Cloud Native

Cloud native platforms, secure from the first commit.

We build Kubernetes platforms on bare metal and in the cloud: hardened, with modern networking, GitOps delivery and a supply chain you can trust. Our engineers are certified by the Linux Foundation as CKA, CKAD and CKS.

The challenge

Spinning up a Kubernetes cluster is quick. A platform that is secure, upgradable and usable by many teams is not. Networking, identities, secrets, supply chain and day-2 operations decide whether Kubernetes takes work off your plate or adds to it.

What we do

Capabilities in detail

Kubernetes platforms

On bare metal and in clouds, hardened to CIS baselines, with admission control, RBAC, private API endpoints, hardened node images and immutable operating systems.

Bare-metal provisioning

Automated provisioning with MAAS, Metal3 and Cluster API, installation media with cloud-init and Packer, including air-gapped networks.

Networking

Cilium with eBPF, OVN-Kubernetes and Kube-OVN, dual-stack IPv4/IPv6, network policies, tenant isolation, Gateway API, BGP underlays for leaf-spine fabrics.

GitOps and delivery

Argo CD and Helm, OCI bundles with Carvel, platform APIs with Crossplane, internal developer portals with Backstage.

DevSecOps and supply chain

GitLab CI pipelines with SBOMs, vulnerability and licence scans, conformance checks and reproducible, signable images.

Identities, secrets, PKI

Central IAM with Keycloak, external secret stores, cert-manager and internal PKI. Credentials belong neither in Git nor in images.

Operators and automation

Custom Kubernetes operators and CRDs in Go, Terraform and Ansible for provisioning, upgrades and day-2 operations.

Observability

Prometheus, Grafana, Loki, Thanos and VictoriaMetrics with SLO-driven alerts instead of alert noise.

Persistent storage

Ceph through ceph-csi and Rook-Ceph, S3 for applications, backup and restore for cluster state and data.

Approach

From requirements to operations.

  1. 01

    Assessment

    We review your existing platform or requirements: security, networking, delivery, operations.

  2. 02

    Platform design

    Distribution, networking, identities, storage and tenancy model are defined.

  3. 03

    Build as code

    Clusters, networking and platform services are created reproducibly with Terraform, Ansible and GitOps.

  4. 04

    Hardening

    Baselines, policies, supply-chain security and secrets management are enforced.

  5. 05

    Handover

    Runbooks, documentation and enablement for your teams.

  6. 06

    Operations

    Upgrades, monitoring and continuous improvement as an ongoing service.

Technology

  • Kubernetes
  • Cilium
  • OVN-Kubernetes
  • Kube-OVN
  • Argo CD
  • Helm
  • Carvel
  • Crossplane
  • Cluster API
  • Metal3
  • Backstage
  • Keycloak
  • cert-manager
  • GitLab CI
  • Trivy
  • Prometheus
  • Loki
  • Thanos
  • VictoriaMetrics
  • Go

Certified expertise

  • CKSCertified Kubernetes Security Specialist
  • CKACertified Kubernetes Administrator
  • CKADCertified Kubernetes Application Developer
  • LFCELinux Foundation Certified Engineer
  • LFCSLinux Foundation Certified System Administrator

Services in detail

Let's talk about your infrastructure.

An architecture review, a new environment from the ground up or support in operations: talk directly to the engineers who will deliver it.