Case study

Besòs Tordera - Kubernetes solution for a Besòs river sanitation system

Besòs Tordera

Client

Besòs Tordera

Services

Cloud

Industry

Water

Context

The client CONSORCIO DE BESÒS TORDERA operated 27 sanitation systems in the Besòs river basin without an integrated view of the data generated by each one. Critical information about water quality, hydraulic performance, asset maintenance, and discharge events was spread across more than a dozen heterogeneous and disconnected systems.

Besòs Tordera

Challenge

Fragmented system visibility

None of the solutions communicated with each other, preventing technical staff from having a unified real-time view of system status or making proactive decisions during heavy rainfall events, overflows, or polluting discharges into the river.

Lack of predictive models

The absence of AI-based predictive models that could anticipate, within a 2 to 24-hour horizon, flow arrivals at wastewater treatment plants, overflow risks in the collector network, or the impact of effluents on Besòs water quality.

Lack of a digital twin

The absence of a digital twin capable of simulating alternative operating scenarios to optimize operations in real time.

Solution

The proposed platform, deployed on Amazon EKS on AWS with high availability across two zones (AZ-A and AZ-B), a data acquisition and integration middleware, and an RDS PostgreSQL database, solves this challenge by centralizing all water-cycle information in a single data lake.

Results

1

On-Premise clients:

End users are located in local on-premise facilities. Their desktop computers or servers connect to AWS infrastructure through a Customer Gateway, which is the local endpoint of the VPN connection. This device (physical or virtual) establishes the encrypted tunnel to AWS.

2

VPN Tunnel (Site-to-Site VPN)

Communication travels through an encrypted IPSec VPN tunnel between the on-premise Customer Gateway and the AWS Virtual Private Gateway. This ensures all traffic between the corporate network and the cloud travels securely and privately, without exposure to the public internet.

3

Multi-AZ

The main production VPC is distributed across two availability zones (AZ-A and AZ-B), ensuring high availability and fault tolerance.

4

Public subnets (AZ-A and AZ-B):

They host NAT Gateways that provide controlled outbound internet access and receive external traffic.

5

EKS Private subnets (AZ-A and AZ-B)

These are the private subnets where Kubernetes worker nodes run with their pods (microservices/containers). Each AZ has its own node group with Auto Scaling, enabling horizontal scaling according to demand.

6

RDS Postgre DB - Private Subnet in multi-AZ mode

To ensure data protection, RDS is deployed in the nodes' private subnet. Access to RDS PostgreSQL is handled through an RDS Endpoint, which centralizes and controls connections from EKS pods to the database. The database is never directly exposed to the internet.

SATEC specializes in the development and modernization of containerized solutions in on-premises or cloud environments

SATEC

Interested in our solution?

Leave us your email and we will get in touch to learn about your needs in detail.