Christophe Boulanger
Passionate about technology and innovation, Christophe drives the evolution of Foyer Group’s IT platforms by combining automation, security, and pragmatism. Always attentive to user needs, he is committed to delivering a smooth and high-performing experience. He firmly believes that technology should be an accelerator rather than a barrier, and that behind every line of code lies an opportunity to improve everyday life.
Head of Data & Platform Engineering – Foyer Group
https://www.linkedin.com/in/christophe-boulanger-4b936183/
christophe.boulanger@foyer.lu
Sessions
API Gateway, ESB, Web Access Management and WAF - from proprietary products to Tyk, Keycloak, Traefik and CrowdSec.
Replacing a security appliance with open source is almost never a like-for-like swap. We set out to move our entire web middleware security stack - API Gateway, ESB, Web Access Management, application WAF - onto Tyk, Keycloak, Traefik and CrowdSec. The first component has been in production since 2019; other workstreams are still under way.
We will share what that journey actually cost and taught us: how to escape XSLT transformations hardcoded inside a product, by turning real traffic captures into unit tests; why moving from Web Access Management to Keycloak is a change of security model rather than a change of tool; what you learn when an open-source ingress controller stops being maintained and you have to migrate under time pressure; and why a load balancer's custom traffic rules remain the hard part, with no mechanical translation available.
We will be honest about what we are leaving behind - our WAF appliance is robust, well-tooled and trusted by auditors - and about the real trade: every workstream swapped a licence cost for code we now maintain ourselves.
This is a workshop, not a lecture. Five questions go to the room, including the ones we have not settled - particularly around PKI, as public certificate lifetimes head towards a few tens of days.
In 2020, Foyer switched off its mainframe in production. Twenty months, 12,000+ COBOL/EGL programs and batch, moved from z/OS to Linux and Java, with a three-day go-live and a single month of code freeze. That was not an open-source project, but it is where open source became a real option.
This is a consumer's story, told by two of the people who lived it. Since 2017, we have replaced proprietary layers one at a time: z/OS to Linux, IBM WebSphere to Tomcat, Tanzu to vanilla Kubernetes. Our platforms now run on Kubernetes, offering services such as MongoDB, Kafka, Elasticsearch, MinIO,... and supporting technologies like Angular, Go, Scala/Play and Java.
Our most ambitious bet yet is a fully open-source Data Platform based on Apache Spark, Iceberg, Polaris, airflow, openmetadata, dbt, Trino and Superset.
We will walk through that timeline honestly, including what did not work: tools we adopted and dropped, and licence changes that forced us to decide all over again, sometimes to stay, sometimes to leave.
One outcome we did not plan for: open source changed who wanted to work for us. Several of our infrastructure and platform engineers joined Foyer because of this stack. Open source has raised our overall skill level, and it helps us attract talent.
The last part is about the debt: nine years of consuming open source and giving too little back. We will share what we are committing to now, contributing upstream, opening internal code, and building the internal organisation that makes it repeatable.
