AWS Public Sector Blog

State of Kansas modernizes mainframe file transfer using AWS Transfer Family

State of Kansas modernizes mainframe file transfer using AWS Transfer Family

Government agencies face a persistent challenge: how do you modernize aging infrastructure while maintaining operational continuity and meeting strict security requirements? The State of Kansas, through its Department of Administration’s Office of Systems Management (OSM), answered that question by migrating from a legacy IBM Mainframe-based file transfer system to a modern, cloud-based solution built on Amazon Web Services (AWS).

In this post, we walk through how OSM partnered with Sierra-Cedar, an AWS Premier Consulting Partner, to design, build, and deploy FileVault—a secure file transfer solution powered by AWS Transfer Family and Amazon Simple Storage Service (Amazon S3)—while preserving the user experience that state employees already knew and trusted.

The challenge: Moving beyond legacy infrastructure

For years, the State of Kansas relied on an IBM Mainframe-based platform for secure file transfers across state agencies. Though functional, this system presented growing challenges:

  1. Costly, rigid infrastructure – The aging mainframe was difficult to maintain, with limited scalability to accommodate the state’s evolving needs
  2. Fragmented tooling – Multiple third-party FTP tools created inconsistent user experiences and increased licensing overhead
  3. Integration friction – Complex integration requirements with modern applications such as PeopleSoft hindered operational efficiency and slowed digital transformation efforts

As the state’s modernization agenda accelerated, OSM recognized the need for a unified solution that could deliver cloud-scale benefits without disrupting the workflows state employees depended on every day.

The solution: FileVault on AWS

Working with Sierra-Cedar, OSM developed FileVault—a secure, cloud-based file transfer solution built on Transfer Family. The solution provides SSH FTP (SFTP) access to files stored in Amazon S3 while maintaining the familiar Multiple Virtual Storage (MVS)-style file naming conventions that users had relied on for years.

Solution overview

The FileVault architecture, as illustrated in the following diagram, demonstrates how multiple AWS services work together to create a secure, scalable file transfer solution that meets government requirements while providing a familiar user experience.

Figure 1 FileVault architecture

Figure 1: FileVault architecture. The solution uses AWS Transfer Family for SFTP access, Amazon S3 for durable storage, and integrates seamlessly with the state’s existing PeopleSoft environment.

The following sections describe each architectural layer.

Secure connectivity

AWS Transfer Family provides SFTP protocol support, deployed across three Availability Zones for high availability. External users and state agencies connect using SFTP to Elastic IP addresses, with traffic flowing through security groups that restrict access based on IP allowlisting. Using VPC endpoints—resources within Amazon Virtual Private Cloud (Amazon VPC)—means traffic to Transfer Family remains within the AWS private network, never traversing the public internet.

Durable, policy-driven storage

Amazon S3 serves as the storage foundation with a versioned bucket implementation that maintains complete file history. Custom retention policies are mapped to file naming conventions, allowing the state to preserve their familiar MVS-style dataset naming structure. This design decision was critical for user adoption: staff could continue working with file structures they understood while benefiting from the durability, scalability, and cost-efficiency of cloud-based storage.

Authentication and access control

The authentication system follows a structured approach that balances security with usability:

  1. User provisioning – SFTP users are created and managed through CSV files maintained by the State of Kansas
  2. Identity mapping – User definitions and SSH public keys are mapped to AWS Identity and Access Management (IAM) roles through a Transfer Family managed identity provider
  3. Connection validation – When users connect using SFTP, the system validates their SSH key and maps the authenticated user to the appropriate IAM role
  4. Fine-grained authorization – The IAM role determines which files and prefixes the user can access within the S3 bucket

This layered approach provides access controls aligned with least-privilege principles without adding complexity to the end-user experience.

PeopleSoft integration

A critical success factor was seamless integration with the state’s existing PeopleSoft environment. Sierra-Cedar developed custom components that bridged FileVault and PeopleSoft through multiple access patterns:

  1. Browser-based access – Authorized users can upload and download files through a familiar PeopleSoft interface, with no specialized SFTP client software required
  2. Application-level automation – Custom PeopleCode handles direct SFTP interactions for programmatic file transfers
  3. Direct mount access – Select PeopleSoft application servers mount the S3 bucket directly to support file listing and access requirements

This multi-layered integration approach meant users could access FileVault through the interface that best suited their workflow—whether browser-based access through PeopleSoft or traditional SFTP clients. The flexibility reduced training requirements and accelerated adoption across state agencies.

Implementation approach: Phased and validated

OSM adopted a deliberate, phased rollout strategy that prioritized validation and user confidence at every step:

  • Pilot deployment – Initial rollout with the Department of Administration to validate core functionality
  • Parallel operation – Both legacy and new systems operated simultaneously during a redundant transfer period, helping teams compare results side by side
  • Data integrity validation – The state verified that all file transfers completed successfully and users could access files as expected
  • Planned expansion – Only after successful validation did OSM proceed with onboarding additional state agencies

This parallel-run approach minimized risk while building organizational confidence in the new solution—a pattern well suited to government environments where continuity is non-negotiable.

Customer perspective

“The FileVault migration from MVS on our IBM mainframe to Amazon S3 was a huge success,” says Josh White, Chief Information Officer at the State of Kansas Department of Administration. “It enhanced our data distribution capabilities, achieving significant improvements in scalability and integration while utilizing the full features of the AWS platform. Our partnership with Sierra-Cedar and AWS was crucial, as their experience helped us migrate and provide a platform that allows us to grow in the future.”

Measurable outcomes

The FileVault migration delivered benefits across four key dimensions:

Operational efficiency:

  • Standardized processes – Consolidating multiple third-party FTP solutions into a single architecture reduced support demands and simplified administration
  • Lower licensing costs – Retiring redundant tools avoided ongoing licensing overhead

Security and compliance:

  • Stronger authentication – SSH key-pair authentication replaced less secure methods, and IAM-based access control enforces least-privilege principles
  • IP-based restrictions – Allowlisting authorized source IPs provides an additional layer of network-level protection
  • Comprehensive auditability – Consistent access controls and centralized logging improved the state’s compliance and security posture

User experience:

  • Minimal disruption – Preserved MVS-style naming conventions and PeopleSoft integration meant users could continue working with familiar workflows
  • Simplified access – Browser-based file transfer alleviated the need for specialized client software
  • Faster onboarding – Intuitive interface design reduced training requirements across agencies

Future-ready infrastructure:

  • Scalable foundation – The architecture is ready to onboard additional state agencies with minimal incremental effort
  • Rapid iteration – Cloud-based design enables new feature additions and improvements without infrastructure constraints
  • Improved cost efficiency – Managed AWS services free up budget and staff resources for other modernization initiatives

Looking ahead

With FileVault successfully deployed for the Department of Administration, OSM is positioned to expand the architecture across additional state agencies. The scalable AWS architecture provides a foundation for ongoing digital transformation—enabling the State of Kansas to deliver better services to its 2.9 million residents while maintaining the security and reliability that government operations demand.

Conclusion

The FileVault project demonstrates that government agencies can successfully modernize legacy systems without sacrificing operational continuity or security. By thoughtfully combining AWS Cloud services with careful change management and a phased rollout strategy, the State of Kansas has created a repeatable model for public sector digital transformation.

To learn more, visit the following resources:

To learn how AWS can help your agency modernize legacy file transfer infrastructure, contact the AWS Public Sector team.

Murty Chappidi

Murty Chappidi

Murty Chappidi is a Senior Solutions Architect at AWS, where he leads technology strategy for systems integrator partners serving U.S. Public Sector. With 30 years in enterprise technology and financial services, he now drives agentic AI adoption through AWS partners to transform government, education, and healthcare. Outside of work, Murty catches sunsets on his e-bike along the San Diego coastline.

Chakri Velvadapu

Chakri Velvadapu

Chakri Velvadapu is a Sr. Director of Cloud Engineering at Sierra-Cedar with deep expertise in cloud architecture, cost optimization, and governance. He excels at building and leading architecture and DevOps teams and specializes in AI-driven solutions that help customers modernize and maximize the value of their cloud investments. Outside of work, Chakri enjoys riding motorcycles.

John Stephens

John Stephens

John Stephens is a Senior Solutions Architect at AWS supporting state and local government agencies across Kansas and Missouri. He helps public sector organizations modernize legacy infrastructure and adopt cloud technologies that improve security, scalability, and operational efficiency. With more than 20 years of software development and architecture experience, John partners closely with agencies to deliver practical, mission-focused solutions.

Tracy Gullett

Tracy Gullett

Tracy Gullett is a retired Cloud Solutions Architect at Sierra-Cedar specializing in highly available and scalable architecture, cloud security, DevOps, and automation. Over his career, he helped customers design resilient, secure cloud environments and automate operations to run reliably at scale. He is passionate about applying best practices that keep systems dependable. In retirement, Tracy enjoys traveling across the US in his RV.