Case study
Legacy Elasticsearch Upgrade for a US Commercial Bank
How a 40+ year old US commercial bank upgraded its Elasticsearch clusters from 7.17 to 8.x after Ansible dropped support for the newer version.
A large, 40+ year old American commercial bank with a global footprint across APAC, Europe, the Middle East, and North America.
It handles more than $1 billion in annual revenue on critical banking infrastructure and transaction systems.
Elasticsearch clusters upgraded from version 7.17 using custom Ansible playbooks. Baseline security assessment completed, with known vulnerabilities patched. Terraform and ECK evaluated as validated long-term upgrade paths.
Key servicesHow SquareShift delivered it.
The challenge
A 40+ year old American commercial bank, running critical banking infrastructure and transactions across APAC, Europe, the Middle East, and North America, was managing its on-prem Elasticsearch clusters on version 7.17 with Ansible playbooks.
Ansible’s native support stopped at 7.17, so the bank couldn’t move to 8.x without custom tooling. With more than $1 billion in annual revenue riding on these systems, the upgrade also had to clear a baseline security review and close known vulnerabilities.
What we delivered
SquareShift built custom Ansible playbooks compatible with Elasticsearch 8.x, closing the automation gap Ansible’s own tooling had left behind, and ran a baseline security assessment to patch known vulnerabilities as part of the same upgrade.
Alongside the playbook work, SquareShift evaluated Terraform and Elastic’s Kubernetes Operator (ECK) as long-term orchestration options and supported the bank’s planning for a future move away from Ansible.
The payoff
The bank’s critical clusters now run on Elasticsearch 8.x, upgraded through Ansible playbooks purpose-built for the jump Ansible itself didn’t support.
Known vulnerabilities identified in the baseline security review were patched as part of the upgrade, and the bank has a validated Terraform/ECK path in hand for whenever it’s ready to modernize its orchestration further.
When your automation tooling stops supporting the version you need, the fix isn't to abandon Ansible — it's to write the playbooks the vendor hasn't gotten to yet.
Cloud Modernization Practice Lead, SquareShift
Where this work sits
