Services / Software house support
For agencies and software housesA platform per client, without building your own operations
GitLab or GitHub Actions for delivery. Argo CD for client environments. Kubernetes with isolation. Grafana and on-call outside office hours. You deliver the product, we the layer that can be written into the client contract.
Delivery, tenants, on-call
A software house without a platform repeats the same operations for every client. We put CI, GitOps, isolation, and observability into a layer you offer beside the product.
- We do not enter your product backlog. We hold the infrastructure under it.
- A retainer or per-project model, with a clear split of who takes application P1.
A pipeline template the team copies onto a new project
One harness: test, scan, image, preview. A new client does not start from an empty YAML. Runner and registry are yours or ours, with isolation and cost per project.
Template
Repo starter, environments, secrets, branch policy.
Preview
The MR comes up in an isolated space and disappears. The client sees a build, not your laptop.
Scan
Dependencies and image in the pipeline. A finding goes to the project backlog.
Billing
CI minutes and registry can be assigned to a client.
When the team lives on GitHub, operations do not require a migration
The same level of gates and OIDC to the cloud. A workflow per template. Actions on kubernetes/kubernetes is a scale pattern, with you we come down to what the team will maintain.
OIDC
No long-lived key in secrets. A role per environment.
Matrix
Client A does not see client B secrets. Separate environment protections.
Cache
Faster build without leaking artifacts between tenants.
Audit trail
Who approved a deploy to the client production.
An environment per client, with a separate project
ApplicationSet or a project template. Namespace, quota, network. The client does not sit on a shared cluster-admin. Sync and health are visible without entering your Slack at 23:00.
Isolation
RBAC, NetworkPolicy, separate secrets. Blast radius of one project.
Template
A new environment from a merge, not from a weekend kubectl session.
Promotion
Client staging, then production. The same path as inside your organization.
Offboarding
Data retention and namespace deletion are in the contract checklist.
On-call and SLO you can put in a contract
A dashboard per tenant or folder. The alert comes to us, with escalation to you when it is the application. An availability report for the contract. You do not build a night shift from zero.
SLO
p95 and error per client service. Budget written down.
On-call
P1 on infrastructure. P2 on the application per the contract.
Cost
Showback per project. The client sees what they pay in the cloud.
Handover
When the project leaves, documentation and IaC remain, not knowledge only in someone's head.
From template to tenant care
First your delivery method. Then an environment catalog. Finally on-call and showback.
- Template Pipeline, chart, secrets, network, quota.
- Onboarding First client on the template, isolation, billing.
- Rhythm Platform upgrade, scan, tenant review.
- Contract SLA, escalation, offboarding, report.
We will discuss the environment template and SLA
On that basis we will prepare a platform layer under your delivery.
Contact us