Fixed price · Legacy API → AWS
Your legacy API on AWS in six weeks. Zero downtime.
- £15,000
- fixed price, plus VAT. No hourly rates, no scope creep
- 6 weeks
- from kick-off to DNS cutover and handover
- 50 endpoints
- covered under the fixed price, migrated in batches
- £80–300 / mo
- typical AWS run-rate for 1-5 million requests a month
How it works
Six weeks, four phases, fixed scope.
- 1
Week 1 · Discovery + IaC scaffolding
We map every endpoint, document request/response shapes, identify auth and side-effects, and produce a written migration plan.
In parallel, we scaffold the AWS account, IAM roles, IaC repository, CI/CD pipeline, and a working "hello world" endpoint through to a staging domain.
- 2
Weeks 2-5 · Endpoint-by-endpoint migration
We migrate endpoints in batches of 5-10, ordered by importance.
Each endpoint ships with contract tests run against the legacy API, observability hooks, and a feature flag controlling whether the new or legacy endpoint serves production traffic.
- 3
Week 6 (Mon-Thu) · Load test, harden, document
Load testing under realistic traffic profiles.
WAF rules tuned. Throttling configured. CloudWatch dashboards and alarms finalised. OpenAPI spec generated. Runbook written for your on-call team.
- 4
Week 6 (Fri) · DNS cutover + handover
60-minute handover call walking your tech lead through the architecture, the IaC repo, the dashboards, the runbook, and the rollback procedure.
We flip DNS during your maintenance window and stay on standby for 48 hours.
- 5
Post-launch (optional) · 30-day post-launch support
A standalone, fixed-price 30-day support window where we monitor, tune, and squash any post-cutover issues.
Optional — most clients do not need it, but it is available for peace of mind.
Tech we use
AWS API GatewayAWS LambdaAWS CDKTerraformNode.js / TypeScriptPython (when it fits)CognitoAWS WAFCloudWatchX-RayDynamoDBRDS ProxyOpenAPI 3.1GitHub Actions
What you get
A production-ready, fully-managed API on AWS.
Not a prototype. A working, monitored, secured, documented API serving real traffic, with the old API still running so you can flip DNS when you are ready.
API Gateway + Lambda
REST endpoints rebuilt as Lambda functions behind API Gateway, with route validation, custom authorisers, throttling and usage plans configured.
Infrastructure as code
Everything defined in AWS CDK or Terraform. Spin up staging or roll back with one command, and audit every change through Git.
Custom domain + SSL
Your existing API hostname pointed at the new gateway, with ACM-managed certificates and automatic renewal. Clients see no change.
Authentication & security
Cognito, custom JWT authorisers or your existing provider wired into API Gateway, plus WAF rules, per-route rate limiting and request validation.
Observability built in
CloudWatch dashboards for latency, errors, throttles and cost, alarms to email or Slack, X-Ray tracing and structured JSON logs.
CI/CD pipeline
GitHub Actions or CodePipeline deploying to dev, staging and production on every merge, with automated tests gating production and preview environments per PR.
OpenAPI documentation
Auto-generated OpenAPI 3.1 spec plus a hosted docs site (Swagger UI or Redoc). New developers onboard in an hour instead of a week.
Contract-tested parity
Every migrated endpoint validated against the legacy API with recorded request/response fixtures, so behavioural drift is caught before DNS flips.
Zero-downtime cutover
Old and new APIs run in parallel during the migration. Cut over with a DNS change you can revert in minutes if anything looks off.
What exactly do I get for the fixed price?
One legacy API (up to 50 endpoints) migrated end-to-end onto AWS API Gateway + Lambda, deployed via infrastructure-as-code, behind a custom domain with SSL, with CloudWatch dashboards and alarms, a CI/CD pipeline, OpenAPI documentation, and a 60-minute handover call with your team. Old API stays running side-by-side until you flip DNS — zero downtime cutover.
How long does it take?
Six working weeks from kick-off. Week 1: discovery and IaC scaffolding. Weeks 2-5: endpoint-by-endpoint migration with contract tests against the legacy API to ensure parity. Week 6: load testing, observability, custom domain, and DNS cutover.
Does this work for any kind of legacy API?
Best fit: REST APIs running on EC2, on-premise servers, Heroku, or aged PaaS platforms — typically Node.js, PHP, or Python — that are showing their age (slow, expensive to operate, painful to deploy). We have migrated APIs handling everything from media analytics workloads to internal admin tools. If your API is GraphQL or gRPC, talk to us first — different tooling, similar pattern.
What if my API has more than 50 endpoints?
We scope larger APIs the same way: phase 1 covers the first 50 endpoints under the fixed price, and phase 2 onwards runs at a fixed per-endpoint rate with no surprise charges. Most clients find that the first 50 endpoints — the highest-traffic core of their API — are enough to validate the approach before committing to the rest.
What about authentication, rate limiting, and security?
Included. We wire up API Gateway authorisers (Cognito, custom Lambda authorisers, or your existing JWT provider), per-route throttling, usage plans, AWS WAF for IP- and pattern-based protection, and request/response validation against your OpenAPI schema. The new API ships harder than the legacy one it replaces.
What does the cost look like once we are running on AWS?
For a typical API handling 1-5 million requests/month, expect £80-£300/month in AWS bills (Lambda + API Gateway + CloudWatch + Route 53). For higher traffic we move to API Gateway HTTP APIs (cheaper) or recommend a CloudFront caching layer in front. We will benchmark the unit economics during discovery so you know the run-rate before we start.
Will my mobile/web clients need to change anything?
No, by design. We preserve URL paths, request/response shapes, status codes, headers, and edge-case error semantics. Contract tests run against both the legacy and new APIs during the migration window to catch any drift before DNS flips. The cutover is invisible to your clients.
Can you sign an NDA?
Yes. We sign your NDA before any code or infrastructure access. If you would prefer, we can sign a mutual NDA we have already used on similar engagements.
Fixed price. Fixed scope. Six weeks.
No hourly rates, no scope creep, no surprise charges. If we under-estimate the work, that is our problem, not yours.
£15,000 plus VAT · up to 50 endpoints · one migration starts per month