Practice 06

Cloud, platform and DevSecOps

Nobody buys a platform. They buy the release that goes out on a Thursday afternoon without anyone holding their breath.

At a glance

We build the landing zones, pipelines, controls and observability that make delivery repeatable, then hand over the keys.

Tools we use most

  • AWS
  • Azure
  • GCP
  • Terraform
  • Kubernetes
  • Helm
  • ArgoCD
  • GitLab CI
  • GitHub Actions
  • Jenkins
  • SonarQube
  • Trivy
  • Fortify
  • Prometheus
  • Grafana
  • OpenTelemetry

Related work

Discuss this

What we get called in for

  • Deployments happen at midnight because that is when someone can watch them.
  • A cloud bill growing faster than usage, with no owner per line item.
  • A security review that requires SAST, SCA, secret scanning and evidence you can show an auditor.
  • A source control migration — SVN or TFS to Git — with history and access controls intact.
  • Alerts that page three people and tell none of them what broke.

How we build it

Baseline the current state

Deployment frequency, lead time, change failure rate and restore time. Improvement claims need a starting number.

Codify the landing zone

Accounts, networks, identity, logging and guardrails as Terraform modules with policy checks. Environments become reproducible instead of remembered.

Make the pipeline the control point

Build, test, SAST, SCA, secret and container scanning, signing and promotion in one path. Security stops being a gate at the end and becomes a step in the middle.

Instrument for the 3 a.m. question

Structured logs, traces and RED/USE dashboards, with alerts that map to a runbook and an owner.

Attach cost to teams

Tagging, budgets, anomaly alerts and a monthly review that names the top three drivers.

What you get

  • DORA baseline and target with a measurement method
  • Terraform landing zone: accounts, network, identity, logging, guardrails
  • CI/CD pipelines with integrated security scanning and artefact signing
  • Observability stack, SLOs, alert routing and runbooks
  • Cost allocation model, budgets and anomaly alerting
  • Migration plan and cutover runbook where applicable

Next step

Tell us what you're trying to ship.

Send the brief, the RFP, or three messy sentences about the problem. You get a written point of view from an architect within two working days — not a sales deck.