Infrastructure as code you can trust to apply
Terraform or OpenTofu, with Terragrunt where it helps. Reviewed in pull requests, applied by CI, reproducible from scratch.
Sound familiar?
- Half the infrastructure was clicked together in the console, and nobody knows which half.
planshows changes nobody made, so nobody dares toapply.- One giant state file: every change risks everything, and CI takes forever.
- CI logs in to the cloud with a long-lived key stored in the pipeline settings.
What you get
Everything in code
Existing resources imported, drift found and resolved.
A layout that scales
Small units with their own state, shared modules, and one way to add a project.
Keyless CI
A plan on every pull request and an apply on merge, authenticated with Workload Identity Federation instead of keys.
Security as code
Org policies and IAM reviewed like any other change.
Or just an audit
A written report on your existing code: what is risky and what to fix first.
How it runs
Review
You show me what runs and where it hurts. I look at the real setup, not a slide deck.
Plan
A short written plan: what changes, in what order, and how long it takes.
Build
Small steps you can review and roll back, dev before prod.
Handover
Docs and a runbook so your team can run it, with me on call if you want.
Where I've done this
- Split two monolithic stacks for a B2B SaaS startup into about 43 Terragrunt units, each with its own plan in CI, and moved the state without recreating resources.
- Engineered GCP foundations in Terraform and Ansible that 10+ delivery teams at HSBC built on.
- Built landing-zone modules at InPost that standardized how new projects are created. HashiCorp Terraform Associate certified.