Engineers from Coinbase and Bitovi share how they migrated 300+ namespaces and services from a custom self-hosted Temporal cluster to Temporal Cloud under strict reliability and security constraints. The talk covers two core migration patterns: 'drain and switch' for short-lived workflows that can tolerate a brief pause, and 'dual workers' using a multi-client manager for long-running, critical workflows requiring zero planned downtime and percent-based traffic routing. Security topics include private link networking, mTLS with certificate filters, a centralized codec server for payload encryption, and a consensus-based admin service for operator access. Lessons emphasize designing for rollback from day one, treating security as a first-class requirement, starting with the simplest viable strategy, and investing in observability and runbooks to build trust with product teams.

32m watch time
250 Impressions