owned multi-account EKS architecture, Terraform-versioned infrastructure and centralized secrets. The cluster stayed on a supported Kubernetes version (1.22 → 1.29) for more than three years. Resource optimization, nightly shutdown of non-production environments and self-hosted runners drove sustained cost savings. The relationship spanned ~3.5 years with high customer satisfaction and ended in an orderly fashion when the customer chose to migrate to GCP.

Stack & technologies

Amazon EKSKarpenterArgo CDTerraformAWS API GatewayVaultAmazon AuroraAmazon RDSOpenTelemetryIstioCI/CD

Facing a similar challenge?

Get a free AWS cost & architecture assessment.

The future of your company
takes off with Craftech

Leverage our AWS expertise to propel your company into the cloud.

Get your free assessment