Independent infrastructure consultancy
Infrastructure that outlasts the engagement.
We design, build and document production infrastructure. That covers Kubernetes platforms, infrastructure as code, identity, observability and disaster recovery. Every engagement ends with your team owning the system and running it without us.
Where we help
Most of our work falls into six areas. They overlap, and engagements usually start in one and expose problems in another.
Kubernetes & platform
Cluster design and bring-up, GitOps delivery with Argo CD, progressive rollouts, storage and networking decisions made deliberately rather than inherited from a tutorial.
Infrastructure as code
Terraform and Ansible that are idempotent and reviewable. Bringing existing hand-built estates under code without a rebuild, including the import-first work most teams avoid.
Identity & access
Single sign-on, SAML and OIDC integration, enforced multi-factor authentication, secrets management, and closing the gap between who can reach a system and who should.
Observability & alerting
Metrics, logs and alerts that mean something at 3am. Alerts tied to runbooks, and a bias against the dashboards nobody reads and the pages nobody can act on.
Resilience & recovery
Backups proven by restoring them. Rehearsed disaster-recovery procedures, documented failure modes, and honest recovery-time expectations.
Endpoint & compliance
Device management and fleet visibility, vulnerability scanning in the build pipeline, and hardening baselines applied consistently instead of per-machine.
How we work
The technical choices matter less than the discipline around them. This is what that looks like in practice.
- Measure before changing. The declared state and the running state disagree more often than anyone expects. We check the live system before we trust any documentation, including our own.
- Write down the reasoning. Decisions get recorded with their reasoning and their trade-offs, so the next person can tell a deliberate choice from an accident.
- Every change reviewable. Infrastructure lives in version control and arrives through pull requests. If it only exists in someone’s shell history, it doesn’t exist.
- Prove it, then claim it. A control that has never been tested is a guess. Backups get restored, failovers get triggered, alerts get fired on purpose.
- Build for handover from day one. Runbooks written so your team can execute them without us on the call. That is the only real test of whether the work was finished.
Ways to engage
Scoped work with a defined end, rather than an open-ended retainer that quietly becomes a dependency.
Assessment
A focused review of what you’re running: risks, gaps and a prioritised list of what to fix first. Delivered as a written report you keep, whether or not we work together afterwards.
Build
A defined piece of infrastructure delivered end to end: designed, built, documented and handed over, with acceptance criteria agreed before anything starts.
Embedded support
Working alongside your team for a fixed period. Part architecture, part implementation, part bringing the team up to speed on what was built and why.
Have something that needs fixing?
Tell us what you’re running and what’s worrying you. If we’re not the right fit we’ll say so early.