Services · contract & fractional
DevOps-as-a-Service
Platform engineering for teams that need production Kubernetes they can actually run.
Most teams don't need another cloud bill. They need infrastructure that stays up, costs what it should, and can be operated by the people who own it after I'm gone. That's the work: bare-metal and self-managed clusters, GitOps delivery, highly available data services, observability, and disaster recovery that has actually been tested.
What I do
- Platform build-outs. Kubernetes from bare metal or a regional cloud — Talos, RKE2, K3s, k0s — with Cilium networking, Ceph or SeaweedFS storage, Vault, SSO and LGTM observability. Built to be handed over, not hoarded.
- GitOps delivery. Flux with digest-pinned image automation, no manual
kubectlin production, merge-to-live measured in minutes. - Reliability & disaster recovery. HA PostgreSQL with synchronous replication and automated failover, tested restore paths, and recovery runbooks that have survived losing an entire datacentre.
- GPU & AI infrastructure. Inference serving on NVIDIA H100 (SGLang), queue backpressure, priority lanes and autoscaling under real production load.
- Airgapped & regulated environments. Offline deployment, internal PKI, CIS hardening, and CI/CD that works with no route to the internet.
- Cost & sovereignty reviews. Where the spend is going, what it would cost self-managed, and what you give up either way — an honest answer, including when the answer is "stay where you are".
Selected work
- AI platform, 80-person company. 31 servers across two datacentres, live in under 50 working days. GPU inference serving 30k+ requests/day. Full cluster recovered after a total datacentre loss.
- Fleet telematics pipeline. MQTT → Kafka → Flink → PostgreSQL, ~8 months in production, 700,603 checkpoints, zero failures, consumer lag held at 0.
- Airgapped GitLab for a regulated bank. Offline install, cold active/standby HA, internal-PKI TLS, host keys preserved so git clients survive a failover.
- GitOps platform for a live campaign app. Fully Flux-delivered, four-layer autoscaling, CNPG PostgreSQL, ~5–8 min merge-to-live.
How it works
Contract and fractional engagements, remote from Finland across European hours. Retainer for ongoing platform ownership, or fixed scope for a build-out or migration. Engagements are contracted directly with me; for EU invoicing I can register as a Finnish sole trader or work through a light-entrepreneurship service, and employer-of-record arrangements are fine too. Most engagements start with a short call and a written scope before anyone commits.