// open source · malmö, sweden

Over a decade working in the open

We upstream fixes, contribute features and help you pick the projects worth betting on, so that when something breaks deep in the stack, nobody has to wait for a vendor.

forkfixtestsprmerged upstream
10+years working in the open
Upstreamfixes merged, not forked forever
CNCFecosystem is our daily ground
0vendor lock-in by default

// what we do

Open source as a strategy, not just a licence

Choosing an open project is easy. Operating it, upgrading it and influencing where it goes is the part that decides whether the bet pays off.

01

Technology selection

Which projects are worth betting on? We look at governance, release cadence, maintainer diversity and issue hygiene, not GitHub stars.

02

Upstream contributions

When something is broken deep in the stack we read the code, fix it and get the patch merged upstream, so you stop carrying a private fork.

03

Fork and patch strategy

Sometimes a fork is the right call. We make it maintainable: minimal diffs, automated rebases and a plan to upstream the delta.

04

Supply-chain security

SBOMs, provenance with Sigstore, dependency scanning and a realistic policy for what you actually do when a CVE lands on a Friday.

05

Releasing your own project

Licensing, contribution guidelines, CI, release automation and community expectations, so opening a repository helps you instead of creating a support desk.

// lifecycle

How we treat a dependency

  1. 01EvaluateHealth, governance and fit against your actual constraints.
  2. 02AdoptPilot in a real workload with an exit plan written down.
  3. 03OperateUpgrade cadence, alerting and ownership inside your team.
  4. 04ContributeReport, patch and upstream, reducing your private diff.
  5. 05SustainTrack project health so a fading dependency is spotted early.

// ecosystem

Projects we know from the inside

orchestration
KubernetesHelmKustomizeCluster API
delivery
ArgoCDFluxTektonBackstage
infrastructure
TerraformOpenTofuCrossplane
networking
LinkerdIstioCiliumEnvoy
observability
PrometheusGrafanaOpenTelemetryThanos
security
OPAKyvernoTrivySigstoreFalco

// how to judge a project

Signals we look at before recommending anything

Maintainer diversity. A project run by a single company can change licence overnight. Several independent maintainers is a much stronger guarantee than any roadmap slide.

Release discipline. Predictable releases, clear deprecation policy and honest changelogs tell you more about long-term cost than feature count.

Issue hygiene. How maintainers respond to an awkward bug report is the best available preview of what your support experience will look like.

// faq

Common questions

Why does upstreaming matter to us as a customer?

Because a private patch is a permanent tax: every upgrade costs more. Getting the fix merged upstream removes that tax and often improves the project for everyone else too.

Can you help us decide between an open source tool and a SaaS product?

Yes, and the honest answer is often the SaaS. We weigh total cost including the engineering time to operate it: self-hosting is only cheaper when you have someone to run it.

Do you help with licence compliance?

We help with the practical parts: dependency inventory, licence classification and flagging combinations that need a lawyer's eye. We are engineers, not legal counsel.

// how we work

01 embed
your team, your tools
02 ship
first change in prod, week one
03 harden
tests, docs, runbooks
04 hand over
your team owns it

// contact

Depending on a project you cannot debug?

Tell us which part of the stack worries you and we will take a look.

office: Malmö, Sweden · uppdrag across Europe

Spam protected. No newsletters, ever.