Home/Blueprints/Public Cloud Repatriation

Blueprint · Cloud economics

Bring Your Regulated Workloads Home.

Egress, DORA Article 28, data residency, FinOps variance and AI data gravity are hitting FSI at once. This blueprint brings the workloads that must leave the hyperscaler onto a sovereign, fixed-envelope platform — proven on one first.

Trusted by600+ FSI customers70+ data centres13 global offices15 yrs SOC compliance

The bottom line.

Repatriation in financial services isn't a niche conversation any more. The economics of keeping data-heavy regulated workloads on hyperscaler infrastructure have weakened — and DORA has changed the question from 'can we use this provider' to 'can we exit it on the regulator's timetable'.

This blueprint finds the workloads where the hyperscaler model has stopped paying and moves them to Options Modern Cloud: managed Red Hat OpenShift on Options private cloud, with PrivateMind for sovereign AI. Fixed-envelope economics, an Article 28 exit story, your data in a region you choose — proven in a sandbox.

Why now.

Cost

Egress Economics

Per-GB outbound charges turn analytics, AI and DR into open-ended OpEx — the largest line item nobody forecast at migration.

Regulation

DORA Article 28

In force since January 2025: a register of every ICT provider, a concentration assessment, and a tested exit for any critical function.

Sovereignty

Data Residency

Regulators increasingly require you to know not just where data sits, but who can access it and whose law governs that access.

Finance

FinOps Predictability

Public cloud bills move with configuration, not workload. Boards increasingly want fixed-envelope economics for production.

AI

AI Data Gravity

Training and inference want to sit next to the data and inside the compliance perimeter — not behind a metered egress boundary.

What comes home, what stays.

Repatriation isn't all-or-nothing. Split the estate on two axes — data intensity and regulatory exposure. Three quadrants move; one stays.

High data · High regulation

Repatriate.

Trading, risk, settlement, ledger, payments — the case is unambiguous on both axes.

High data · Low regulation

Repatriate on cost.

Analytics warehouses, ML feature stores, log archives — egress and FinOps drive it.

Low data · High regulation

Repatriate on regulation.

Identity, secrets, audit, regulator-facing services — the DORA case is dispositive.

Low data · Low regulation

Stay.

Marketing sites, hackathons, public-AI evaluations — the public cloud is the right answer.

Managed Kubernetes isn't sovereign.

A hyperscaler appliance on your own floor — EKS on Outposts, AKS on Stack, GKE on bare metal — is the same provider on different metal. The control plane, IAM and support contract still belong to a provider that may already be a DORA Critical ICT Third-Party.

Control plane

  • Hyperscaler: Operated in the provider's jurisdiction.
  • OMC: Operated by PodOps in the Options region you choose.

Exit & substitutability

  • Hyperscaler: Proprietary control plane, portability is your burden.
  • OMC: Standard OpenShift and customer-owned operators, portable by design.

Cost shape

  • Hyperscaler: Usage-metered OpEx with per-GB egress.
  • OMC: A subscription envelope, egress inside the service.

How it runs on OMC.

Whatever comes home lands on managed Red Hat OpenShift on Options private cloud, sized to the workload. The tier changes worker isolation, not the foundation.

Standard

Standard

Shared, multi-tenant OpenShift under one Options compliance policy. Code-ready on day one.

Advanced

Advanced

Dedicated worker pools, host control-plane isolation, and your CI/CD or ours. Optional active-active across two sites.

Dedicated

Dedicated

Single-tenant bare metal, designed in. Capacity, network and compliance scoped to your firm.

PodOps managed service

Options FSI hardening

Red Hat OpenShift

Kubernetes

Validation Sandbox.

A fixed-fee engagement that provisions a working OMC environment in the Options region you choose, migrates one nominated workload, and runs it side by side with the hyperscaler — with pass-or-no-pay exit criteria agreed up front.

  • An Article 28 evidence pack: register entry, exit strategy, migration logs
  • A FinOps comparison: same workload, both platforms, from your own bill
  • An operational handbook: the runbooks your SRE team would use in production

Repatriation is a sequence of small reversible decisions before it's one big irreversible one. The sandbox is the first.

Fixed fee · one workload · pass-or-no-pay

The migration path.

Once the sandbox passes, migration runs in four phases on the Factory Migration methodology — PodOps operates the platform from the first wave, so your team isn't building and running in parallel.

01

Discover

Inventory the estate, classify it on the four-quadrant model, map dependencies, and produce a wave plan and per-application business case.

02

Design

The OMC landing zone — network, identity, observability, security, DR — plus per-wave application designs and the Article 28 artefacts.

03

Migrate

Execution in waves. Registry, CI/CD, secrets, observability and security move as platform services, not app by app.

04

Operate & Optimise

Steady-state PodOps with quarterly reviews, FinOps optimisation, and scheduled DR and exit-strategy testing — ongoing DORA evidence.

Proof and business case.

$0.05–0.09
Per GB hyperscaler egress, 2026 standard tiers
10–40%
Of a typical cloud bill is data movement
45%
Of organisations repatriated workloads last year
600+
FSI customers on the platform

The OMC case is five cost lines — compute, egress, managed Kubernetes, DORA overhead, AI — rebuilt from twelve months of your own invoices in Discover. No customer-specific outcomes are stated here.

Red Hat Premier partner · standard OpenShift, portable by design · operated from the Options region you choose

Ready to bring workloads home?.

Stacks with Oracle → EDB if your Oracle estate is on AWS or Azure. Also: AI & PrivateMind · Capital Markets Teams.