Independent infrastructure consulting
Infrastructure that outlasts the consultant.
I design, build and document production infrastructure — Kubernetes platforms, infrastructure as code, identity, observability and disaster recovery. Every engagement ends with your team owning the system, not a dependency on me.
Where I help
Most of my work falls into six areas. They overlap, and engagements usually start in one and expose problems in another.
Kubernetes & platform
Cluster design and bring-up, GitOps delivery with Argo CD, progressive rollouts, storage and networking decisions made deliberately rather than inherited from a tutorial.
Infrastructure as code
Terraform and Ansible that are idempotent and reviewable. Bringing existing hand-built estates under code without a rebuild, including the import-first work most teams avoid.
Identity & access
Single sign-on, SAML and OIDC integration, enforced multi-factor authentication, secrets management, and closing the gap between who can reach a system and who should.
Observability & alerting
Metrics, logs and alerts that mean something at 3am. Alerts tied to runbooks, and a bias against the dashboards nobody reads and the pages nobody can act on.
Resilience & recovery
Backups that have been restored, not just scheduled. Rehearsed disaster-recovery procedures, documented failure modes, and honest recovery-time expectations.
Endpoint & compliance
Device management and fleet visibility, vulnerability scanning in the build pipeline, and hardening baselines applied consistently instead of per-machine.
How I work
The technical choices matter less than the discipline around them. This is what that looks like in practice.
- Measure before changing. The declared state and the running state disagree more often than anyone expects. I check the live system rather than trusting the documentation — including my own.
- Write down the why, not just the what. Decisions get recorded with their reasoning and their trade-offs, so the next person can tell a deliberate choice from an accident.
- Every change reviewable. Infrastructure lives in version control and arrives through pull requests. If it only exists in someone's shell history, it doesn't exist.
- Prove it, then claim it. A control that has never been tested is a guess. Backups get restored, failovers get triggered, alerts get fired on purpose.
- Build for handover from day one. Runbooks written so your team can execute them without me on the call — which is the only real test of whether the work was finished.
Ways to engage
Scoped work with a defined end, rather than an open-ended retainer that quietly becomes a dependency.
Assessment
A focused review of what you're running — risks, gaps and a prioritised list of what to fix first. Delivered as a written report you keep, whether or not we work together afterwards.
Build
A defined piece of infrastructure delivered end to end: designed, built, documented and handed over, with acceptance criteria agreed before anything starts.
Embedded support
Working alongside your team for a fixed period — part architecture, part implementation, part bringing the team up to speed on what was built and why.
Have something that needs fixing?
Tell me what you're running and what's worrying you. If I'm not the right fit I'll say so early.