Context

At Inserm I worked as Solutions Architect and Tech Lead through Inventiv IT (2025 – 2026, Paris). The assignment was to design and implement a company-wide software factory for 12 teams: a common way to build, test and ship software that standardises CI/CD pipelines, improves code quality and reduces delivery times. The toolchain combines GitLab Enterprise, Nexus, SonarQube, Kubernetes and Ansible, and it handles HDS-compliant data (the French health-data hosting requirements).

Problem

Twelve teams building software independently tend to end up with twelve ways of building, testing and releasing it. Quality becomes uneven, delivery slows down, and compliance is hard to demonstrate, especially when the data is regulated. A software factory replaces that variation with one paved road that teams choose because it is easier than building their own.

Architecture decisions

One standardised pipeline model for every team

The CI/CD pipelines were standardised across the 12 teams, so a project joins an existing model instead of inventing its own. The result is automated CI/CD for 40+ projects.

Trade-off: a shared model constrains teams that want something different. Keeping the standard small and focused on the common path keeps exceptions rare and visible.

Quality gates as part of the toolchain

The toolchain includes SonarQube for code-quality analysis, and improving code quality was one of the goals of the standardisation. Making analysis a default part of the pipeline turns quality from an optional review into a routine check.

Trade-off: gates that fail builds add friction and need sensible thresholds. They work when they block real problems rather than generate noise.

Artifact management with Nexus

Nexus is part of the toolchain as the artifact repository, giving every team one place for build artifacts and dependencies.

Trade-off: a central repository is a shared dependency, so its availability and access rules matter for every team’s builds.

Kubernetes and Ansible industrialisation

Kubernetes and Ansible were used to industrialise deployments and operations, which reduced manual interventions by 50%.

Trade-off: automation moves effort from repeated manual work to maintaining the automation itself. It pays off when the same operation recurs across many projects, which is exactly the situation with dozens of them.

Compliance built into the platform

The pipelines were automated for 40+ projects with HDS compliance. Encoding the compliance requirements once in the platform is cheaper and more reliable than asking each project to prove them separately.

Trade-off: compliance constraints limit tool and hosting choices. Absorbing them in the platform means individual teams do not have to carry that limit themselves.

Outcome

CI/CD is automated for 40+ projects across 12 teams, with HDS compliance built in. The Kubernetes and Ansible industrialisation reduced manual interventions by 50%, code quality improved, and delivery times were reduced.

Stack

  • GitLab Enterprise
  • Nexus
  • SonarQube
  • Kubernetes
  • Ansible
  • HDS-compliant environments