From Legacy Apps to AI Agents: Modernising Securely with GitLab and VMware VKS

Blog
From Legacy Apps to AI Agents: Modernising Securely with GitLab and VMware VKS
Many enterprises want the speed of cloud-native software delivery.
They want shorter release cycles, better developer productivity, automated security checks, faster deployment, and the ability to build modern digital services at scale.
But not every workload can move to public cloud.
For many India-based enterprises, especially in banking, insurance, financial services, manufacturing, healthcare, pharma, telecom, government, and public sector, public cloud adoption must be balanced with data residency, compliance, latency, cost predictability, security, and integration with core systems.
The answer is not always “cloud migration”.
In many cases, the more practical answer is to bring a cloud operating model on-prem.
This is where GitLab, AI-assisted software delivery, AI agents, and VMware vSphere Kubernetes Service — VKS on VMware Cloud Foundation 9.x can create a strong enterprise modernisation blueprint.
GitLab provides the DevSecOps backbone. VKS provides the Kubernetes runtime on VMware Cloud Foundation. AI agents can automate repeatable software delivery workflows. And Sunfire Technologies helps enterprises bring these pieces together through assessment, implementation, modernisation, deployment, and enablement.
Why Application Modernisation Matters Now
Indian enterprises are under pressure to launch digital services faster while maintaining strong governance and auditability.
Business teams want faster product releases. Technology teams want better engineering practices. Security teams want earlier visibility into risk. Compliance teams want evidence, traceability, and control. Infrastructure teams want better utilisation of existing private cloud investments.
Application modernisation addresses these priorities together.
Done well, it can help enterprises achieve:
- Faster time to market
- Shorter release cycles
- Better developer productivity
- Improved software quality
- Security embedded into delivery
- Compliance evidence built into pipelines
- Reduced manual effort across build, test, release, and deployment
- Support for modern digital, API, and AI use cases
- Better utilisation of private cloud and data centre investments
The objective is not just to run applications differently. The objective is to deliver software with greater speed, consistency, security, and operational control.
Press enter or click to view image in full size

Modernisation Is More Than Containerisation
Application modernisation is a spectrum. Some applications may only need to be rehosted on newer infrastructure. Some may be replatformed into containers. Some may need refactoring. Others may require rearchitecture into APIs, microservices, or event-driven components. A few may be better replaced entirely. The right path depends on business value, technical debt, application criticality, cost, compliance, and operational complexity.
Containerisation is an important step in this journey because it creates a more consistent way to package and run applications across environments.
A containerised application can be built, scanned, promoted, deployed, scaled, and rolled back in a more repeatable manner. This is especially useful when combined with CI/CD pipelines, Kubernetes, policy controls, and observability.
Good initial candidates for modernisation and containerisation may include:
- Internal portals
- Java applications
- .NET Core applications
- API services
- Batch jobs
- Middleware adapters
- Reporting dashboards
- Digital onboarding applications
- AI/ML inference services
- Low-risk customer-facing microservices
However, some workloads require deeper assessment before containerisation. These may include:
- Highly stateful monoliths
- Applications with hard-coded file paths
- Legacy operating system dependencies
- Applications with complex database coupling
- Applications with heavy local storage dependency
The best approach is to start with a structured application assessment, identify quick wins, and create repeatable patterns before scaling the programme.
GitLab as the Software Delivery Control Plane
In many enterprises, software delivery is still fragmented.
Code may be in one system. Requirements may be tracked elsewhere. Security scans may happen late. Deployment may depend on manual approvals and scripts. Compliance evidence may be collected after the fact. This slows delivery and increases operational risk.
GitLab helps address this by acting as a software delivery control plane.
It brings together source code, planning, CI/CD, security, compliance, release governance, and deployment workflows into a unified platform.
For application modernisation, GitLab can support:
- Source code management
- Issue and requirement tracking
- CI/CD pipelines
- Build automation
- Container image build
- Container registry
- Code quality checks
- Static Application Security Testing
- Dynamic Application Security Testing
- Secret detection
- Dependency scanning
- Container scanning
- Compliance pipelines
- Merge request approvals
- Auditability
- Environment promotion
- GitOps integration
- Release governance
This helps enterprises move from manual, ticket-driven releases to automated, traceable, and policy-driven software delivery.
For example, consider a legacy Java application.
The application can be assessed, containerised, checked into GitLab, built through CI/CD, scanned for vulnerabilities, packaged as a container image, stored in a registry, and deployed to VKS through controlled pipelines or GitOps.
Every step can be traced.
Who changed the code?
Which pipeline built it?
Which vulnerabilities were detected?
Who approved the merge request?
Which image was deployed?
Which environment received the release?
This traceability is especially valuable for regulated enterprises where auditability, segregation of duties, and change governance are critical.
The Role of AI in Modernisation and Software Delivery
AI is becoming an important accelerator in software engineering.
For enterprises, the value is not only in generating code. The bigger opportunity is to use AI to reduce repetitive effort, improve engineering consistency, assist developers, and capture institutional knowledge.
In an application modernisation programme, AI can help with:
- Code explanation
- Test generation
- Legacy code understanding
- Documentation generation
- Security remediation suggestions
- Pipeline troubleshooting
- Developer productivity
- Knowledge capture
- Assisted refactoring
- Release note generation
For example, a developer working on a legacy service may use AI assistance to understand old code, generate unit tests, identify risky dependencies, improve documentation, or troubleshoot a failed pipeline.
But the next step is even more interesting: AI agents.
In simple enterprise terms, AI agents are software assistants that can reason over context, take actions through approved tools, and help automate repeatable workflows.
They are not just chatbots. They can be designed to support specific software delivery tasks.
Examples of AI agents in enterprise software delivery include:
- Code review agent to suggest improvements before merge
- Test case generation agent to create unit or regression tests
- Security remediation agent to recommend fixes for vulnerabilities
- Compliance evidence agent to collect pipeline, approval, and scan evidence
- Release readiness agent to check whether a build is ready for promotion
- Incident triage agent to summarise logs, alerts, and recent deployment changes
- Application modernisation assessment agent to review code, dependencies, and deployment artefacts
- Documentation agent to generate technical and operational documentation
- Platform support agent to answer GitLab and Kubernetes queries for developers
However, these agents must be governed properly.
They should be secured, logged, integrated with enterprise workflows, and designed to respect change control, access policies, approval gates, and human oversight.
AI agents should accelerate enterprise delivery. They should not bypass security, compliance, or accountability.
Why Deploy on VKS with VMware Cloud Foundation 9.x
Many Indian enterprises already have significant investments in VMware infrastructure.
They run critical workloads on vSphere. They use enterprise storage, network controls, backup systems, security tools, and operational processes built around their data centre and private cloud environments.
For such enterprises, VKS provides a practical path to Kubernetes adoption on familiar infrastructure.
VMware vSphere Kubernetes Service — VKS is the Kubernetes runtime available with VMware Cloud Foundation. It helps enterprises run modern containerised workloads on-prem while extending their existing VMware platform investments.
VKS is relevant for enterprises because it:
- Runs Kubernetes on familiar VMware infrastructure
- Provides a consistent platform for VMs and containers
- Helps infrastructure teams extend existing VCF investments
- Supports on-prem Kubernetes adoption
- Keeps workloads closer to enterprise data and core systems
- Helps meet data control and latency requirements
- Reduces the need for separate Kubernetes platform procurement where VCF entitlement already includes VKS
- Enables a cloud operating model inside the enterprise data centre
For enterprises already investing in VMware Cloud Foundation 9.x, VKS is included as part of the platform. This can help avoid an additional Kubernetes platform licence line item and improve the business case for on-prem application modernisation.
However, commercial entitlement should always be validated with the customer’s VMware/Broadcom agreement.
The value proposition is clear: enterprises can modernise applications using Kubernetes while continuing to leverage their existing VMware Cloud Foundation platform.
GitLab + VKS Reference Architecture
A practical GitLab + VKS architecture can be viewed in layers.
Infrastructure Layer
This layer provides the enterprise private cloud foundation.
It may include:
- VMware Cloud Foundation 9.x
- vSphere
- vSAN
- NSX / networking
- Enterprise storage and backup
- Data centre security controls
This is where existing enterprise investments can be extended to support modern workloads.
Kubernetes Platform Layer
This layer provides the Kubernetes runtime and cluster services.
It may include:
- VMware vSphere Kubernetes Service
- Kubernetes clusters
- Namespace management
- Storage classes
- Ingress and load balancing
- Network policies
This layer allows application teams to deploy containerised workloads in a controlled and standardised manner.
DevSecOps Layer
This layer manages software delivery.
It may include:
- GitLab source control
- GitLab CI/CD
- Container registry
- Security scanning
- Merge request approval
- Compliance pipelines
- GitOps deployment flow
GitLab becomes the control plane for build, test, scan, approve, release, and deploy.
Application Layer
This is where modernised workloads run.
It may include:
- Microservices
- APIs
- Modernised monoliths
- Batch jobs
- AI agents
- Internal enterprise applications
Not every workload needs to become a microservice. The architecture should support different modernisation patterns.
Security and Compliance Layer
This layer cuts across the entire platform.
Remember me for faster sign in
It may include:
- RBAC
- Secrets management
- Vulnerability management
- Audit logs
- Policy as code
- Compliance evidence
- Segregation of duties
- Approval workflows
This ensures that speed does not come at the cost of control.
Operations Layer
This layer supports Day-2 operations.
It may include:
- Monitoring
- Logging
- Backup
- Disaster recovery
- Incident management
- Platform support
- Capacity management
In this architecture, GitLab manages the software delivery lifecycle while VKS provides the Kubernetes runtime on VMware Cloud Foundation.
Together, they provide a strong foundation for modern, secure, on-prem application delivery.
Press enter or click to view image in full size

Security and Compliance for India-Based Enterprises
For Indian enterprises, application modernisation must be designed with security and compliance from the beginning.
This is especially important in regulated sectors such as banking, insurance, capital markets, telecom, healthcare, pharma, government, and public sector.
Key considerations include:
- Data residency and data sovereignty
- Audit trails
- Role-based access control
- Segregation of duties
- Vulnerability management
- Secure SDLC
- Change control
- Evidence for internal and external audits
- Encryption and secrets management
- Patch and image governance
- Compliance reporting
- Incident response readiness
- Vendor and supply chain risk management
Indian enterprises may also need to align with sectoral and national regulatory expectations, including:
- RBI expectations for regulated financial entities
- SEBI-regulated entities where applicable
- IRDAI-regulated insurance organisations where applicable
- CERT-In incident reporting expectations
- Digital Personal Data Protection Act considerations
- Internal ITGC and ISO 27001 controls
- Sector-specific audit and risk requirements
This is not a legal interpretation. It is a technology alignment and control enablement view.
GitLab and VKS can support this control model in multiple ways.
GitLab provides traceability from requirement to code to build to deployment. Security scanning helps detect vulnerabilities earlier. Approval workflows support change governance. Audit logs support evidence generation. Compliance pipelines help standardise control checks.
VKS keeps workloads on enterprise-controlled infrastructure. VCF provides the private cloud foundation for regulated workloads. Together, they help enterprises adopt modern delivery practices while maintaining control over where workloads run and how they are governed.
Sunfire’s Role in the Modernisation Journey
Technology alone does not deliver modernisation.
Enterprises need an implementation approach that connects application teams, infrastructure teams, platform engineering, security, compliance, and operations.
This is where Sunfire Technologies plays an important role.
Sunfire helps enterprises modernise applications, implement GitLab-based DevSecOps, deploy workloads on VKS, and build governed AI agents that accelerate software delivery without compromising security or compliance.
Sunfire’s role can cover:
- Application portfolio assessment
- Modernisation roadmap
- GitLab setup and configuration
- GitLab CI/CD implementation
- DevSecOps pipeline design
- Security scanning and compliance workflow setup
- VKS setup on VCF 9.x
- Kubernetes cluster design
- Containerisation of selected applications
- Deployment automation
- GitOps enablement
- AI agent design and integration
- Platform operating model
- Knowledge transfer and enablement
- Day-2 operations support
The goal is not just to create a pilot.
The goal is to help enterprises move from isolated experiments to scalable adoption, with reusable patterns, governance, and operational confidence.
Business Benefits
A GitLab + VKS modernisation model can create measurable business and technology benefits.
These include:
- Faster time to market
- Reduced release cycle time
- Better developer productivity
- Standardised delivery process
- Stronger security posture
- Earlier vulnerability detection
- Improved compliance evidence
- Better use of existing VCF investment
- Reduced manual deployment effort
- Repeatable application modernisation patterns
- Lower operational risk
- Improved collaboration between application, security, and infrastructure teams
- A platform for future AI-enabled software delivery
For business leaders, the benefit is faster delivery of digital capabilities.
For technology leaders, the benefit is standardisation and control.
For security and compliance teams, the benefit is earlier visibility, stronger governance, and better evidence.
For developers, the benefit is a more automated and productive engineering experience.
A Practical 90-Day Roadmap
Application modernisation should not begin with a big-bang transformation.
A better approach is to define a focused 90-day roadmap, prove the foundation, and then scale.
Days 0–30: Assess and Design
The first 30 days should focus on assessment and architecture.
Key activities include:
- Identify candidate applications
- Assess GitLab and VCF readiness
- Validate VKS entitlement and architecture
- Define security and compliance baseline
- Select the first 2–3 applications
- Define success metrics
This phase should answer three questions:
Which applications should we start with?
What platform foundation do we need?
What does success look like?
Days 31–60: Build the Foundation
The next 30 days should focus on setting up the platform and delivery foundation.
Key activities include:
- Set up VKS on VCF 9.x
- Configure GitLab projects, runners, registry, and access
- Build CI/CD templates
- Set up container image scanning
- Configure deployment pipelines
- Define RBAC, secrets, and approval flows
- Set up observability and backup approach
This phase creates the standard operating model for modernised application delivery.
Days 61–90: Modernise and Deploy
The final 30 days should focus on modernising and deploying selected workloads.
Key activities include:
- Containerise selected applications
- Build and scan images
- Deploy to non-production VKS clusters
- Validate performance and security
- Move approved workloads to production
- Document reusable patterns
- Train application and platform teams
This phase should create working examples that other teams can learn from and reuse.
Beyond 90 Days: Scale and Mature
After the first 90 days, enterprises can scale adoption.
Key activities include:
- Onboard more application teams
- Build reusable golden paths
- Introduce GitOps
- Expand AI-assisted development and AI agents
- Automate compliance reporting
- Mature platform engineering practices
The objective is to make modernisation repeatable.
Press enter or click to view image in full size

Common Mistakes to Avoid
Modernisation programmes can fail when technology is implemented without an operating model.
Common mistakes include:
- Treating Kubernetes only as infrastructure
- Deploying GitLab without standard pipeline templates
- Ignoring security scans in the CI/CD lifecycle
- Moving applications without dependency assessment
- Not defining image governance
- Poor secrets management
- Lack of observability
- No clear ownership between application, platform, infrastructure, and security teams
- Treating AI agents as uncontrolled automation
- Assuming every legacy application must become microservices
- Not validating VCF/VKS licensing and operational readiness upfront
The most successful programmes start small, create standards, prove value, and then scale with discipline.
Conclusion
For Indian enterprises, application modernisation must balance speed, security, compliance, cost, and operational control.
GitLab provides the DevSecOps backbone.
VKS on VMware Cloud Foundation 9.x provides the on-prem Kubernetes runtime.
AI agents can improve productivity and automate software delivery workflows when governed properly.
Sunfire Technologies brings these elements together through assessment, implementation, modernisation, deployment, and enablement.
This approach allows enterprises to modernise applications while keeping workloads close to enterprise data, core systems, and regulatory controls.
Modernisation is not only about moving applications.
It is about creating a secure, automated, AI-ready software delivery platform that helps the enterprise move faster with confidence.


