TrackIt
TrackIt
Contact us
Case Studies

Enabling a Phased Migration from Akamai to Amazon CloudFront and AWS WAF

Author

Ludovic Francois

Date Published

Customer Challenge

A global enterprise operating multiple business-critical digital platforms and customer-facing services engaged TrackIt to migrate its large-scale Akamai Content Delivery Network (CDN) and Web Application Firewall (WAF) deployment to Amazon CloudFront and AWS WAF. The existing environment included numerous CDN properties, Akamai Property Manager configurations, Cloudlets, EdgeWorkers, and custom WAF policies accumulated over time across different teams and use cases.

Migrating such a complex environment to AWS required more than a direct feature replacement. The project involved addressing architectural dependencies, validating replacement strategies for Akamai-specific services, and defining a secure and scalable operating model for edge delivery on AWS.

Due to the scale and business criticality of the workloads involved, the migration needed to be executed through a phased approach that could progressively validate tooling, deployment patterns, security controls, and cutover procedures before moving to higher-risk production platforms.

Implementation

Akamai to CloudFront and WAF Migration Steps

Assessment & Migration Strategy

TrackIt supported the customer through a structured multi-phase migration program designed to transition the organization’s Akamai CDN and WAF platform to AWS CloudFront and AWS WAF.

The engagement began with a completed assessment phase that established the migration baseline, including inventory analysis, complexity classification, risk segmentation, and identification of technical and organizational dependencies across the Akamai estate.

AWS Foundations & Governance

TrackIt designed an AWS account, governance, and operational framework aligned with AWS best practices to support the migration program. This included AWS account structure design, governance and IAM models for edge services, logging and monitoring baselines using AWS services such as Amazon CloudWatch, Amazon S3, and Amazon Athena.

The team also established CI/CD pipelines for Lambda@Edge, CloudFront Functions, and AWS WAF deployments, integrating with customer-approved tooling where applicable.

Security & AWS WAF Implementation

Security foundations were implemented using AWS WAF, including Web ACL design, managed rule group deployment, logging configuration, and definition of deployment strategies across environments and properties.

As the migration progressed, the implementation expanded to include medium and high-complexity custom WAF rules, replacement strategies for Akamai-specific protections, and comparative validation of AWS WAF and Akamai security behaviors.

Infrastructure as Code & Automation

To support repeatable and scalable migrations, TrackIt implemented Infrastructure as Code (IaC) practices using Terraform. Infrastructure definitions were version-controlled and standardized through consistent naming, tagging, and environment strategies.

Reusable edge templates and deployment patterns were developed to accelerate migrations across properties and environments.

CDN & Edge Migration

The migration was executed through progressively higher-risk phases. Early stages focused on validating migration tooling and replacement strategies through low-risk workloads such as image delivery services and simple edge logic migrations using Amazon CloudFront and CloudFront Functions.

Subsequent phases addressed customer portals, consumer-facing websites, payment-related platforms, and advanced edge processing logic implemented with Lambda@Edge and DynamoDB integrations. The implementation also included origin routing logic, cache key management, DNS cutover orchestration, and rollback validation procedures.

Testing & Production Cutovers

Throughout the engagement, TrackIt incorporated automated and agentic testing approaches to validate functionality, security behavior, and performance consistency against the previous Akamai baseline before production cutovers.

The migration program included coordinated testing activities with the customer’s teams, incremental production cutovers, post-migration monitoring procedures, and rollback readiness validation for business-critical workloads.

Outcome

The engagement established a structured and phased migration framework enabling the customer to transition its Akamai CDN and WAF deployment to an AWS-native edge and security platform built on Amazon CloudFront and AWS WAF.

By implementing reusable edge patterns, CI/CD automation, Infrastructure as Code practices, and standardized deployment procedures, TrackIt helped establish a scalable operational model for ongoing edge platform management while progressively validating migration, testing, security, and rollback procedures before higher-risk production cutovers.

Customer Benefits

  • Structured migration framework for transitioning a large-scale Akamai CDN and WAF environment to an AWS-native architecture with reduced operational risk
  • Standardized Infrastructure as Code, CI/CD pipelines, and reusable edge deployment patterns supporting scalable long-term operations
  • Improved visibility, governance, and security management across CDN, edge, and WAF services through centralized AWS-native tooling and monitoring capabilities