Skip to content

The platform team you don’t have to hire yet.

Production CI/CD, Kubernetes that doesn’t wake you up, observability that actually catches the bug, on-call rotations that don’t burn out the team. We embed with you to build the platform, then hand it over.

Rate $100 – $120 USD / hour · fixed-fee and retainer available

What you get

CI/CD
trunk-based, ephemeral environments per PR, signed images, policy gates, real rollback.
Kubernetes
EKS / GKE / AKS / k3s, with Helm or Kustomize, GitOps via ArgoCD or Flux.
Observability
OpenTelemetry traces, structured logs, SLO dashboards, error budgets, real alerts.
On-call
PagerDuty / Opsgenie, escalation tree, runbook per alert, blameless post-mortems.
Cost
rightsizing, autoscaling, spot/preemptible where it’s safe, monthly cost review.
Performance
load testing in CI, p95/p99 budgets, capacity planning.

How we engage

  1. 01

    Platform audit (1 week, fixed fee)

    We review your CI, your deploys, your incident history, and your cost. Written findings, no obligation to continue.

  2. 02

    Reference pipeline (2–4 weeks)

    One end-to-end deploy that becomes the template for every service.

  3. 03

    On-call retainer

    Optional — we cover your on-call for 90 days post-handover, then hand the pager to your team.

Stack we work in

CI/CD

GitHub Actions, GitLab CI, Buildkite, CircleCI, Argo Workflows

CD/GitOps

ArgoCD, Flux, Spinnaker, custom Helm/Kustomize

Kubernetes

EKS, GKE, AKS, k3s, OpenShift, Rancher

Observability

Grafana, Prometheus, Loki, Tempo, Datadog, Honeycomb, Sentry

Secrets

Vault, AWS Secrets Manager, External Secrets Operator

Policy

OPA / Conftest, Kyverno, Datadog Cloud Security

Reference architectures

Anonymized patterns from real engagements. Client names omitted; details available under NDA.

Series A SaaS — 14min deploys → 90s

Replaced a manual Jenkins pipeline with trunk-based GitHub Actions + ArgoCD. Deploy time down 89%, rollback under 30s, zero-downtime migrations.

Pre-Series-A healthtech — first SOC2 audit

Wired policy-as-code, signed images, change tickets, and an evidence pipeline. SOC2 Type II issued without critical findings.

IoT startup — 4 Kubernetes clusters, 1 PR

Unified 4 dev/staging/prod clusters behind one GitOps repo with per-env overlays. Eliminated snowflake clusters.

Questions we get asked

What does a good first engagement look like?

Usually a 1-week platform audit. You get a written report of what’s working, what’s broken, and a prioritized roadmap. We don’t write code until you sign off on the plan.

Do you do managed operations after handover?

Optional. We can cover on-call for 90 days, then transition to your team. Most of our clients keep us on a small monthly retainer for incident review.

Can you help us hire our first DevOps engineer?

Yes. We write the JD, run the interview loop, and onboard the new hire using the documentation we built. Fractional CTO add-on available.

Do you push Kubernetes for everything?

No. K8s is the right answer for ~30% of workloads. For the other 70% (single-region, low-traffic, simple deploys), ECS / Cloud Run / Vercel / Render is faster, cheaper, and easier to operate. We tell you which one.

What’s your take on platform engineering teams vs DevOps?

Both. For a 5-engineer startup, one senior DevOps engineer + a platform team of zero. For a 50-engineer company, a 4-person platform team with embedded DevOps in each product squad. We staff to your stage, not the industry average.

Let’s scope it properly.

A 30-minute call. No deck, no pitch — we read your repo or your architecture diagram and tell you what’s realistic.