Cloud Transformation at Allianz: Building an Internal Cloud Platform (FCP)
Role: Technical Product Owner Lead · 2022–2023
Cloud infrastructure was fractured across 70+ countries. A self-service platform replaced 18-month provisioning with days.

- Migration, zero downtime
- 4 months
- Provisioning, was 12–18 months
- Days
- Global operations
- 70+ countries
The shift
- Migration time
- Developer access
Team
- Team
- Tungi Dang
- Technical Product Owner Lead
The ticket everyone had stopped questioning
A senior engineer needs a test environment before a Friday release. She files the ticket already knowing what comes back: six to eight weeks, if the approvals go smoothly. At its worst, standing up new infrastructure at Allianz took 12 to 18 months — manual sign-offs, bespoke networking per entity, and a queue that no single team owned.
The waiting was only half the damage. Engineers who wait build workarounds: local setups that don't match production, shared servers nobody administers, deployments that route around the approval process entirely. For one of the world's largest insurers, handling regulated financial data in every jurisdiction it operates in, that shadow estate was the real liability. It just didn't show up on any dashboard.
The call: the wait itself was the product problem
I joined as technical product owner for the Future Cloud Platform (FCP), and the decision that shaped everything else was what to measure. Not migration milestones, not cluster counts — the time between an engineer asking for an environment and deploying their first code into it. That framing forces trade-offs you otherwise avoid: golden paths instead of bespoke setups, which meant telling country entities that their custom configurations were going away. Some of those conversations were long. The platform's bet was that a compliant default which takes days beats a tailored setup that takes a year, and engineers would vote with their workloads.
A private cloud inside the public cloud
FCP put a policy-controlled boundary around all Allianz workloads: public-cloud flexibility, private-grade compliance. Multiple cloud vendors, fit-for-purpose per entity, under one security baseline. Data sovereignty as configuration, not exception handling — Australian customer data stays in Australia. Underneath, platform engineering ran on Kubernetes, Helm, and Argo. My layer was the one above the plumbing: the contracts, defaults, and paved roads that decide whether engineers adopt a platform or quietly route around it.
Compliance as co-builder, not final boss
The failure mode I most wanted to avoid was the standard one: architecture settles for months, then Security and Compliance review it at the end and find structural problems. So IT, Security, and Compliance sat inside platform governance from the start, and their requirements became pipeline checks — automated auditing, GDPR-compliant data handling, region-specific hosting — instead of a review gate before launch. The compliant path became the fast path, which is the only condition under which busy engineers choose it.
What it took, and what came out
The migration ran on-premise and cloud in parallel throughout, so mission-critical systems never went dark. Work that had previously taken 12 to 18 months completed in four, with zero downtime.
- Standard environment provisioning went from months to days, through self-service templates and Infrastructure-as-Code.
- Operations standardised across multiple providers and 70+ countries.
- Hundreds of teams inherited best practices as defaults — CI/CD, observability, golden paths — rather than as a wiki page.
- The platform now carries Allianz's enterprise AI workloads, including the Enterprise Knowledge Assistant processing 90,000+ paragraphs for customer service.
The platform self-service and paved-road patterns I used here inform The AI-native Platform Playbook.
4 months migration, zero downtime. Days provisioning, was 12–18 months. 70+ countries global operations.
