A large-scale Plone 6 headless deployment for a Swiss canton
A high-traffic public-sector platform for the Canton of Basel-Landschaft, built on 7inOne — webcloud7's product on top of Plone 6 Classic, running as a headless backend with a decoupled frontend consuming the REST API. Built by webcloud7, a small Swiss web agency.
Goals and requirements: The customer is the Canton of Basel-Landschaft (baselland.ch), a Swiss canton. It's a large public-sector platform serving 500K–1M hits per day (peaking at ~2M), with 100K–350K Plone REST API requests daily. Around 300 staff users create and maintain the content. Migrate over 10'000 News Items from Plone 5.1 Our goal, as a small team under tight time-to-market pressure, was to launch our first major customer on a new Plone 6 product platform using a decoupled architecture: Plone 6 Classic as the backend/CMS, exposing all data via plone.restapi, with an independent frontend (built by a separate company) consuming that API. The backend was optimized purely for content authors, with no anonymous access to the Classic UI. The main requirements were: serve very high public traffic cost-effectively (solved by caching over 90% of requests through Cloudflare while keeping the uncached REST API fast, at a ~200–250ms 95th percentile); prepare for enterprise authentication via SAML2 for staff and CAS for admins; a content-entry-optimized editor experience with a custom block-based page builder, live frontend preview, map/GEOJSON editing, staging, a 30-day trash, and an internal review system; powerful search with Elasticsearch; an async tasks system with Redis; and reproducible, cloud-agnostic infrastructure on Kubernetes and Docker.
Development process: The project was delivered by a small team. webcloud7 built and owns the backend: all Plone code, add-ons, Docker images, services, and Cloudflare configuration were done by webcloud7. The Kubernetes cluster was implemented for us by Six Feet Up (Helm charts optimized for Exoscale but cloud-agnostic; we also tested on AWS, DigitalOcean, and Google). The frontend was built by a separate external company (around four people: two developers, one QA, and their CEO). On the customer side, our business partner and project manager handled coordination. Time-to-market was a critical constraint, so we deliberately built on Plone 6 Classic — the stack we knew best — rather than taking on Volto in parallel, which let us ship a quality product on schedule.
Outcome: Plone 6 Classic UI plus plone.restapi gave us a fully decoupled architecture: the backend stays close to the Plone standard and can be updated at any time, while the frontend remains completely independent. Because the backend serves authors only (no anonymous access to the Classic UI), we could optimize the entire editor experience without any frontend compromise. We cache over 90% of all requests through Cloudflare with targeted invalidation, which means we serve very high traffic on modest resources. On top of Plone we built and open-sourced several add-ons — wcs.samlauth (SAML2), wcs.adminauth (CAS), a configurable ReferenceWidget, and our own block-based page builder (wcs.simplelayout) — and contributed an async Redis/python-rq integration to collective.elasticsearch. Other features include a Leaflet/OpenStreetMap map widget storing GeoJSON, a working-copy/staging implementation, a 30-day trash/bin, an internal task/review system, and a live iframe preview of the frontend inside the Classic editor. The REST API and decoupling proved the model works at scale, and we're now rolling the same platform out to additional public-sector customers.
Numbers (some interesting stats about the website): - 500K–1M hits per 24h (peak ~2M) - 100K–350K Plone REST API requests per 24h. - More than 300 content authors. - Over 90% of requests cached via Cloudflare - 100% frontend availability since October 2024 - 10,000 news items migrated from Plone 5.1
Plone version: Plone 6 Classic
Industry: Government
"Plone 6 Classic with the REST API let us, as a small team, ship a large-scale headless platform under tight deadlines — close to Plone standard, fully decoupled, and easy to keep updated. We're now launching more customers on the same stack." — Mathias, webcloud7
Additional comments: A post with more technical details can be found here: https://community.plone.org/t/large-ish-plone-6-deployment-baselland-ch/20833
Provider information
webcloud7 ag
Mathias Leimgruber
m.leimgruber@webcloud7.ch
