---
title: VM Application Migration with Controlled Cutover
description: "Template runbook for migrating an application with VM runtime to STACKIT with clear prerequisites, cutover governance, and defined rollback boundaries."
sidebar:
  badge:
    text: "STACKIT"
    variant: success
scfAsset:
  managed: false
  category: "runbook"
  external: false
  tags: ["design-and-mobilize", "use-cases", "app-stack", "rehost", "vm"]
  maintainers:
    - user: "lukas.weberruss"
      role: true
      website: true
source_url: "https://framework.stackit.cloud/migration/assetcontainer/stackit/runbook-vm-app-rehost-cutover/"
source_file: "docs/migration/assetcontainer/stackit/runbook-vm-app-rehost-cutover.mdx"
---

## Use case

- **Category**: Application stack migration
- **Typical source**: Existing VM-based runtime
- **Typical target**: VM runtime on STACKIT with standardized operations handover

## Prerequisites

- **Dependency map completed**: Interfaces, schedules, and critical upstream/downstream systems are documented.
- **Landing zone readiness**: Network, IAM, monitoring, backup, and logging controls are available.
- **Cutover governance**: Approved window, freeze rules, and business sign-off path are defined.
- **Rollback readiness**: Source restore path and technical rollback trigger are tested.

## Not suitable when

- **Heavy redesign is required**: Significant architecture changes are expected in the same wave.
- **No rollback option exists**: Source cannot be kept stable for fallback during cutover.

## Implementation template

### Phase 1: Prepare target runtime

1. Provision target VM baseline and apply security controls.
2. Install runtime dependencies and deploy the application artifact.
3. Configure environment, certificates, and endpoint integration.
4. Validate observability baseline (metrics, logs, alerts).

### Phase 2: Align data and configuration

1. Freeze non-essential writes on the source.
2. Run final data synchronization.
3. Validate integrity and application readiness on target.

### Phase 3: Run cutover

1. Stop source service according to cutover governance.
2. Activate target service and verify health checks.
3. Activate the approved target endpoint or traffic path and run business-critical validation.
4. Start stabilization watch and complete evidence log.

## Validation checklist

- **Functional readiness**: Core user journeys pass.
- **Data readiness**: Consistency checks meet acceptance criteria.
- **Security readiness**: Access controls and TLS chain verified.
- **Operations readiness**: Runbook, alerts, and escalation ownership confirmed.

## Evidence template

| Checkpoint               | Owner | Result    | Evidence |
| ------------------------ | ----- | --------- | -------- |
| Target runtime ready     |       | Pass/Fail |          |
| Data sync validated      |       | Pass/Fail |          |
| Traffic switch completed |       | Pass/Fail |          |
| Stabilization accepted   |       | Pass/Fail |          |
