Every tool the industry offers your legacy Java estate — recipe refactoring, AI version upgrades, container replatforming — answers the same question: how do we keep running this Java? Marcus, Kinetech's AI Mendix developer, answers the other one: it reads the Struts configs, Hibernate mappings, and security constraints your frameworks already wrote down, and rebuilds the applications — modern, tested per role, and proven with published evidence.
01 · The clock
Struts 1 reached end-of-life in April 2013 — and kept accumulating vulnerabilities anyway. In May 2025, CVE-2025-48734 (CVSS 8.8) made a Commons BeanUtils flaw reachable straight through Struts 1's core form-population mechanism. There's now a commercial market selling patched Struts 1 jars just to stand still — proof of how much of this is still running in production.
02 · The differentiator
Here's the irony of that era's frameworks: they forced developers to write the application's structure down in declarative files. The screen graph, the data model, the validation rules, the security matrix — it's all sitting in XML and annotations, waiting to be read.
| Java EE artifact | What Marcus extracts | Where it lands in Mendix |
|---|---|---|
| struts-config.xml / faces-config.xml | The complete screen-and-navigation graph — every action, form, and forward in one file | Pages and navigation structure |
| JSP pages / Facelets | Page inventory, layouts, tiles composition | Page designs on a modern responsive UI |
| Hibernate .hbm.xml / JPA annotations | The entire data model with associations, keys, and constraints | Domain-model entities and associations |
| validation.xml / ActionForms | Field-level validation rules per screen | Attribute validations and validation microflows |
| web.xml + LDAP realm roles | Security constraints — the full authorization matrix | User roles and entity access rules, SSO-connected |
| Session beans / DAOs | Business-logic units and their call graph | Microflows |
| Lost source | Java 8-era bytecode decompiles near-perfectly (CFR/Fernflower) — for code you own the rights to | Recovered specification, then a native rebuild |
Why this matters: refactoring tools upgrade the code you have. What has not existed is a developer that reads these artifacts and produces a new application — rebuilt, tested per role, documented, and delivered with evidence. That gap between "refactor the Java" and "rewrite by hand at SI prices" is exactly where Marcus works.
03 · How a migration runs
Your Java team will rewrite the flagship apps — that's the right call. The first deliverable here is a scored inventory of everything else: the departmental long tail no rewrite backlog will ever reach.
The same four approval gates that govern every Marcus engagement govern each migrated app — held by you:
The extracted specification of each app — screens, flows, rules, integrations — approved by you before a line of the model is written.
The translated security model — web.xml constraints and LDAP roles mapped to Mendix roles and access rules — presented in plain English for sign-off.
Modern, branded design directions presented before pages are generated. Your users leave the 2006 table-layout UI behind — you pick what they land on.
Each app reaches you only after all quality gates pass; it cuts over only when you accept it, evidence in hand.
04 · The date
Here is the commitment we will put in writing. The assessment does not end with a range — it ends with a date, sized from your actual extracted complexity. Miss that date and the assessment fee comes back. We can promise a date because we never quote a calendar before reading your source.
The assessment names the date. Miss it, and the assessment fee comes back.
That is a real term, not a slide. It is affordable to us for one reason: the clock below starts only when a complete artifact pack is in our hands, and it pauses only for your own approval gates.
| One Java EE application or module | Complete artifact pack → UAT-ready |
|---|---|
| Compact — single WAR, ≤40 JSP or JSF views, ≤3 integrations | 4–5 weeks |
| Departmental — EAR with an EJB tier, 40–120 views, 3–6 integrations | ~60 days typical |
| Load-bearing — multi-module EAR, JMS and MDB messaging, app-server-specific features, 100k+ lines | 12–20 weeks |
| Each further module in the same estate | 30–40% faster |
Sizing model, not a price list — the assessment reads your actual source and returns one date. Bands assume a single rebuild boundary agreed at the scope gate.
The date is only honest if the inputs are complete, so here is the whole list up front. Nothing on it is unusual, and most of it exists already.
Three approval gates are yours: scope, permission ratification, design sign-off. We answer each within three business days. Time beyond that on your side moves the date by exactly that much — and nothing else does.
Production cutover on your change calendar. SSO and network provisioning by your IT. Third-party licenses or vendor contracts we don't control. Remediation of source-data quality problems the assessment flagged. Anything added after the scope gate.
Functional parity against the approved specification, running on your migrated data in a parallel environment, with production security enforced and tested per role, all nine quality gates green, and documentation published. Your users click through it.
Java EE source is readable, and the Mendix runtime is itself Java, so nothing here is exotic. These take longer than the platform decks for size and coupling, not difficulty: an EAR is usually several applications wearing one name, and the messaging and app-server surface has to be re-homed deliberately. The assessment's first job is to draw the rebuild boundary — which module, not which system.
05 · Why Mendix
Here's the part your ops team will appreciate: the Mendix Runtime is itself a Java application. This isn't a leap to an alien stack — it's the same JVM operational world your team already runs, with the application layer modernized above it.
06 · Straight talk
| Area | The honest position |
|---|---|
| Your database | Stays. The SQL schema behind these apps is typically sound — Mendix maps to it, or migrates it cleanly, per app. Old and new can run against the same data during cutover. |
| High-scale public sites | Not the pitch. Customer-facing systems at serious scale belong in code, and the assessment marks them "keep in code" — integrated via REST, not rebuilt. |
| Batch, ETL & middleware | Message-driven beans, integration flows, and nightly batch aren't applications — they're plumbing. They stay in code or move to purpose-built tools; we'll say which, per item. |
| SPA frontends someone loves | If a team already modernized an app's frontend, leave it alone. The assessment targets the untouched Struts/JSF tail, not working modern code. |
| Licensing math | Mendix per-user pricing can exceed the status quo for very large user counts — we'll show the comparison against the full cost of staying: S&S plus Java subscription plus the CVE exposure your auditors keep flagging. |
| Latency-critical paths | Departmental form-submit CRUD is comfortably in range. Genuinely high-throughput or latency-critical systems are disqualified honestly in the assessment. |
07 · Quality & security
Watch real build evidence land on the live Build Console, and see the delivery lifecycle at our interactive explainer.
08 · Engagement & pricing
Pick one Struts or JSF app. Marcus extracts its screens, navigation flows, entities, validation rules, roles, and logic map — and returns the specification plus a fixed-bid rebuild quote. Judge the extraction on your own code.
Credited toward onboarding if you proceed.
Each app quoted from its actual extracted complexity — not a day-rate guess. Built, tested per role, documented, and delivered through the approval gates with published evidence.
Best for a first wave of 3–10 apps.
For 20+ apps on the app-server estate: a Marcus instance works your migration backlog continuously. Priced on what the work is, how many lanes run in parallel, and how fast you need it — always with Kinetech engineer review and an escalation SLA.
Bring your own Claude access: roughly 15–25% off the monthly.
Every figure here is an indicative range; your actual range is confirmed in writing before anything is charged. On bundled plans, heavy build months may incur metered usage beyond the included allowance; your quote states the allowance plainly. Your applications, models, and repositories are contractually yours.
09 · The questions you should ask
For your three flagship apps — absolutely, and they should. Now do the math on the other forty: each hand rewrite re-implements UI, validation, and security from scratch, and your team's backlog for that is measured in years, not quarters. The departmental long tail is precisely the work that never makes it above the line. Marcus attacks that tail while your best people do the work that deserves them.
Use it — genuinely. OpenRewrite is excellent at javax→jakarta, Spring upgrades, and Java version bumps: it upgrades the code you have. What it cannot do is produce a modern UI, a workflow engine, or mobile support from a Struts Action; framework-to-framework UI conversion is explicitly outside its scope. After it runs, you're maintaining the same 2005 architecture on a newer runtime — with the same shrinking pool of people who understand it.
The licenses were an asset; the S&S is an annuity. You're not preserving an investment by continuing to pay support on a 2012-era runtime — you're renting the past at compounding prices, with Oracle's per-employee Java subscription stacked on top. Every app that migrates shrinks both bills. The sunk cost argues for leaving, not staying.
For what these apps actually do — form-submit CRUD and workflow at departmental request rates — comfortably; a Mendix JVM handles that load without drama and scales horizontally in ways a WAS-bound app doesn't. Where an app has genuinely high-throughput or latency-critical paths, we'll say so in the assessment and recommend it stay in code. We'd rather lose that line item than pretend.
More common than anyone admits. Java 8-era bytecode decompiles near-perfectly with standard tools — no lambdas gymnastics, rarely obfuscated — so the specification can be recovered from the binaries you're running, provided you own the rights to them. Recovered spec, then a native rebuild: same gated process, same evidence.
It's a fair frame, so compare the exits. Exiting the status quo means paying S&S and Java subscriptions forever on an architecture nobody will hire for. Exiting Mendix means standard SQL data, documented visual models, REST APIs, and a platform any Mendix partner supports — with your test suites and docs included. Both are commitments; only one of them is a commitment to 2005.
They're the easiest part to get right, because they're written down: web.xml security constraints and realm role mappings are the authorization matrix. Marcus translates them to Mendix roles and entity access rules, you ratify the model in plain English before build, and per-role journeys — including negative tests — prove enforcement in the delivered evidence. Your SSO connects via the standard protocols.
10 · Next step
Pick a Struts app your security scanner keeps flagging, a JSF app whose author left, and the one still holding a business process hostage. We'll run the extraction and return the scored specs — screens, flows, entities, roles, and a fixed price to rebuild each — inside two weeks. Judge the approach on your own code, not on a slide.
Marc Lehane · Solutions Architect / CTO, Kinetech · [email protected]
Kinetech Cloud · San Antonio, TX · How we deliver · Live Build Console
You are reading Your platform — deeper detail on step 4, Why now?.
That is the pressure. What it costs to answer it is not one number — three things move it.