Cloud infrastructure that makes releases routine

We set up and run the platform under your product - cloud, CI/CD, monitoring and backups - on your own account, so every release is small, checked and easy to undo.

Built with
DockerGitHub ActionsTraefikPrometheusLet's EncryptPostgreSQLRedisRabbitMQNode.js

Everything between your code and your users

One team owns the whole path, from the commit an engineer pushes to the request a customer makes.

platform / migration.log
09:02inventory47 services · 6 databases mapped
09:40plan128 to add · 0 to destroy
10:15cutoverstage 1 · billing-api → aws/eu-west-1
10:31traffic10% → 40% · error rate flat
11:05rollbackdrill passed · restored in 90 s
11:20cutoverstage 2 · 40% traffic · holding

Secure by default, not by audit

Switched on from the first day of the setup, not added when a questionnaire asks for it.

  1. 01

    Least-privilege access

    Every person and service gets only the access it needs, and every production change is logged.

    IAM roles
    On
  2. 02

    Encrypted by default

    TLS in transit, encryption at rest, and secrets in a managed vault - never in code or config files.

    TLS · KMS · vault
    On
  3. 03

    Autoscaling, load-tested

    Capacity follows demand, tested against your own traffic peaks before launch day.

    load tests
    On
  4. 04

    Backups you have restored

    Automated snapshots copied to a second region, with restore drills on a schedule.

    restore drills
    On

Moving to the cloud without a big-bang weekend

A typical migration. Nothing moves until it has been mapped, and nothing moves all at once.

  1. Week 1
    Audit

    Every service, database and scheduled job mapped, with what depends on what.

  2. Week 2
    Plan, as code

    The target setup written in Terraform and reviewed with your team.

  3. Weeks 3–5
    Staged cutover

    Traffic moves one service at a time; every step can be undone.

  4. Week 6
    Handover

    Runbooks, dashboards and alerts your team knows how to use.

  5. After
    Run and improve

    Patching, cost reviews and on-call, if you want us to stay on.

mainhandover commit · 6 folders
  • your-repo/
  • ├infra/# Terraform, per environment
  • └production/
  • └staging/
  • ├.github/workflows/# build, test, deploy
  • ├monitoring/# dashboards and alerts
  • ├runbooks/# what to do when paged
  • ├SECURITY.md# access, secrets, backups

What you get is in your repo

Every server, pipeline, dashboard and alert is written down as code in your repository - not held in our heads or our accounts.

  • Infrastructure as code for every environment
  • CI/CD with preview environments
  • Dashboards and alerts for every service
  • Runbooks for the common incidents

Questions we get asked

Something else? Email hello@gigax.net.

Which clouds do you work with?

AWS, Google Cloud and Azure - and simpler hosting like Vercel or a single server when that is all a product needs.

Whose account does it run on?

Yours. The cloud account, the billing and the keys stay with you, and everything we set up is written as code in your repository.

Will a migration mean downtime?

It is planned so it does not: services move one at a time, traffic shifts gradually, and each step can be rolled back.

Can you take over an existing setup?

Yes. We start with a short review of what is running and what it costs, fix what is risky, and then carry on from there.

What happens after handover?

Either your team runs it with the runbooks and dashboards we leave, or we stay on for patching, cost reviews and on-call.

How is it priced?

Tell us what you run today and we come back with scope, a timeline and a price - not a discovery call first.

Have a setup that needs fixing?

Tell us what you run today and where it hurts - we come back with what we would change first.

Book a demo