Cloud infrastructure that works — designed, built, and kept running.
Networking and landing zones, compute and containers, CI/CD, observability, security, and cost control — end to end, mostly on AWS, with hands-on GCP and Azure for teams that aren't. You work directly with the person doing the work.
Reference architectures
Patterns I actually build.
Five common builds, cycling on their own — click a tab to stop it and dig in, or click any box for what it actually does.
Capability
End-to-end, not just one layer.
Eight layers, one point of contact. Everything here is a system I've built, not a slide I've presented.
Foundations & Networking
VPC design, multi-account landing zones, and IAM boundaries that contain the blast radius.
Compute & Containers
EC2, EKS/Kubernetes, ECS/Fargate, and Lambda — sized for the actual workload, not a guess.
CI/CD & Infrastructure as Code
Terraform, GitOps via ArgoCD, Jenkins, GitHub Actions — changes ship safely, not by hand at midnight.
Observability & Monitoring
Prometheus, Grafana, CloudWatch, and alerting scoped to page the person who can fix it.
Security & DevSecOps
Least-privilege IAM, Trivy/SonarQube scanning gates, hardening built in from the start. A flat-fee AWS security audit is running right now. See it →
Cost Optimization (FinOps)
A flat-fee, read-only AWS cost audit, running right now. See it →
AI/ML & LLM Infrastructure
SageMaker pipelines, Bedrock, and retrieval-augmented tools for internal use.
Multi-Cloud (GCP & Azure)
AWS-deep, hands-on elsewhere — for teams not fully on one cloud.
Ways to work together
Engagement models.
Assessment
A prioritised review of what's risky, wasteful, or fragile right now.
Implementation
Design and build it — empty account to production-ready.
Managed Operations
Once it's live, I keep it running: monitoring, incidents, iteration.
Enablement
Your team takes over — you're not locked into needing me forever.
Why not an agency
You hire the person doing the work.
No account manager, no bench of juniors learning on your bill, no multi-week procurement process.
Direct access
You talk to the person writing the Terraform, not a relay.
Transparent pricing
Quoted upfront — proven on the live audit service.
Documented approach
Written down, not tribal knowledge you take on faith.
Fast start
A scoping call, then a start date — no procurement maze.
Approach
How I'd approach common engagements.
One is a pattern description. Two are real and live right now.
Landing zone from zero
One unstructured AWS account. A multi-account foundation — segmentation, centralized logging and IAM — so every new workload starts on solid ground.
Know what you're spending, then fix it
A flat-fee, read-only AWS cost audit — a prioritised savings roadmap, optional hands-on remediation. See the audit service →
Find what's exposed, then fix it
A flat-fee AWS security audit — findings mapped to CIS AWS Foundations, prioritised by severity. Already have a report? Remediation only, no redundant audit. See the audit service →
Get in touch
Let's talk about what you're building.
AWS Certified Solutions Architect – Professional, verified on Credly — with hands-on GCP and Azure experience too.