A government body responsible for regulating Indonesia’s state-owned enterprises had no cloud disaster recovery for the systems running national recruitment and inter-agency workflows. PT Metrodata Electronics Tbk delivered a hybrid architecture on AWS with enterprise application security.
|
11 m 44 s |
12 m 9 s |
~15 min |
Layer 7 |
|
Measured recovery of the application server |
Measured recovery of the database server |
Recovery point (asynchronous DRS replication) |
Application security and DDoS mitigation added |
The customer is an Indonesian government body responsible for the regulation and stewardship of state-owned enterprises. Its mandate covers driving transformation, strengthening governance and improving operational efficiency across the country’s portfolio of government-owned companies. The organisation operates several critical digital platforms in a hybrid environment, including national recruitment systems, internship management platforms and integrated business workflow applications that connect directly with multiple state-owned enterprises. These systems serve applicants and enterprises across Indonesia and require secure, highly available and resilient infrastructure.
As the organisation expanded its digital services in support of Indonesia’s state-owned enterprise transformation agenda, its environment grew to approximately 45 on-premises servers running integrated applications, Active Directory services and inter-agency connectivity. That environment had no cloud-based disaster recovery capability of any kind. A disruption to the on-premises site could take days to recover from, directly interrupting recruitment cycles, internship placements and the business workflows connecting the regulator to the enterprises it oversees.
The risks of leaving this unaddressed were both operational and institutional. As a government regulator, the organisation would face legitimate scrutiny over the adequacy of its own business continuity planning for critical public sector systems. Application-layer protection and distributed denial of service mitigation were limited, leaving public-facing government platforms exposed to attack. Monitoring and visibility were constrained enough to slow incident response and root cause analysis, extending any outage. And disruption to recruitment and internship systems would affect thousands of individual applicants, with a corresponding cost to public trust.
The organisation therefore required more than a backup arrangement. It needed a hybrid-cloud architecture that could provide genuine disaster recovery on AWS while integrating cleanly with the existing on-premises estate, together with centralised identity management, enterprise-grade network segmentation, application-layer security, DNS services and load balancing.
PT Metrodata Electronics Tbk, delivering through its subsidiary PT Sinergi Transformasi Digital, designed and implemented a secure hybrid-cloud disaster recovery architecture on AWS. Production remains on-premises; AWS in the Asia Pacific (Jakarta) Region serves as the disaster recovery site, with AWS Elastic Disaster Recovery providing continuous replication between them. The design keeps all replicated government data within Indonesia.
Metrodata began with an assessment across the 45-server on-premises estate, mapping application dependencies, Active Directory integration points and inter-agency connectivity requirements, then agreed recovery objectives with the customer’s IT leadership. The resulting architecture was built on AWS Control Tower for multi-account governance, with three dedicated DRS VPCs and a private subnet structure separating the replication staging area from the recovery environment. AWS Transit Gateway centralised connectivity between accounts and VPCs, and a Site-to-Site VPN provided the encrypted replication path from the on-premises data centre to AWS.
Deployment installed AWS DRS replication agents across the on-premises fleet, configuring continuous block-level replication into Amazon EBS volumes in the staging subnet. Recovery servers are held as launch configurations rather than running instances, following the pilot light pattern. Active Directory and an F5 firewall instance were deployed as persistent EC2 instances within the recovery VPC so that identity services and traffic inspection are available the moment a recovery is invoked, rather than being recovered themselves at the point of need — a design decision that removes a common circular dependency in Active Directory-dependent recovery plans.
Alongside the disaster recovery capability, Metrodata implemented F5 technologies for Layer 7 traffic inspection, filtering, load balancing and distributed denial of service mitigation, addressing the application-layer exposure the assessment had identified. Active Directory synchronisation was established to provide consistent authentication and access control across the hybrid estate, replacing per-application identity silos with centralised management.
Metrodata provided support services across both phases. Before implementation, the partner conducted the assessment, produced the architecture design covering replication, application security and failover and failback topology, executed initial replication and tuned the replication mechanism, and authored the drill plan and recovery runbooks. After implementation, Metrodata provides ongoing monitoring, managed support, and periodic disaster recovery validation, together with documented procedures for replication management and recovery operations and training for the customer’s own IT team.
Recovery capability was validated by drill against defined success criteria. Two servers — an application server and its database server — were recovered from on-premises into the AWS environment and confirmed operational. The application server recovered in 11 minutes 44 seconds and the database server in 12 minutes 9 seconds, both measured from initiation of the recovery job to the instance reaching a running state. Replication ran asynchronously with a measured recovery point of about 15 minutes (validated on the AWS DRS source-server dashboard), well within the 30-minute Tier 2 objective. Application access through the AWS network load balancer was verified, and functionality testing on the recovered systems passed. All four success criteria were recorded as met.
A 12-minute measured recovery replaces a position where recovery from an on-premises failure would have taken days. For a government regulator whose recruitment and inter-agency workflow platforms serve thousands of applicants and every state-owned enterprise in the portfolio, that is the difference between an incident and an outage.
|
Measure |
Before |
After |
|
Cloud disaster recovery capability |
None |
Hybrid DR on AWS Jakarta |
|
Recovery time, measured |
Days, no defined capability |
11 m 44 s and 12 m 9 s |
|
Recovery point |
Undefined |
~15 min (async DRS replication; 30-min objective) |
|
Application-layer security |
Limited |
F5 Layer 7 inspection and DDoS mitigation |
|
Identity management |
Siloed per application |
Centralised Active Directory synchronisation |
|
Operational visibility |
Limited monitoring |
Centralised monitoring and logging |
|
Governance |
Single environment |
AWS Control Tower multi-account structure |
The engagement addressed each risk the assessment had identified. A disruption that would previously have taken days to recover from now has a measured recovery path of roughly twelve minutes per server, with runbooks the customer’s own team has been trained to execute. Application-layer protection and denial of service mitigation now cover public-facing government platforms that previously had limited defence. Identity management is centralised rather than fragmented across applications, and monitoring provides the visibility that incident response and root cause analysis previously lacked. As the regulator responsible for governance standards across Indonesia’s state-owned enterprises, the organisation now holds documented, tested business continuity evidence for its own critical systems.
PT Metrodata Electronics Tbk (IDX: MTDL) is one of Indonesia’s leading digital solution providers and an AWS Advanced Tier Services Partner, trusted by more than 200 organisations across healthcare, financial services, manufacturing, retail, mining and the public sector in adopting and implementing cloud solutions. Metrodata currently holds the AWS Migration and Modernization Competency and the AWS Glue Service Delivery designation, demonstrating validated technical expertise in cloud migration, data integration, and business continuity. Delivering through its consulting and system integration subsidiaries PT Mitra Integrasi Informatika and PT Sinergi Transformasi Digital, the company maintains a dedicated practice of certified AWS solutions architects and engineers supporting customers throughout Indonesia.
PT. Metrodata Electronics, Tbk.
APL Tower 37th Floor
Jl. Letjen S. Parman Kav. 28
Jakarta 11470
Contact Us:
P: (62-21) 2934 5888
F: (62-21) 2934 5899
E: info.metrodata@metrodata.co.id