ALeOps
Available/Helsinki, FI/EU & EEA

Infrastructure that stops being the bottleneck.

Deploys that take half an hour. Alerts everyone has muted. A cloud bill that grows faster than your traffic. I fix that for European B2B tech companies — in weeks, not quarters.

In IT since 2005 · DevOps and SRE since 2016

Commitgit pushfeature branchBuildCI pipelinetest · scan · imageregistrysigned artefactDeliverArgoCDgit state = cluster stateRuncluster · eu-northautoscaled workloadscluster · eu-westautoscaled workloadsobservabilityprometheus · grafana · loki · alertsyou know before your users do

Commit to production — 2.5 min

Results

Numbers from production, not from a brochure.

Every figure is a before-and-after from a real engagement.

−40%Total infrastructure cost
10+Kubernetes clusters managed
2.5 minCommit to production
Deployment time 15 min→2.5 min
−83%
Backup & restore 4 h→7 min
−97%
Incident recovery hours→2 min
≈−97%
AWS infrastructure cost baseline→−25%
−25%

Bar length = how much was cut; longer is better. Hatched = approximate — “hours” is charted against a one-hour baseline.

Services

Ten things companies hire me for.

Grouped by what they change: how you build, how you run it, how you prove it is safe, and where you want a second opinion.

Build

03

Cloud & Infrastructure

AWS design, Terraform & Terragrunt, multi-account, cost control.

CI/CD & Automation

GitLab CI, GitHub Actions, ArgoCD — commit to prod in minutes.

Kubernetes & Containers

Cluster design, Helm charts, multi-cluster ops, autoscaling.

Operate

03

Monitoring & Observability

Prometheus, Grafana, Loki, ELK — know before your users do.

K8s Cost Optimisation

Cluster analysis with ready-to-merge PRs. Paid from the savings.

Privacy-First Managed SRE

Your isolated EU instance — hosted, patched, backed up, watched.

Secure

03

Security & Resilience

Hardened baselines, secrets, disaster recovery, SLOs, runbooks.

NIS2 Readiness

Gap assessment, technical remediation, audit-ready checklist.

DNS & IaC Drift Monitor

Live DNS against your Terraform state. Alerts on drift and expiry.

Advise

01

Consulting & Support

Architecture reviews, team enablement, post-mortems, SRE retainers.

Review

Fixed price, two weeks. You get a written assessment with priorities and effort estimates — useful even if you stop there.

Project

Scoped and quoted before we start. Migrations, platform builds, pipeline rebuilds, observability from scratch.

Retainer

Monthly, an agreed number of days. Ongoing SRE capacity, on-call support and someone who already knows your setup.

Paid from savings

For cost work only. You pay a share of what the cluster actually stops costing you. If nothing is saved, nothing is owed.

About

Building infrastructure engineers trust.

I work with European B2B tech companies to build infrastructure that is secure, observable and built to scale — from zero to production.

Based in Helsinki, trading as a Finnish toiminimi, available across the EU and EEA.

Since 2005 keeping production systems running
Since 2016 doing it as DevOps and SRE

Long enough to have made most of these mistakes once already.

Approach

How the work actually gets done.

The tools change from one client to the next. These six do not.

Everything as code

Infrastructure, networks and policy live in Git and get reviewed like application code. Nothing is clicked into existence in a console.

Terraform · Terragrunt · Ansible

Git is the source of truth

The cluster follows the repository, never the other way round. A rollback is a revert, and anyone can read what production is supposed to look like.

Kubernetes · Helm · ArgoCD

You find out before your users

Metrics, logs and traces on every service, with alerts tied to what users actually feel rather than to raw CPU graphs.

Prometheus · Grafana · Loki · tracing

Capacity follows load

Nodes and workloads scale to real traffic, and right-sizing is a continuous job — not an annual panic when the bill arrives.

Karpenter · autoscaling · cost review

Secrets never sit in a repo

Credentials come from one place, live briefly, and can be revoked everywhere at once. Access is granted by role, not by memory.

Vault · managed secrets · SSO

Recoverable by design

A backup that has never been restored is a rumour. Restores are rehearsed on a schedule and the runbook is written before the incident.

Tested restores · DR runbooks

Contact

Start with thirty minutes.

No deck, no discovery questionnaire. Tell me what hurts, and I will tell you what I would fix first, roughly what it takes — and whether you actually need outside help for it.

You keep everything

Code lives in your repositories, infrastructure in your accounts. No proprietary tooling, no lock-in, and runbooks stay behind when I leave.

NDA before anything sensitive

Mutual NDA signed before access is discussed. Credentials go through your secret manager — never email, never chat.

With your team, not around it

Your engineers keep owning the platform. I work in your review process and hand over as I go, so nothing depends on me staying.

Finnish company, EU-only infrastructure

Registered toiminimi in Helsinki, Y-tunnus 3608757-4, invoiced in EUR with Finnish VAT. Everything I host runs in Germany and Finland — no data, backups or logs leave the EU, and none are planned to.

Based inHelsinki, Finland
EngagementsRemote across the EU & EEA