Case study · Grocery technology · thousands of engineers

Kubernetes and databases without the IP allowlist

Instacart runs a large EKS estate and hundreds of data stores. Getting engineers to them used to mean allowlists and bastions. OpenVLAN made access an identity question instead of a network question.

Instacart — hexagonal compute clusters with private laptop lines

The challenge

Scale changes everything about access. With thousands of engineers, "add my IP to the security group" stops being a ticket and becomes a second job for the platform team. Bastions multiplied per cluster; the Kubernetes API servers faced the internet because the alternative was unmanageable. Access reviews meant reconciling three systems that disagreed.

The switch

The platform team deployed OpenVLAN as the access layer for internal infrastructure: cluster APIs reached through the operator, databases through subnet routers, and every connection authenticated against corporate SSO with group-driven ACLs.

The results
100%

of cluster APIs off the public internet

−70%

access-related tickets to the platform team

1

system of truth for who can reach what

The takeaway

At Instacart's scale, the win wasn't removing VPN appliances — it was making access legible. When every connection carries an engineer's identity, audit questions answer themselves from logs instead of forensic work.

This case study is an illustrative example with fictional data for demonstration purposes.

Access at scale, without the scale of access problems