Cloud you can version, review, and re-run.
Infrastructure as code so environments aren't trapped in one person's console history. You work directly with JD Savage through Define · Design · Deploy — clear scope, honest tiers, real handoff.
What we build
From click-ops to code
Pick the shape that matches the problem. We scope the rest together.
IaC foundation
Repo structure, remote state, one environment, core networking and compute, and a CI path to plan/apply safely.
Multi-environment stacks
Dev, stage, and prod that look the same on purpose — modules, variables, and guardrails so drift doesn't win.
CI/CD for infrastructure
Pipelines that plan on PR, apply on merge, and keep secrets out of the repo. Your team reviews changes like code.
Networking & identity
VPCs, subnets, security groups, IAM roles, and least-privilege access patterns that match how you actually deploy apps.
Secrets & config
Parameter stores, secret managers, and environment config wired so apps get what they need without shared passwords in chat.
Click-ops recovery
Already built in the console? We capture, modularize, and put it under version control so the next change is reviewable.
How we work
Define · Design · Deploy
The deliverable is working infrastructure your team can change — not a slide with boxes and arrows.
D
Define
Cloud account(s), environments, what must exist on day one, and what stays out of scope. Success = repeatable apply, not a diagram.
D
Design
Tooling fit (Terraform/OpenTofu, Bicep, CloudFormation, or Pulumi), module layout, state, and how your team will change it.
D
Deploy
Working pipeline, applied baseline, runbooks, and handoff so you're not dependent on one person's console clicks.
Tools
Tooling that fits the cloud and the team
We're not locked to one product. The right choice is the one you can maintain after handoff.
Terraform / OpenTofu
Default for multi-cloud and portable modules when you want a wide ecosystem.
Bicep / ARM
Natural fit when you're all-in on Azure and want first-party tooling.
CloudFormation
Solid when AWS-native stacks and existing org standards already lean that way.
Pulumi
When the team prefers real programming languages for infra and policy.
Pricing
Honest bands, confirmed after scope
Ranges below are market-aligned starting points. Exact quotes depend on accounts, compliance, and how much is greenfield vs recovery.
IaC foundation
$5,000–$15,000
about 2–4 weeks
One cloud, one env, core network/compute, remote state, first pipeline
Repo structure, remote state, one environment, core networking/compute, CI apply pipeline.
Multi-env IaC + pipelines
$15,000–$40,000
about 4–8 weeks
Dev/stage/prod, modules, secrets, guardrails, documented runbooks
Dev/stage/prod, secrets, modules, guardrails, documented runbooks.
Platform / larger cloud program
$40,000+
scoped after discovery
Multi-account, shared services, compliance, or greenfield platform work
Multi-account, compliance, shared services, or greenfield platform work.
Typically included
- Working IaC in a repo your team owns
- Remote state and basic backend setup
- At least one pipeline path (plan/apply)
- README / runbook for day-2 changes
- Handoff walkthrough with JD
Not assumed
- Unlimited on-call or 24/7 ops (unless scoped as retainer)
- Full enterprise landing zones by default — those are platform-tier
- Migrating every legacy resource on day one without prioritization
- Ownership of your cloud bill or vendor contracts
Example scopes
What projects often look like
App environment baseline
VPC, subnets, security groups, a compute target, and secrets wiring so a web app can deploy the same way every time.
From console to code
Import or rebuild the pieces that matter, modularize them, and stop relying on tribal knowledge in screenshots.
Team delivery pipeline
PRs show plan output; merges apply to the right environment. Review infrastructure the way you review application code.
FAQ
Common questions
- Which tool should we use?
- Whatever fits your cloud and team. Terraform/OpenTofu is common for portable modules; Bicep or CloudFormation when you're single-cloud and want native tooling; Pulumi when the team wants general-purpose languages. We pick for the job, not fashion.
- Do you manage our cloud after the project?
- The goal is handoff: your repo, your pipeline, your runbook. Ongoing help is available as a scoped retainer — not assumed.
- Can this pair with a web app or AI agent project?
- Yes. Many clients need a solid environment under the app or agent. We can sequence foundation first, then application work — or keep them separate if you already have infra.
- What does foundation include vs platform?
- Foundation is one coherent environment and a path to change it safely. Platform is multi-account, shared services, compliance controls, and org-wide patterns — priced after discovery.
- What's the first step?
- Share cloud (AWS/Azure/GCP), current pain (drift, no pipeline, click-ops), and email. I'll reply with a sensible scope band — not a vague open engagement.
Ready to put infrastructure in code?
Tell me your cloud and the pain (drift, no pipeline, click-ops). I'll reply with a sensible next step — usually a tight scope, not a hard sell.