What we do
Services
Senior engineering on contract, across the whole path from commit to production. Engagements range from a focused review to hands-on delivery embedded with your team.
Every engagement runs the same way: understand the estate as it really is, agree the target in writing, deliver through reviewed pull requests, and hand over something your team can run without us. Below is what that covers.
DevSecOps & pipeline security
Security that lives in the pipeline and the platform, not in a spreadsheet. Scanning, secrets handling, encryption and logging designed in from the start, plus the policy and documentation an auditor will ask for.
- Dependency, container and code scanning wired into CI/CD
- Cloud posture review and remediation
- Secrets management and encryption design
- Secure, centralised logging pipelines
- AWS security testing and hardening
- Security policy, runbooks and team training
Typical tooling
- Snyk
- Twistlock / Prisma
- Sonatype
- WAF
- Cloud Conformity
- ELK
- Kinesis
- GPG
Cloud & platform engineering
Designing, building and running the cloud platforms that product teams deploy onto, and the network paths in front of them. Production experience across the major public clouds and OpenStack.
- Landing zones, VPC design and cross-cloud VPN
- Ingress, WAF, load balancing and service mesh
- Platform uplift and migration between providers
- Cost and reliability review of existing estates
Typical tooling
- AWS
- Azure
- GCP
- Alibaba Cloud
- OpenStack
- Istio
- Kong
- Flannel
Kubernetes & containers
Managed and self-hosted Kubernetes, and the container platforms that came before it. Cluster design, security, patching and upgrades, and the ingress and identity pieces that make it usable for the teams on top.
- EKS and AKS design, deployment and hardening
- Cluster patching and upgrade programmes
- Ingress, network policy and workload security
- ECS, Swarm and container build pipelines
Typical tooling
- Kubernetes
- EKS
- AKS
- ECS
- Docker
- Swarm
- LXC
- Windows Containers
Infrastructure as code & automation
Infrastructure described in code, reviewed like code and deployed through a pipeline. New builds, and migrations of existing estates onto IaC or from one tool to another.
- Terraform and Pulumi module and stack design
- Configuration management with Ansible, SaltStack or Puppet
- CloudFormation to Terraform migrations
- GitOps workflows for infrastructure change
Typical tooling
- Terraform
- Pulumi
- Ansible
- SaltStack
- Puppet
- CloudFormation
CI/CD & developer self-service
Pipelines that are fast, secure and understood by the people using them, and developer tooling that removes the queue between an engineer and their environment.
- Pipeline design, rebuild and uplift
- Self-service developer tooling in Go
- Release process and red-tape reduction
- Documentation and training that outlasts the engagement
Typical tooling
- GitHub Actions
- GitLab CI
- Jenkins
- Buildkite
- Bamboo
- Drone
- Go
Private cloud & infrastructure
Not everything belongs in a public cloud. Private cloud, virtualisation and storage platforms, built by someone who has also racked, cabled and diagnosed the hardware underneath.
- OpenStack and Proxmox design and migration
- Storage integration, including TrueNAS
- Linux systems engineering and diagnostics
- Monitoring and observability for self-hosted estates
Typical tooling
- OpenStack
- Proxmox
- KVM
- TrueNAS
- VMware ESXi
- Grafana
- Linux
Next step
Have a platform that needs to ship faster and safer?
Tell us the problem, the stack and the timeframe.