We build and maintain production-grade infrastructure, automated test suites, and backend systems — and we ship drift-warden, a GitOps platform bootstrap for Kubernetes teams, and nexus-hetzner, IaC for self-hosted clusters.
End-to-end delivery across infrastructure, quality, backend, and project execution — without the coordination overhead of five separate vendors.
Kubernetes clusters, CI/CD pipelines, GitOps workflows, infrastructure-as-code, observability stacks. We design for day-two operations from the start.
Automated test suites, performance benchmarking, contract testing, security scanning. We embed quality into pipelines rather than bolting it on at the end.
API design, Go and Python services, database modelling, event-driven architecture. We write code that ops teams are happy to run at 3 AM.
Technical project leadership, delivery planning, stakeholder communication, risk management. We bridge engineering reality and business expectations.
A versioned GitOps reference architecture for platform teams. From bare Kubernetes to a fully wired, CIS-compliant platform — Argo CD, Authentik, Kargo, secrets, certs, ingress, storage — in a single bootstrapped operation.
# Scaffold a new GitOps repo $ drift-warden bootstrap \ --env prod \ --clusters 2 \ --argo-cd-version 3.0 \ --chart-version v1.49.4 \ --output ./my-gitops-repo ✓ bootstrap-app.yaml ✓ applicationset.yaml ✓ values-override.yaml ✓ README.md → Fill in values-override.yaml, then: kubectl apply -f bootstrap-app.yaml
Infrastructure-as-code for a production-ready k3s cluster on Hetzner Cloud. Terraform provisions the servers, Ansible configures every node — Tailscale VPN, NFS mounts, k3s install — and drift-warden takes it from there.
# Bootstrap full k3s cluster on Hetzner $ gh workflow run deploy.yml \ --field bootstrap_mode=true \ --field worker_count=3 ✓ Terraform: network, firewall, servers ✓ Ansible: Tailscale → NFS → k3s master ✓ Ansible: k3s workers joined ✓ SSH locked to Tailscale CGNAT ✓ kubeconfig patched and uploaded → Cluster ready. Run drift-warden next.
Whether you need help with drift-warden, nexus-hetzner, a full DevOps engagement, or just a code review — let's talk.
Services engagement, drift-warden support, or a quick technical question — reach out and we'll respond within one business day.