Services / Software house support

For agencies and software houses

A platform per client, without building your own operations

GitLab or GitHub Actions for delivery. Argo CD for client environments. Kubernetes with isolation. Grafana and on-call outside office hours. You deliver the product, we the layer that can be written into the client contract.

Template A new environment from a catalog, not from zero
Isolation IAM, network, and billing per client
Preview An MR with a live environment
SLA On-call that can be written into a contract
How it fits together

Delivery, tenants, on-call

A software house without a platform repeats the same operations for every client. We put CI, GitOps, isolation, and observability into a layer you offer beside the product.

  • We do not enter your product backlog. We hold the infrastructure under it.
  • A retainer or per-project model, with a clear split of who takes application P1.
GitLab, CI/CD pipeline, status and build stages
01, CI/CD

A pipeline template the team copies onto a new project

One harness: test, scan, image, preview. A new client does not start from an empty YAML. Runner and registry are yours or ours, with isolation and cost per project.

Template

Repo starter, environments, secrets, branch policy.

Preview

The MR comes up in an isolated space and disappears. The client sees a build, not your laptop.

Scan

Dependencies and image in the pipeline. A finding goes to the project backlog.

Billing

CI minutes and registry can be assigned to a client.

GitHub Actions, workflow runs and job status
02, GitHub Actions

When the team lives on GitHub, operations do not require a migration

The same level of gates and OIDC to the cloud. A workflow per template. Actions on kubernetes/kubernetes is a scale pattern, with you we come down to what the team will maintain.

OIDC

No long-lived key in secrets. A role per environment.

Matrix

Client A does not see client B secrets. Separate environment protections.

Cache

Faster build without leaking artifacts between tenants.

Audit trail

Who approved a deploy to the client production.

Argo CD, applications, health and GitOps sync
03, Argo CD

An environment per client, with a separate project

ApplicationSet or a project template. Namespace, quota, network. The client does not sit on a shared cluster-admin. Sync and health are visible without entering your Slack at 23:00.

Isolation

RBAC, NetworkPolicy, separate secrets. Blast radius of one project.

Template

A new environment from a merge, not from a weekend kubectl session.

Promotion

Client staging, then production. The same path as inside your organization.

Offboarding

Data retention and namespace deletion are in the contract checklist.

Grafana, dashboard catalog and data sources
04, Grafana

On-call and SLO you can put in a contract

A dashboard per tenant or folder. The alert comes to us, with escalation to you when it is the application. An availability report for the contract. You do not build a night shift from zero.

SLO

p95 and error per client service. Budget written down.

On-call

P1 on infrastructure. P2 on the application per the contract.

Cost

Showback per project. The client sees what they pay in the cloud.

Handover

When the project leaves, documentation and IaC remain, not knowledge only in someone's head.

Operations

From template to tenant care

First your delivery method. Then an environment catalog. Finally on-call and showback.

  1. Template Pipeline, chart, secrets, network, quota.
  2. Onboarding First client on the template, isolation, billing.
  3. Rhythm Platform upgrade, scan, tenant review.
  4. Contract SLA, escalation, offboarding, report.
Talk

We will discuss the environment template and SLA

On that basis we will prepare a platform layer under your delivery.

Contact us