Kubernetes expertise to tackle your production issues.
Because Kubernetes shouldn't need a platform team you don't have. Senior help for teams under 50 engineers — enterprise-grade discipline, sized for teams that can't copy the enterprise.
Nobody's problem is "Kubernetes."
It's always one of these five. Every note and every scorecard question on this site maps to one of them.
Costs nobody owns
"Your observability bill has its own line item now." Half of teams report costs went up after adopting Kubernetes — over-provisioning and log retention lead the list.
Deploys that feel risky
"Rolling updates are zero-downtime — except for the 503s." Rollback exists in theory; nobody has run it since it was configured.
One engineer knows everything
"The cluster works. Only one person knows why." That's not a platform — it's key-person risk with YAML on top.
Security reviews block deals
"The enterprise contract is waiting on a questionnaire you can't answer." RBAC, secrets and policies exist — undocumented and untested.
Upgrades postponed for a year
"Two versions behind, and afraid to touch it." Every deferred upgrade quietly raises the cost of the next one.
Enterprise discipline, small-team size.
Big organizations run Kubernetes safely because of habits, not headcount. The habits scale down. The machinery doesn't. Most Kubernetes advice adds weight — the useful move is subtracting it.
Copy the discipline
- Named ownership — a person, not "everyone"
- Everything in Git; rollback that's actually been run
- A restore that has been tested, not assumed
- Upgrades on a calendar, twice a year
- RBAC and secrets you could show an auditor
- Runbooks for the top five failure scenarios
Skip the machinery
- Multi-cluster, multi-region before multi-customer problems
- A service mesh "because security" — start with NetworkPolicies
- An internal developer portal for five engineers
- Change advisory boards — your PR review is the change process
- Every logo on the CNCF landscape — it's a map, not a shopping list
- Observing everything instead of answering three questions fast
Senior help, fixed scope.
Audit-first engagements with a deliverable and an end date — never a retainer you can't leave. The goal is always that your team operates the platform without me.
Production Readiness Audit
Read-only, 2 weeks: risk map, cost opportunity in €/month, 10-item remediation backlog.
Details → cloudManaged K8s: AKS · EKS · GKE
Migrations, landing zones, and honest advice on which cloud tier you actually need.
Details → service meshIstio Service Mesh
Traffic, mTLS and observability — including the assessment that says "not yet."
Details → finopsCost Optimization
Typical first-audit outcome: 30–60% off the bill, no architecture changes, no new tools.
Details → securitySecurity & Compliance Baseline
Everything the enterprise questionnaire will ask — done before the deal appears.
Details → all servicesFull catalog →
Operations, observability & GitOps, team enablement, and the Audit → Stabilize → Enable engagement model.
See all 8 services →Free samples of the criteria.
The Kubernetes checklist for teams without a platform team
The minimum viable discipline for production — and the enterprise baggage to refuse.
Read → triageThe first 10 things I'd check in a messy cluster
A 90-minute, read-only triage: risk map, cost estimate and a prioritized backlog.
Read → cost8 Kubernetes cost leaks small teams miss
Requests copied from tutorials, logs kept forever, one load balancer per service.
Read → deploysWhy rolling updates still give you 503s
Rolling updates guarantee replacement order, not traffic correctness. Four causes, four fixes.
Read → auditThe Kubernetes audit worksheet
Assess your own cluster in half a day — every command read-only, three artifacts out.
Read → interactiveProduction Readiness Scorecard
50 questions, scored 0–100 in your browser. The fastest honest picture of where your cluster stands.
Start scoring →An SRE working in enterprise finance, documenting how to shrink enterprise-grade Kubernetes discipline down to small-team size. I live the heavyweight version daily; these notes are the lightweight one. More about the project →
One field-tested pattern per week.
Production Kubernetes for small teams, in your inbox. No vendor pitches, no tool-of-the-week, unsubscribe anytime.
Your address is used for the newsletter only. Details in the privacy policy.