Services
Four engagements. One connected path to Operate.
Whichever door you come through — a security audit, a greenfield build, or an application migration — the engagement is scoped to hand off cleanly into a managed Operate retainer, so platforms don’t just launch, they get run.
Secure
Score, prioritize, and close the gaps in a cluster you already run.
View detailsLaunchpad
Stand up a production-ready Kubernetes platform from zero.
View detailsMigrate
Move applications onto a cluster you already run — no rebuild required.
View detailsOperate
Keep the platform patched, monitored, and accountable — every month.
View detailsCluster Security & Posture
Secure
“I have a running cluster and I’m worried about its security posture.” Self-driven, or compliance and tender-driven.
Audit
CIS Kubernetes Benchmark scoring, RBAC review, network policy gap analysis, secrets management review, pod security standards check, image provenance and scanning gaps, exposed control-plane and etcd checks, ingress and TLS review.
Deliverable
Scored report (0–100, CIS-aligned), a severity-ranked remediation backlog, and an executive summary written for a non-technical stakeholder.
Excludes
No changes are made to the cluster — this is diagnostic only, to preserve audit independence.
1–2 weeks, scaling with cluster and node count.
Request AuditHarden
Fixed-price implementation of the specific backlog generated by Audit — nothing open-ended.
Deliverable
Implemented fixes, a before/after re-score, and a handover runbook.
Prerequisite
Requires an Audit backlog to price against — either ours or a validated gap list from elsewhere.
Billing
Fixed price, paid across 2–3 milestones — never time & materials.
2–6 weeks, depending on backlog size and severity mix.
Request HardenGreenfield Build & Migration
Launchpad
“I need a Kubernetes cluster that doesn’t exist yet.” New platform, or first-time Kubernetes adoption.
Essential
Single app or monolith, single environment.
Managed Kubernetes provisioning (EKS, GKE, AKS, or on-prem kubeadm/RKE2), ingress and TLS, basic monitoring (Prometheus/Grafana), a single CI/CD pipeline, containerization, and a handover knowledge-transfer session.
Excludes
Multi-environment setup, service mesh, disaster recovery, compliance reporting.
3–4 weeks.
Request EssentialProfessional
Multiple services, multi-environment (dev/stage/prod).
Everything in Essential, plus GitOps (ArgoCD/Flux), multi-environment namespace setup, full observability (metrics, logs, and traces), per-service CI/CD, basic backup and disaster recovery, and namespace-level network policies.
Excludes
Cross-region disaster recovery, multi-tenancy isolation, compliance audit trails.
6–9 weeks.
Request ProfessionalEnterprise
Multi-cluster or multi-region, regulated or multi-tenant workloads.
Everything in Professional, plus multi-cluster and multi-region architecture, multi-tenancy isolation, cross-region high availability and disaster recovery, compliance-ready audit logging, cost governance and autoscaling, and a dedicated architecture review.
10–16+ weeks.
Request EnterpriseApplication Migration onto an Existing Cluster
Migrate
“I already have a running cluster — just get my application onto it.” No cluster build involved.
Essential
Single app, one existing cluster.
Lightweight cluster readiness check (folded into the engagement, not a separate paid step), containerization, deployment manifests, CI/CD wiring into your existing tooling, and a cutover/rollback plan.
2–3 weeks.
Request EssentialProfessional
Multiple services, phased or strangler-pattern migration.
Everything in Essential, plus a phased migration plan across services, pre-cutover load testing, per-service CI/CD integration, and a minimal-downtime cutover.
5–8 weeks.
Request ProfessionalEnterprise
Large legacy estate, stateful workloads (databases, queues), zero-downtime requirement.
Everything in Professional, plus stateful workload migration, a zero-downtime cutover strategy, a tested rollback plan, and compliance sign-off documentation.
10–14+ weeks.
Request EnterpriseIf the readiness check finds the existing cluster’s architecture itself is broken — not just under-configured — that’s a redirect to Launchpad, not a reason to proceed with Migrate.
Managed Kubernetes Retainer
Operate
Always sold as the close of Secure, Launchpad, or Migrate — rarely a cold start.
Essential
Single cluster, business-hours support, monthly patching, a monthly posture and cost report, and next-business-day incident response.
Billing
Monthly retainer.
Ongoing.
Request EssentialProfessional
Multi-cluster, extended/on-call SLA, a quarterly re-audit bundled in, cost optimization reviews, and same-day incident response.
Billing
Monthly retainer.
Ongoing.
Request ProfessionalEnterprise
24/7 on-call SLA, a dedicated engineer, compliance reporting for government and regulated environments, multi-tenant governance, and a quarterly architecture review.
Billing
Monthly retainer.
Ongoing.
Request EnterpriseHow It Connects
One path to Operate.
Secure, Launchpad, and Migrate are three different front doors into the same operating model. Discovery in any one of them can surface a need better served by another.
Secure
Launchpad
Migrate
Operate
Managed Kubernetes retainer
Secure: Audit → Secure: Harden → Operate — the standard security path.
Launchpad (any tier) → Operate — the standard build path.
Migrate (any tier) → Operate — the standard migration path.
Redirect
Launchpad or Migrate discovery surfaces security gaps → routes to Secure: Audit.
Redirect
Secure: Audit surfaces an architecture-level failure, not just a config gap → routes to Launchpad, not Harden.
First Call
How we scope your first conversation.
These are the questions we use to route you to the right product and tier before any proposal is written.
Do you have a Kubernetes cluster running today?
No → Launchpad. Yes → next question.
Are you moving an application onto it, or worried about its security?
Moving → Migrate. Security → Secure.
How many clusters, environments, or services are involved?
Routes the tier: Essential for one, Professional for a few, Enterprise for many or regulated.
Is this compliance or tender-driven?
Flags Enterprise tier and Secure regardless of size — compliance requirements override simple scale-based tiering.
How We Work
Senior-level execution without unnecessary process overhead.
Engagements are structured to keep decisions clear, implementation practical, and founder or CTO time protected.
Short discovery engagements to find infrastructure bottlenecks quickly.
Hands-on implementation with clear ownership and practical documentation.
Ongoing advisory support for internal teams preparing to scale further.
Platform Mandate
Request Architecture Review
Review platform posture, reliability constraints, and cost governance priorities with an infrastructure engineering team.
