DOC: EMW-WEB-03 / REV 2026-07-17 / STATUS: PUBLISHED

Case Studies

A track record of moving — and keeping alive — systems that cannot stop.

INCIDENT-FREE: 2,000+ days since 2021-01-01 JST — 重大障害ゼロ継続中(当社担当範囲)
Company names and confidential figures are withheld, but every case is based on real projects we designed, built, and operate. Within our scope of responsibility, zero major incidents occurred from 2021 through 2025. We are happy to share more detail in a meeting, to the extent confidentiality allows.
Zero-Incident Ledger

Zero-Incident Ledger — five straight years, zero major incidents

2021-01-01 – 2025-12-31 / 1,826 days
Major incidents (2021–2025) 0
Continuous operation (since 2021-01-01 JST) 2,000+
still counting
Ledger period 1,826 days, all clear

One tick = one day, within our scope of responsibility (same disclosure as above).

小売業のイメージ
Case 01 — Retail / POS

Major department store: Host migration of POS backbone

Industry: Retail Scope: POS & core integration Type: Host-to-AWS phased migration
Challenge

The aging host had to be retired, but POS cannot stop during business hours. With store sales directly at stake, the migration had to fit an extremely narrow downtime window.

Approach

We fixed the downtime budget and rollback criteria first, then designed a phased migration from a full dependency inventory. After building a Multi-AZ AWS foundation and repeated rehearsals, we executed the production cutover with audit-ready change records.

Outcome

Phased migration completed without stopping sales operations. We continue to operate the platform with zero major incidents (2021–2025).

店舗網 POS端末 店舗サーバ 専用線 AWS Cloud(Multi-AZ) ALB App AZ-a App AZ-c Aurora Multi-AZ CloudWatch 監視 / 変更管理・承認フロー・証跡保管
Simplified architecture
食品製造のイメージ
Case 02 — Manufacturing

Food manufacturer: Hybrid cloud for factory management

Industry: Food & Beverage Scope: Factory management system Type: Hybrid cloud
Challenge

Systems tied to plant equipment had to stay on-site, but server aging and fragmented monitoring were growing risks. Cloud benefits had to be introduced without touching plant uptime.

Approach

We defined the on-site/cloud operational boundary first, connected plants to AWS over VPN, automated data and file integration, and unified monitoring on CloudWatch — shifting roles to the cloud in phases while preserving existing operations.

Outcome

Cloud adoption began with zero impact on plant operations; unified monitoring accelerated first-line incident triage.

工場拠点 生産設備・PLC 工場管理サーバ 現場端末 VPN AWS Cloud データ連携 EC2 / EventBridge ファイル連携 S3 / 自動転送 分析・活用 RDS / BI連携 統合監視 CloudWatch SNS通知 運用境界を定義し、既存運用と共存
Simplified architecture
社会インフラのイメージ
Case 03 — Social Infrastructure

Expressway operator: Governed operations for always-on infrastructure

Industry: Expressway / Infrastructure Scope: Platform operations & governance Type: Multi-account operations
Challenge

As critical social infrastructure, the platform required not just availability but the ability to always answer who changed what, when — without slowing daily operations.

Approach

We designed a multi-account structure separating production, staging, and log aggregation; automated evidence collection with CloudTrail and Config; and embedded two-step approvals and recurring access reviews into the daily workflow.

Outcome

Audit-ready evidence now accumulates automatically as part of daily operations — stronger governance without longer change lead times, supporting continuous service on a redundant foundation.

AWS Organizations 管理アカウント(SCP・請求統制) 本番 冗長構成・監視 検証 リハーサル環境 ログ集約 CloudTrail / Config 改ざん防止保管 2段階承認(承認者と実行者を分離)/ 定期的な権限棚卸し 変更申請 → 承認 → 実行 → 証跡保管を標準フロー化
Simplified architecture
不動産業のイメージ
Case 04 — Real Estate / Identity

Major real estate company: Unified corporate identity platform with Keycloak

Industry: Real Estate Scope: Corporate SSO & identity Type: Keycloak (OSS) on AWS
Challenge

Every internal system had its own credentials — users recycled passwords while IT chased account provisioning across systems at every join and leave. Avoiding vendor lock-in was also a requirement.

Approach

We selected Keycloak (OSS) and built it in a Multi-AZ redundant topology on AWS with RDS Multi-AZ as its datastore — so the identity platform itself is no single point of failure. Federated with the existing corporate directory, internal systems were onboarded to SSO one by one via SAML / OpenID Connect.

Outcome

One set of credentials plus MFA now opens every internal system. Joiner-leaver management is centralized, structurally eliminating orphaned accounts — and the front door to every system runs on a no-single-point-of-failure foundation.

社員 ブラウザ / MFA 既存ディレクトリ ユーザー連携 AWS Cloud(Multi-AZ) ALB Keycloak AZ-a Keycloak AZ-c RDS Multi-AZ 社内システム群(基幹・グループウェア・各種業務システム) SAML / OpenID Connect で順次SSO接続
Simplified architecture
プライベートクラウド/HCIのイメージ
Case 05 — Windows / Private Cloud

Under a major SIer: designing and building a resilient S2D × Hyper-V platform from scratch

Role: Subcontractor to a major SIer (design & build) Scope: Windows Server 2025 / S2D / Hyper-V Type: HCI private cloud (live migration)
Challenge

As a subcontractor to a major SIer, we designed and built a Storage Spaces Direct (S2D) HCI platform from scratch, with a hard requirement to evacuate nodes non-disruptively via live migration. Frankly, it was not straightforward: S2D is a field full of pitfalls — RDMA/RoCE with DCB/PFC, quorum, the migration AD, and live-migration authentication — where a single design mistake destabilizes production.

Approach

The most time-consuming part was actually before touching hardware: surveying the existing setup, coordinating with the SIer and stakeholders, and nailing down the design — skip that and it bites back later. Early on we stumbled repeatedly on the network (RDMA DCB/PFC, SET switches), tracing storage latency and drops all the way back to switch-side PFC and jumbo frames. Live migration wouldn't work under the default CredSSP, so we registered SPNs in the migration AD and configured Kerberos constrained delegation. Quorum (file-share witness), CSV/ReFS volume design, and non-disruptive patching via CAU were each validated step by step into production.

Outcome

We knocked down the hard spots one by one and brought the HCI platform into production with non-disruptive node evacuation via live migration. And that painful, stumble-filled experience is exactly what EMW is built on: because we learned the ins and outs of S2D, Hyper-V, AD, and Kerberos the hard way, we can design AWS migrations with a correct understanding of what is really happening on the on-prem side.

Windows フェイルオーバークラスタ(S2D HCI) ライブマイグレーション Hyper-V ノード1 VM VM Hyper-V ノード2 VM VM Hyper-V ノード3 VM VM ノード間:RDMA / SMB Direct(ライブマイグレーション網) Storage Spaces Direct 共有プール 各ノードのローカルNVMeを束ねる / ReFS・CSV・ミラー クォーラム:ファイル共有ウィットネス / CAUで無停止パッチ適用 移行用 Active Directory + Kerberos 制約付き委任 ライブマイグレーションの認証・二重ホップ対策
Simplified architecture
Read the raw design-decision log — where RDMA, Kerberos delegation & the migration AD burned us →

These are a selection of our cases. We also handle high-load platforms for amusement equipment makers and small-start architectures for SMBs.

Facing a Similar Challenge?

Share your current setup and pain points — we'll propose a practical path forward.

Start a Conversation