Speaker
Abstract
If you've made a bank transfer recently, there's a good chance that Form3 handled it. When we have a wobble, people notice. So when the UK's payments regulator said they were worried about cloud concentration risk, we knew we had a challenge ahead: we needed to keep running when our cloud provider failed. What followed was a company-wide effort to unpick our cloud-specific dependencies and replace them with a cloud-agnostic active/active/active architecture spanning AWS, GCP, and Azure. We'll break down the design trade-offs, operational costs, dead-ends, and hard slog needed to build this platform. We'll share what we've learned from the experience of several years' operation, and what really happens when a cloud falls over.
On the other side of the pond, we'll look at how we needed to adapt this multi-cloud architecture to a new market. We quickly learned that dominant perceptions in the US would prevent us from lifting and shift our solution from the UK, so we had to re-evaluate our choices and ultimately take a step backward to achieve market fit. We'll look at the power of 'resilience stories', how we architected to address them, and how we handled our first major incident without the comfort of active/active/active multi-cloud.
Key Takeaways:
- How to run real-world active/active/active multi-cloud
- When to lean on cloud's hosted offerings, and when to stay agnostic
- How to adapt architecture to fit resilience narratives
Interview
Kev and I are sharing details about Form3's journey to multi-cloud. We'll talk about the practical work required to run active/active/active, and what we've learned along the way. Multi-cloud is awesome tech, but it doesn't necessarily fit everywhere, so we'll also be looking at how we took a different approach when we launched in the US last year.
Running on three clouds at once might seem a bit extreme, but we feel that customers and regulators are becoming less tolerant of the idea that we all fall over when one cloud has a wobble. This talk should give senior engineers and architects an idea if multi-cloud is really for them and, if so, how to actually make it happen.
We've seen all the major cloud providers have outages recently, and I don't think there's any sign of those going away. For those of us in critical domains, where we can't afford to stop and wait for a cloud to recover, we need a concrete plan to isolate ourselves from these inevitable events and keep running.
The big one is decoupling an application from cloud-specific dependencies. Depending on your existing architecture, that might need some sweeping changes. Then, there are the operational headaches of dealing with fleets of machines across multiple clouds, in dev/test/production environments. Just rolling out an operating system patch can be a pain without the right tooling. We're fortunate to have a great Platform team at Form3, but I imagine lots of other organisations would struggle to support the kind of platform engineering needed to make these shifts and still allow the rest of the engineering team to keep moving.
I hope they'll embrace being cloud-agnostic. Even if you're not running multi-cloud, not depending on a high-value-add managed service vastly improves your chances of survival when a CSP's control plane is misbehaving.
I came last year and the quality of talks, questions, and just conversations was excellent. There's no sales pressure anywhere. It just feels like a bunch of smart, experienced people genuinely exchanging ideas about how to grow and adapt in the industry.
I had a great chat about 'Resilience Stories' during one of the unconference sessions that has stayed with me, and has become a component of this talk. The way that we think about resilience is in part cultural, and the best solution for one market won't work everywhere.
Topics
QCon London 2026 is a three day conference for senior software engineers, architects and team leads. An international program committee of working engineers selects every session. Patterns and practices, not products and pitches.
From the same track
Monday 16 March
10:35 Mountbatten (6th Fl.) Session architecture How To Run on Three Clouds at Once, and When Not To Ross McFarlane, Kevin Holditch If you've made a bank transfer recently, there's a good chance that Form3 handled it. When we have a wobble, people notice. 11:45 Windsor (5th Fl.) Session AI/ML Your Multicloud Strategy Is a Product Problem - Treat It Like One Luis Henrique Albinati Junior, Surabhi Mahajan You can't really "opt out" of multicloud anymore. Between cloud concentration risk, SaaS sprawl, and increasing regulatory expectations, most enterprises end up operating across multiple clouds whether they planned to or not. The hard part isn't having two or three providers. 13:35 Rutherford (4th Fl.) Unconference Unconference: Tech of Finance Industry 14:45 Mountbatten (6th Fl.) Session Alpha Copilot The Realities of Building an AI Native Fintech Startup David Lin Founder and CEO @Linvest21, Previously CTO @JPMorgan For fifty years, $400 trillion in professionally managed assets sat untouched by external technology. The most analytically demanding investment workflows required a combination of PhD-level quant finance and advanced engineering that no outside vendor could sustain commercially. 15:55 Mountbatten (6th Fl.) Session Platform Engineering Move Fast, Don’t Break Trust: Shipping Constantly with Humans and Beyond Suhail Patel Senior Staff Engineer @Monzo Leading the Platform and Data Functions, Previously @Citymapper Moving fast only works if your systems are engineered with trust and verification in mind. In this talk, we showcase how teams can scale to the point where shipping hundreds of changes a day becomes boring, routine, and safe.