Cloud & infrastructure as code

Environments described in code, recreatable from scratch, with a bill someone is actually watching.

  • AWS
  • GCP
  • Azure
  • Terraform
  • Pulumi
  • Kubernetes
  • Helm
  • Cloudflare

The test of an infrastructure setup is whether you could rebuild it in a new account this week. If the honest answer is no, you do not have infrastructure — you have an artefact, and one person’s memory of how it was assembled.

We describe environments in Terraform or Pulumi, get staging and production genuinely identical apart from scale, and put a network and IAM baseline in place that does not rely on everyone being careful. Kubernetes where the workload justifies it; managed services and a container runtime where it does not, which is often.

Cost gets the same treatment as any other engineering constraint: measured, attributed to a team or feature, and reviewed. The savings that matter are usually structural — an oversized cluster, a forgotten environment, egress nobody costed — not the ones a dashboard suggests.

What you get

  • Terraform or Pulumi modules covering every environment
  • Staging and production rebuildable from scratch, verified by doing it
  • Network, IAM and secrets baseline with least privilege as the default
  • Cost review with the changes that pay for themselves, ranked

Common questions

Can you migrate us between clouds, or off one?
Yes, and we will start by asking whether you should. Migration is worth it for a real cost or capability reason; it is rarely worth it as a strategic gesture. If it is worth it, we do it incrementally with a rollback at every step.
Do we need Kubernetes?
Probably less than you think. It earns its complexity with many services, real multi-tenancy or genuine scaling needs. Below that, a managed container runtime costs a fraction of the operational attention. We will say which one you are.
Can you help us pass a security or compliance review?
We can get the infrastructure side in order — access control, secrets handling, audit logging, network boundaries, backup and restore actually tested. We are engineers, not auditors, so we work alongside whoever runs your certification.

Next step

Tell us what has to ship, and by when.

One call, no deck. If we are not the right team for it we will say so, and usually point you at who is.

Start a conversation branislav@thrivee.io

Typical reply within one business day · CET / CEST (UTC+1 / UTC+2)