Coinbase Migrates 300+ Namespaces to Temporal Cloud
Coinbase has successfully migrated over 300 namespaces from a self-hosted Temporal cluster to Temporal Cloud, a significant undertaking for the company's infrastructure. The migration was a complex process, involving multiple phases and careful planning to minimize downtime and ensure a smooth transition. In a blog post, Coinbase explained the challenges and strategies employed during the migration, highlighting the importance of a gradual rollout and the need for a rollback path at every stage.
The company's original Temporal cluster was a shared instance, which led to scalability and performance issues as more teams adopted the platform. To address these challenges, Coinbase built a custom persistence layer, but this added to the operational load and made upgrades slow. Furthermore, the company faced security and compliance concerns, requiring stronger service identity, tighter access control, and encrypted workflow payloads.
The migration process involved two phases. First, Coinbase moved namespaces from the custom self-hosted stack to open-source Temporal backed by Aurora, still operated by the company. This phase served as a staging ground for testing migration patterns, dashboards, and rollback procedures. The second phase involved moving from Aurora to Temporal Cloud, which reused nearly all of the previously developed infrastructure.
One of the key considerations during the migration was securing the connection between services and Temporal Cloud. Coinbase implemented private connectivity using AWS PrivateLink, ensuring that no traffic crossed the public internet. Temporal Cloud authenticates clients using mTLS, and the company configured certificate filters for each namespace to control access. Additionally, Coinbase built a Temporal Admin service to wrap privileged workflow operations with an approval step and a change log.