Omegajam Migration and Modernization from Google Cloud Platform to Amazon Web Services
Executive Summary
About the Customer
About OmegaJam
Omegajam provides online gaming and contest experiences through a platform powered by web applications, APIs, and supporting services. Their goal is to deliver engaging, reliable, and scalable digital gaming experiences while supporting real-time user interactions and contest operations. The platform leverages modern cloud technologies to ensure high availability, performance, and operational efficiency as the business continues to grow.
Customer Challenge
Production workloads –
Production workloads, databases, and supporting services were operating within a single cloud environment, limiting governance, environment separation, and operational flexibility.
Containerized applications –
Containerized applications hosted on GCP Cloud Run lacked a standardized AWS-based operating model, creating challenges for future scalability, monitoring, and centralized management.
Limited visibility into security –
Limited visibility into security, compliance, and operational health across workloads, increasing the risk of misconfigurations and delayed issue detection
Challenges –
If left unaddressed, these challenges would have impacted Omegajam’s ability to scale efficiently, strengthen security and governance controls, optimize cloud costs, and establish a modern cloud platform capable of supporting future business growth.
Why Amazon
Web Services
Why OmegaJam
Chose GoCloud
As an AWS Advanced Consulting Partner, GoCloud demonstrated expertise in cloud migration and application modernization aligned with AWS best practices and the AWS Well-Architected Framework. Omegajam selected GoCloud for its proven ability to assess existing cloud environments, design secure multi-account AWS architectures, and execute large-scale workload migrations with minimal disruption. GoCloud provided guidance on migration strategy, landing zone design, security, governance, and workload modernization, ensuring a structured transition from GCP to AWS while reducing operational risk and supporting future growth objectives.
GoCloud’s Solution
Services Used
AWS Control Tower →
Centralized governance and multi-account setup with guardrails for compliance.
AWS CloudFormation →
Automated provisioning and management of the infrastructure, ensuring consistency, repeatability, and scalability.
Amazon VPC (isolated per environment) →
Strong network isolation for dev, staging, and production.
AWS CodePipeline →
Automated CI/CD pipeline ensuring faster and reliable deployments.
AWS Security Hub →
Unified view of security posture with automated compliance checks.
Elastic Load Balancer (ALB) →
Efficient traffic distribution with SSL termination and health checks.
Auto Scaling →
Automatic scaling of workloads based on demand, optimizing performance and cost.
Amazon ECR →
Centralized container image repository replacing GCP Artifact Registry for secure image storage and management.
AWS Amplify →
Fully managed frontend hosting with integrated CI/CD, HTTPS, and content delivery capabilities.
Amazon RDS (MySQL Multi-AZ) →
High availability, automated failover, and scalability for critical databases.
AWS ALB (Application Load Balancer) →
Efficient traffic distribution with SSL termination and health checks.
AWS WAF →
Protection against common web threats including SQL injection and cross-site scripting attacks.
Amazon ElastiCache for Redis →
Low-latency caching layer supporting contest data, user queues, and application performance optimization.
Amazon ECS with AWS Fargate →
Serverless container platform hosting Omegajam microservices, reducing operational overhead and improving scalability.
AWS KMS →
AWS KMS → Centralized encryption key management protecting databases, caches, and application secrets.
Cloudwatch →
Real-time monitoring, alerting, and centralized logging for system health visibility.
AWS IAM Access Analyzer →
Continuously analyzes IAM policies and resource permissions to identify unintended public or cross-account access, improving security and policy governance.
Amazon Inspector →
Automatically scans Amazon EC2 instances and Amazon ECR images to detect software vulnerabilities and configuration issues for improved workload security.
Architecture Diagram
Workflow
For Omegajam, a multi-account AWS environment was designed using AWS Control
Tower to provide governance, security, and workload isolation throughout the migration
from GCP to AWS. Separate accounts were established for Non-Production, Production,
Security, and Shared Services workloads, ensuring controlled access, operational
separation, and compliance with AWS best practices. Each workload environment is
deployed within dedicated Amazon VPCs spanning multiple Availability Zones (AZs) to
provide fault tolerance, high availability, and secure network segmentation.
For Omegajam, a multi-account setup was created by using AWS Control Tower,
details of which are as follows:
• 2 Organizational Units (OUs) – Security OU and Workloads OU
• 4 Core Accounts – Management Account, Security Account, Shared Services Account, and Production/Non-Production Workload Accounts.
• AWS IAM Identity Center (SSO) for centralized identity management and rolebased access across all AWS accounts.
• Centralized governance through AWS Organizations, Service Control Policies (SCPs), AWS Config, and AWS CloudTrail.
Core OU Contains Audit and Log Archive accounts. The Audit account consolidates security findings, while Log Archive aggregates CloudTrail and Config logs from all accounts.
Security OU: Contains the Security Account, which centralizes AWS Security Hub, GuardDuty, AWS Config, CloudTrail logging, compliance monitoring, and audit activities across the AWS environment.
Workloads OU: Hosts Non-Production and Production accounts, providing workload isolation and environment-specific controls for migrated applications and services.
Management Account: Serves as the AWS Organizations management account, responsible for account governance, consolidated billing, and overall AWS environment administration.
Shared Services Account: Hosts common services including CI/CD tooling, Amazon ECR repositories, monitoring, and operational services shared across workload accounts.
Guardrails and Policies:
• Service Control Policies (SCPs) enforce governance controls and restrict unauthorized or non-compliant configurations.
• AWS Config continuously monitors resource configurations and evaluates compliance against defined policies and standards.
• AWS CloudTrail provides centralized audit logging across all AWS accounts for governance, security, and operational visibility.
• AWS IAM Identity Center (SSO) provides centralized authentication and leastprivilege access to AWS resources across all accounts.
Workloads & Applications:
• Non-Production: Application workloads are deployed on Amazon ECS with AWS Fargate for testing, validation, and migration readiness activities.
• Production: Amazon ECS with AWS Fargate hosts the Games API, RNG API, Web API, and Onboarding Services across multiple Availability Zones for high availability and scalability.
• Frontend Applications: eb applications are hosted using AWS Amplify, providing managed hosting, HTTPS, and integrated deployment capabilities
• Database Layer: Amazon RDS for MySQL (Multi-AZ) serves as the primary database platform, providing automated backups, failover protection, and high availability.
• Caching Layer: Amazon ElastiCache for Redis supports low-latency access to contest data, user queues, and application caching requirements.
Monitoring & Security:
● CloudTrail and AWS Config enabled in all regions with logs centralized in the Log Archive account.
● Amazon CloudWatch provides application and infrastructure monitoring with alarms and dashboards.
● AWS GuardDuty and Security Hub aggregate security findings across accounts into the Audit account for centralized threat detection.
● Role-based access controls ensure developers work in Dev, QA/operations in Stage, and only authorized personnel access Prod.
GoCloud delivers ongoing Managed Services through a structured operating model aligned with AWS best practices. This includes 24/7 monitoring and alerting, incident management with defined SLAs, proactive patch and vulnerability management, backup monitoring and recovery testing, cost optimization reviews, and controlled change management processes. Monthly service review meetings provide performance reporting, security posture updates, compliance status, and optimization recommendations, ensuring continuous improvement and operational excellence.
Results, Operational Improvements, and Business Impact
• Established a secure and scalable AWS landing zone supporting production and nonproduction workloads.
• Modernized application hosting by migrating containerized workloads from GCP Cloud Run to Amazon ECS with AWS Fargate.
● Improved availability, resilience, and operational efficiency through Multi-AZ deployments, managed database services, and deployment automation.
● Enhanced security, governance, and visibility while creating a foundation for future growth and cloud optimization.