Cloud infrastructure & DevOps
From Hetzner VPS for MVPs to multi-region Kubernetes — CI/CD, monitoring, backup, and security baseline included.
Cloud provider — which fits you
Hetzner Cloud
3-5x cheaper than AWS for stable workloads. EU datacenters (Falkenstein, Helsinki). Recommended for RO/EU SaaS.
AWS
For apps with extensive managed services: Lambda, Aurora, SQS, EventBridge, AI/ML.
Google Cloud
BigQuery, Vertex AI, native Kubernetes. For data-heavy applications and analytics.
Azure
Enterprise Microsoft stack, Active Directory integration, .NET workloads.
Cloudflare
CDN, DDoS protection, Workers, R2 storage. Combine with any cloud for edge.
Multi-cloud
For vendor lock-in resistance: critical workload on 2 clouds, automated failover.
Numbers behind it: AWS vs Hetzner — real cost analysis for SaaS under 100k monthly active users.
Infrastructure services
Setup & architecture
- Architecture design: high availability, auto-scaling, multi-AZ/multi-region
- Infrastructure as Code: Terraform, Pulumi (everything versioned in git)
- Network: VPC, subnets, security groups, WAF, NAT gateway
- DNS: Cloudflare, Route 53, Hetzner DNS — DNSSEC, CAA records
- SSL/TLS: auto Let's Encrypt, enterprise certificates for pinning
Containerization & orchestration
- Docker: containerize existing apps, multi-stage builds, image scanning (Trivy)
- Kubernetes: K3s for small-scale, EKS/GKE for enterprise, ArgoCD for GitOps
- Service mesh: Istio or Linkerd when scale requires
- Custom Helm charts for your apps
CI/CD & deployment
- GitHub Actions, GitLab CI, CircleCI
- Auto deploy: zero-downtime (blue-green, canary, rolling)
- Instant rollback to previous version
- Preview environments per PR
- Secret management: Vault, AWS Secrets Manager, Doppler
Monitoring & observability
- Metrics: Prometheus + Grafana, Datadog, New Relic
- Logs: Loki, ELK stack, CloudWatch, Better Stack
- Distributed tracing: OpenTelemetry, Jaeger, Tempo
- Error tracking: Sentry for frontend + backend
- Uptime monitoring: Better Stack, UptimeRobot, custom synthetics
- Alerting: Slack, PagerDuty, Opsgenie with oncall rotation
Backup & disaster recovery
- Automated daily DB backup with 30+ days retention
- Off-site backup (different region or different cloud)
- Monthly restore drills — we actually verify backups work
- Defined RTO & RPO in SLA
- Point-in-time recovery for PostgreSQL/MySQL
Security
- Server hardening: SSH keys-only, fail2ban, automatic security updates
- WAF: Cloudflare, AWS WAF, ModSecurity
- DDoS protection
- Periodic vulnerability scanning (Nessus, Trivy, Snyk)
- Annual penetration testing recommended
- Compliance: ISO 27001 prep, SOC 2, GDPR audit trail
Indicative structure and service levels are on our pricing page — I reply with next steps after a short discussion.
See examples of delivered projects.
FAQ
How much does SaaS hosting cost?
Do you do 24/7 oncall?
Yes, in Premium plan. Rotation between 2-3 engineers, Slack/PagerDuty alerts, 30 min response for critical, runbook for any scenario.
Migration from shared hosting?
Yes, frequent: cPanel → Hetzner VPS, GoDaddy → AWS. We include app audit, zero-downtime plan, pre-migration backup, gradual DNS cutover.
ISO/SOC 2 compliance?
We set technical baseline (encryption at rest/transit, audit logs, access reviews, backup, DR plan). We don't issue certifications — but we prepare you for auditors (Drata, Vanta).