Open Source Conference Luxembourg

Leaving the appliances: what seven years of open-source migration taught us

API Gateway, ESB, Web Access Management and WAF - from proprietary products to Tyk, Keycloak, Traefik and CrowdSec.

Replacing a security appliance with open source is almost never a like-for-like swap. We set out to move our entire web middleware security stack - API Gateway, ESB, Web Access Management, application WAF - onto Tyk, Keycloak, Traefik and CrowdSec. The first component has been in production since 2019; other workstreams are still under way.

We will share what that journey actually cost and taught us: how to escape XSLT transformations hardcoded inside a product, by turning real traffic captures into unit tests; why moving from Web Access Management to Keycloak is a change of security model rather than a change of tool; what you learn when an open-source ingress controller stops being maintained and you have to migrate under time pressure; and why a load balancer's custom traffic rules remain the hard part, with no mechanical translation available.

We will be honest about what we are leaving behind - our WAF appliance is robust, well-tooled and trusted by auditors - and about the real trade: every workstream swapped a licence cost for code we now maintain ourselves.

This is a workshop, not a lecture. Five questions go to the room, including the ones we have not settled - particularly around PKI, as public certificate lifetimes head towards a few tens of days.


Key takeaways

  • A migration method that travels: real traffic capture as the regression test suite for a rewrite.
  • The difference between a header-injecting authentication proxy and a token-issuing identity provider, and the transition pattern for applications that cannot speak OIDC.
  • The real cost of an open-source dependency going end-of-life, and why to target the standard API rather than a product's extensions.
  • The PKI deadline coming for everyone, and why automation becomes an availability requirement rather than an optimisation.
Christophe Boulanger

Passionate about technology and innovation, Christophe drives the evolution of Foyer Group’s IT platforms by combining automation, security, and pragmatism. Always attentive to user needs, he is committed to delivering a smooth and high-performing experience.
He firmly believes that technology should be an accelerator rather than a barrier, and that behind every line of code lies an opportunity to improve everyday life.

Head of Data & Platform Engineering – Foyer Group
https://www.linkedin.com/in/christophe-boulanger-4b936183/
christophe.boulanger@foyer.lu