// aws consultancy · malmö, sweden

AWS infrastructure that is documented, codified and affordable

Documented experience running everything from small workloads to enterprise estates: landing zones, migrations, EKS and cost-aware operations, all as code.

region: eu-north-1
vpc: prod
alb
public subnet
eks workloads
private subnet
rds · s3
data layer
iam boundaries · cost tags on everything · scale to demand
Enterpriseestates run in production
IaCeverything we build is codified
30-40%typical waste found in a first cost review
Malmöbased, working across Europe

// what we do

From first account to a well-run estate

We work inside your team, leave everything in Terraform and document the decisions so the next engineer understands why the architecture looks the way it does.

01

Landing zones & account strategy

Multi-account setups with AWS Organizations, SSO, guardrails and network baselines, codified in Terraform so a new account is a merge request, not a project.

02

Migration to AWS

From on-prem, another cloud or legacy hosting. We assess, pick the right pattern per workload, and move things in slices with rollback available at every step.

03

EKS & container platforms

Production-grade EKS with IRSA, Karpenter autoscaling, network policy and observability wired in from the start.

04

Cost engineering

Tag hygiene, right-sizing, Savings Plans and Graviton moves, with a report that shows where the money goes and what changed after we touched it.

05

Security & compliance baseline

Least-privilege IAM, encryption defaults, GuardDuty and Security Hub, audit trails and evidence that satisfies your customers' questionnaires.

06

Reliability & operations

SLOs, alerting that people trust, disaster-recovery drills and runbooks written for the engineer who gets paged at 03:00.

// reference architecture

A shape that works for most teams

edge
Route 53CloudFrontWAF
compute
EKSLambdaECS Fargate
data
RDS / AuroraS3DynamoDB
foundation
OrganizationsIAM Identity CenterTerraform

// engagement

How we approach an AWS estate

  1. 01AssessAccount, cost and architecture review with prioritised findings.
  2. 02BaselineLanding zone, IAM and network foundations codified in Terraform.
  3. 03MigrateWorkloads moved in slices, verified against real traffic.
  4. 04OptimiseRight-sizing, autoscaling and commitments once the shape is stable.
  5. 05OperateSLOs, alerting and a handover your team can run without us.

// services

AWS services we use in anger

compute
EKSECSLambdaEC2KarpenterGraviton
data
RDSAuroraDynamoDBS3OpenSearchMSK
networking
VPCTransit GatewayPrivateLinkRoute 53CloudFront
security
IAMIdentity CenterKMSGuardDutySecurity Hub
automation
TerraformCDKCrossplaneEventBridgeStep Functions
observability
CloudWatchOpenTelemetryPrometheusGrafana

// faq

Common questions

Can you do a one-off review instead of a long engagement?

Yes. A fixed-scope AWS review, covering architecture, security posture and cost, is a common way to start. You get a prioritised findings report and can decide what to do next.

Do you only work with Kubernetes on AWS?

No. Plenty of workloads are better served by Lambda, ECS Fargate or plain managed services. We pick the boring option that fits the team that has to run it.

Are you an AWS reseller?

No. We are engineers, not a billing intermediary. Your AWS relationship and invoices stay yours, and our cost advice has no incentive attached.

// how we work

01 embed
your team, your tools
02 ship
first change in prod, week one
03 harden
tests, docs, runbooks
04 hand over
your team owns it

// contact

Curious what your AWS estate looks like from the outside?

Tell us roughly what you run today and we will suggest a sensible first step.

office: Malmö, Sweden · uppdrag across Europe

Spam protected. No newsletters, ever.