Kinetech · MARCUS — Managed Agent Resource Constructing Unbelievable Software

Those Struts apps aren't going to rewrite themselves. Nobody else is rewriting them either.

Every tool the industry offers your legacy Java estate — recipe refactoring, AI version upgrades, container replatforming — answers the same question: how do we keep running this Java? Marcus, Kinetech's AI Mendix developer, answers the other one: it reads the Struts configs, Hibernate mappings, and security constraints your frameworks already wrote down, and rebuilds the applications — modern, tested per role, and proven with published evidence.

01 · The clock

A 2005 architecture, billed at 2026 prices

Struts 1 reached end-of-life in April 2013 — and kept accumulating vulnerabilities anyway. In May 2025, CVE-2025-48734 (CVSS 8.8) made a Commons BeanUtils flaw reachable straight through Struts 1's core form-population mechanism. There's now a commercial market selling patched Struts 1 jars just to stand still — proof of how much of this is still running in production.

2013
Struts 1 end-of-life — with critical CVEs still landing against it in 2025
Dec 2026
WebLogic 12.2.1.4 Premier Support ends; Extended ends Dec 2027, per Oracle's lifetime support policy
~29%
of production apps still run Java 8 — New Relic's 2024 ecosystem report
2–10×
documented Java bill increases under Oracle's 2023 per-employee subscription pricing

02 · The differentiator

Marcus reads your Java estate directly

Here's the irony of that era's frameworks: they forced developers to write the application's structure down in declarative files. The screen graph, the data model, the validation rules, the security matrix — it's all sitting in XML and annotations, waiting to be read.

Java EE artifactWhat Marcus extractsWhere it lands in Mendix
struts-config.xml / faces-config.xmlThe complete screen-and-navigation graph — every action, form, and forward in one filePages and navigation structure
JSP pages / FaceletsPage inventory, layouts, tiles compositionPage designs on a modern responsive UI
Hibernate .hbm.xml / JPA annotationsThe entire data model with associations, keys, and constraintsDomain-model entities and associations
validation.xml / ActionFormsField-level validation rules per screenAttribute validations and validation microflows
web.xml + LDAP realm rolesSecurity constraints — the full authorization matrixUser roles and entity access rules, SSO-connected
Session beans / DAOsBusiness-logic units and their call graphMicroflows
Lost sourceJava 8-era bytecode decompiles near-perfectly (CFR/Fernflower) — for code you own the rights toRecovered specification, then a native rebuild

Why this matters: refactoring tools upgrade the code you have. What has not existed is a developer that reads these artifacts and produces a new application — rebuilt, tested per role, documented, and delivered with evidence. That gap between "refactor the Java" and "rewrite by hand at SI prices" is exactly where Marcus works.

03 · How a migration runs

Inventory the estate. Rebuild the long tail. Prove every step.

Your Java team will rewrite the flagship apps — that's the right call. The first deliverable here is a scored inventory of everything else: the departmental long tail no rewrite backlog will ever reach.

The same four approval gates that govern every Marcus engagement govern each migrated app — held by you:

Gate

Scope approval

The extracted specification of each app — screens, flows, rules, integrations — approved by you before a line of the model is written.

Gate

Permission ratification

The translated security model — web.xml constraints and LDAP roles mapped to Mendix roles and access rules — presented in plain English for sign-off.

Gate

Design sign-off

Modern, branded design directions presented before pages are generated. Your users leave the 2006 table-layout UI behind — you pick what they land on.

Gate

Release acceptance

Each app reaches you only after all quality gates pass; it cuts over only when you accept it, evidence in hand.

04 · The date

Hand over the repository. Sixty days to a running Mendix app for a typical Java EE module.

Here is the commitment we will put in writing. The assessment does not end with a range — it ends with a date, sized from your actual extracted complexity. Miss that date and the assessment fee comes back. We can promise a date because we never quote a calendar before reading your source.

The assessment names the date. Miss it, and the assessment fee comes back.

That is a real term, not a slide. It is affordable to us for one reason: the clock below starts only when a complete artifact pack is in our hands, and it pauses only for your own approval gates.

How the date gets sized

One Java EE application or moduleComplete artifact pack → UAT-ready
Compact — single WAR, ≤40 JSP or JSF views, ≤3 integrations4–5 weeks
Departmental — EAR with an EJB tier, 40–120 views, 3–6 integrations~60 days typical
Load-bearing — multi-module EAR, JMS and MDB messaging, app-server-specific features, 100k+ lines12–20 weeks
Each further module in the same estate30–40% faster

Sizing model, not a price list — the assessment reads your actual source and returns one date. Bands assume a single rebuild boundary agreed at the scope gate.

What starts the clock

The date is only honest if the inputs are complete, so here is the whole list up front. Nothing on it is unusual, and most of it exists already.

What pauses it

Your gates, at your pace

Three approval gates are yours: scope, permission ratification, design sign-off. We answer each within three business days. Time beyond that on your side moves the date by exactly that much — and nothing else does.

What is outside it

Things we don't control

Production cutover on your change calendar. SSO and network provisioning by your IT. Third-party licenses or vendor contracts we don't control. Remediation of source-data quality problems the assessment flagged. Anything added after the scope gate.

The finish line

What "UAT-ready" means

Functional parity against the approved specification, running on your migrated data in a parallel environment, with production security enforced and tested per role, all nine quality gates green, and documentation published. Your users click through it.

What actually moves a date

Java EE source is readable, and the Mendix runtime is itself Java, so nothing here is exotic. These take longer than the platform decks for size and coupling, not difficulty: an EAR is usually several applications wearing one name, and the messaging and app-server surface has to be re-homed deliberately. The assessment's first job is to draw the rebuild boundary — which module, not which system.

05 · Why Mendix

Still a JVM. Minus two vendor bills.

Here's the part your ops team will appreciate: the Mendix Runtime is itself a Java application. This isn't a leap to an alien stack — it's the same JVM operational world your team already runs, with the application layer modernized above it.

06 · Straight talk

What transfers, what changes, what we won't pretend

AreaThe honest position
Your databaseStays. The SQL schema behind these apps is typically sound — Mendix maps to it, or migrates it cleanly, per app. Old and new can run against the same data during cutover.
High-scale public sitesNot the pitch. Customer-facing systems at serious scale belong in code, and the assessment marks them "keep in code" — integrated via REST, not rebuilt.
Batch, ETL & middlewareMessage-driven beans, integration flows, and nightly batch aren't applications — they're plumbing. They stay in code or move to purpose-built tools; we'll say which, per item.
SPA frontends someone lovesIf a team already modernized an app's frontend, leave it alone. The assessment targets the untouched Struts/JSF tail, not working modern code.
Licensing mathMendix per-user pricing can exceed the status quo for very large user counts — we'll show the comparison against the full cost of staying: S&S plus Java subscription plus the CVE exposure your auditors keep flagging.
Latency-critical pathsDepartmental form-submit CRUD is comfortably in range. Genuinely high-throughput or latency-critical systems are disqualified honestly in the assessment.

07 · Quality & security

Every migrated app ships with evidence

Watch real build evidence land on the live Build Console, and see the delivery lifecycle at our interactive explainer.

08 · Engagement & pricing

Start with one app's X-Ray. Scale by the estate.

Step 1 · Legacy X-Ray

$6,000–$12,000

Pick one Struts or JSF app. Marcus extracts its screens, navigation flows, entities, validation rules, roles, and logic map — and returns the specification plus a fixed-bid rebuild quote. Judge the extraction on your own code.

Credited toward onboarding if you proceed.

Step 2 · Delivered rebuilds

Fixed bid per app

Each app quoted from its actual extracted complexity — not a day-rate guess. Built, tested per role, documented, and delivered through the approval gates with published evidence.

Best for a first wave of 3–10 apps.

Estate scale · Most popular

Dedicated Marcus instance

For 20+ apps on the app-server estate: a Marcus instance works your migration backlog continuously. Priced on what the work is, how many lanes run in parallel, and how fast you need it — always with Kinetech engineer review and an escalation SLA.

Bring your own Claude access: roughly 15–25% off the monthly.

Every figure here is an indicative range; your actual range is confirmed in writing before anything is charged. On bundled plans, heavy build months may incur metered usage beyond the included allowance; your quote states the allowance plainly. Your applications, models, and repositories are contractually yours.

09 · The questions you should ask

Fair pushback, straight answers

We have Java developers. They'll rewrite these in Spring Boot.

For your three flagship apps — absolutely, and they should. Now do the math on the other forty: each hand rewrite re-implements UI, validation, and security from scratch, and your team's backlog for that is measured in years, not quarters. The departmental long tail is precisely the work that never makes it above the line. Marcus attacks that tail while your best people do the work that deserves them.

OpenRewrite is free. Why pay for a migration?

Use it — genuinely. OpenRewrite is excellent at javax→jakarta, Spring upgrades, and Java version bumps: it upgrades the code you have. What it cannot do is produce a modern UI, a workflow engine, or mobile support from a Struts Action; framework-to-framework UI conversion is explicitly outside its scope. After it runs, you're maintaining the same 2005 architecture on a newer runtime — with the same shrinking pool of people who understand it.

We've paid for WebSphere/WebLogic for fifteen years. Walking away wastes that investment.

The licenses were an asset; the S&S is an annuity. You're not preserving an investment by continuing to pay support on a 2012-era runtime — you're renting the past at compounding prices, with Oracle's per-employee Java subscription stacked on top. Every app that migrates shrinks both bills. The sunk cost argues for leaving, not staying.

Can Mendix match our performance?

For what these apps actually do — form-submit CRUD and workflow at departmental request rates — comfortably; a Mendix JVM handles that load without drama and scales horizontally in ways a WAS-bound app doesn't. Where an app has genuinely high-throughput or latency-critical paths, we'll say so in the assessment and recommend it stay in code. We'd rather lose that line item than pretend.

Some of these apps have no source code anymore.

More common than anyone admits. Java 8-era bytecode decompiles near-perfectly with standard tools — no lambdas gymnastics, rarely obfuscated — so the specification can be recovered from the binaries you're running, provided you own the rights to them. Recovered spec, then a native rebuild: same gated process, same evidence.

Isn't low-code just another lock-in — trading Oracle for Mendix?

It's a fair frame, so compare the exits. Exiting the status quo means paying S&S and Java subscriptions forever on an architecture nobody will hire for. Exiting Mendix means standard SQL data, documented visual models, REST APIs, and a platform any Mendix partner supports — with your test suites and docs included. Both are commitments; only one of them is a commitment to 2005.

Our security team will ask: what happens to the LDAP roles and access rules?

They're the easiest part to get right, because they're written down: web.xml security constraints and realm role mappings are the authorization matrix. Marcus translates them to Mendix roles and entity access rules, you ratify the model in plain English before build, and per-role journeys — including negative tests — prove enforcement in the delivered evidence. Your SSO connects via the standard protocols.

10 · Next step

Give us your three most stranded apps

Pick a Struts app your security scanner keeps flagging, a JSF app whose author left, and the one still holding a business process hostage. We'll run the extraction and return the scored specs — screens, flows, entities, roles, and a fixed price to rebuild each — inside two weeks. Judge the approach on your own code, not on a slide.

Marc Lehane · Solutions Architect / CTO, Kinetech · [email protected]

Kinetech Cloud · San Antonio, TX · How we deliver · Live Build Console

123456

You are reading Your platform — deeper detail on step 4, Why now?.

That is the pressure. What it costs to answer it is not one number — three things move it.

All platformsNext — What does it cost?