Services / FinOps

Cloud cost

A cloud whose cost has an owner

Grafana and tags show which team spends. Kubernetes says where idle sits. Terraform holds size in code. The pipeline does not leave a preview for a week. Rightsizing, commitments, and anomaly have a rhythm, without a blind lock-in.

Owner Every cost has a tag and a team
Rhythm Week, month, quarter, not a one-off action
Rightsize Measure use, then change the type
SLO A saving that does not break availability
How it fits together

Visibility, capacity, code, hygiene

The invoice alone changes nothing. We put allocation, Kubernetes, Terraform, and pipeline into a FinOps rhythm that engineering will maintain.

  • For fintech, a saving does not break control and SLO. A cheap environment that will not survive audit is the most expensive.
  • Cloud commitments after several measurement cycles, not in the first week.
Grafana, dashboard catalog and data sources
01, Visibility

The bill in product language, not the invoice alone

Allocation per service, team, environment. A dashboard for engineering and for finance. An anomaly of the day, not a surprise at month end. Without tags there is no owner, so label hygiene first.

Tags

Required on the account. Policy blocks a resource without an owner.

Showback

Cost per product. Chargeback when the organization is ready for it.

Anomaly

An alert on a spike. Idle disk, logs without retention, a dead load balancer.

Rhythm

A week of anomalies, a month of rightsizing, a quarter of commitments.

Kubernetes Dashboard, pods, CPU and memory
02, Kubernetes

Requests and a node group that match traffic

Excess requests inflate the node pool. Missing limits hurt neighbors. We see idle, burstable, and spot where SLO allows. This is an engineering cost lever, not a price-list discount.

Rightsize

Pod CPU and RAM vs use. A recommendation from measurement, not from guesswork.

Node

Instance type, autoscaler, spot for batch. Production has a separate policy.

Idle

A namespace after a project, a preview without TTL, a dead PVC.

SLO

A saving that breaks p95 comes back as incident cost.

Terraform Registry, infrastructure providers and modules
03, Terraform

Size and storage class in the module, not in the console

The registry and your modules hold default instance types, storage lifecycle, backup. A size change goes through plan. Infracost or an equivalent view in the MR, when the team is ready for it.

Defaults

The module does not stand up x2xlarge just in case.

Lifecycle

gp disk, archive, log retention. Policy in code.

Commitments

RI and Savings Plans after measurement, not blindly. A documented horizon.

MR

Plan shows a resource delta. Change cost is part of the review.

GitLab, CI/CD pipeline, status and build stages
04, Pipeline

Preview and runner do not stay on the invoice

An environment from an MR has a TTL. Artifacts and cache have retention. The runner autoscales. GitLab shows which project burns minutes. This is the simplest lever, often skipped.

TTL

Preview dies after merge or after N days. An alert when it stays.

Artifacts

Images, job logs, cache. Retention and GC.

Minutes

CI showback per team. A shared runner is not free.

Production

The pipeline has no right to leave a test stack without a tag and an owner.

Operations

From tags to commitments

First allocation. Then idle and rightsizing. Finally RI or SP and a quarterly rhythm.

FinOps illustration, cloud cost chart and account tag
  1. Allocation Tags, showback, anomaly, owners.
  2. Quick wins Idle, retention, preview TTL, obvious oversize.
  3. Architecture Storage class, node group, traffic model.
  4. Commitments RI, SP, committed use, quarterly review.
Talk

We will discuss allocation, idle, and cost rhythm

On that basis we will prepare a FinOps scope, from tags to commitments.

Contact us