Production Kubernetes
A production-ready EKS, AKS, or GKE cluster delivered in one week by a senior CKA or CKS certified engineer. Terraform IaC, RBAC, networking, ingress, and runbooks. Fixed core price, optional add-ons for everything else.
Production cluster on EKS, AKS, or GKE
Terraform IaC you own from day one
RBAC, networking, ingress, cert-manager
3 production runbooks and a handover call
What's in the core setup
Six deliverables, end of week 1. Fixed price.
Production cluster
New EKS, AKS, or GKE cluster provisioned with production-grade defaults: multi-AZ, node groups, autoscaling enabled.
Terraform IaC
Modular Terraform code for the entire stack. Versioned in your Git repo. You own it.
Networking and ingress
VPC, subnets, security groups, ingress controller, cert-manager with Let's Encrypt automation.
RBAC baseline
Least-privilege Roles and RoleBindings, namespace structure, ServiceAccount hygiene.
3 production runbooks
Step-by-step procedures for the most common operational scenarios: scaling, rollback, node replacement.
Handover call
One-hour handover with your platform team. Walkthrough of the cluster, docs, and runbooks.
Optional add-ons
Stack only what you need. Each add-on is its own fixed-price productized service with a defined scope and timeline delta.
Observability Stack
Self-hosted Prometheus, Grafana, and Loki deployed on the cluster with starter dashboards and alerting.
- + Prometheus + Grafana + Loki deployed via Helm
- + 5 starter dashboards (cluster, workload, ingress, node, cost)
- + Alertmanager with 10 production-ready alert rules
- + Log retention configured for 30 days
GitOps with ArgoCD
ArgoCD installed and configured to deploy from your Git repo. Application of Apps pattern, RBAC, and notifications.
- + ArgoCD installed and configured
- + Application of Apps pattern set up
- + GitHub or GitLab integration
- + Sync notifications to Slack
Compliance Hardening
Hardened cluster posture for GDPR, UK GDPR, PDPL, NESA, HIPAA, or PIPEDA. Encryption, audit logging, network policies, and control mapping document.
- + Pod Security Admission enforced
- + Default-deny NetworkPolicies
- + Audit logging routed to long-term storage
- + Control mapping document for the chosen regulation
Workload Migration Support
Migration of one production service from your existing environment onto the new cluster, including Helm chart, CI pipeline, and validation.
- + Containerization review or refactor of one service
- + Helm chart authored and versioned
- + CI/CD pipeline updated
- + Cutover plan with rollback procedure
Multi-cluster Setup
Second cluster provisioned for staging, DR, or multi-region. Shared Terraform modules, identical configuration patterns.
- + Second cluster (different environment or region)
- + Shared Terraform modules across clusters
- + Cross-cluster service discovery considerations documented
- + Promotion workflow between clusters
Example bundles
How it works
Four phases. Five working days of senior engineer effort. One calendar week.
-
Kickoff
Day 0. 60-minute architecture call. Cloud account access set up, requirements captured, NDA signed. You meet the engineer building your cluster.
-
Provision
Days 1-2. Terraform written and applied. Cluster bootstrapped on EKS, AKS, or GKE with production defaults: multi-AZ, node groups, autoscaling.
-
Configure
Days 3-4. Networking, ingress controller, cert-manager, RBAC baseline, and 3 production runbooks. Cluster validated end-to-end.
-
Handover
Day 5. One-hour handover call. Walkthrough of the cluster, Terraform repo, runbooks, and operational handover to your team.
Core ($2,995)
- +Production EKS, AKS, or GKE cluster
- +Terraform IaC, committed to your repo
- +Networking, ingress, cert-manager
- +RBAC baseline and namespace structure
- +3 production runbooks
- +1-hour handover call with your team
- +14 days of post-handover Slack Q&A
Not in core (available as add-ons)
- -Observability stack ($1,495)
- -GitOps with ArgoCD ($995)
- -Compliance hardening ($2,495)
- -Workload migration support ($1,495)
- -Multi-cluster setup ($1,995)
- -Ongoing managed-services retainer
Who this is for
Good fit:
- Teams starting fresh on Kubernetes who want a production baseline done right the first time
- Teams rebuilding after a botched cluster setup
- Companies who want fixed pricing and a 1-week timeline, not a 12-week consulting engagement
Not a fit:
- Just need an opinion on an existing cluster - run the Audit ($495) instead
- Highly bespoke architecture requirements outside Kubernetes defaults
- Want ongoing operations - that's the managed retainer, not a one-time setup
Where this fits in the journey
Most teams come to Setup from one of two places.
Kubernetes Production Readiness Audit →
If you have an existing cluster and are not sure whether to fix it or start fresh, the $495 audit gives you the answer in 2 weeks.
Managed Kubernetes operations →
Once the cluster is live, our ongoing Kubernetes consulting and managed-services covers day-two operations, scaling, and incident response.
Frequently asked questions
Everything we get asked before someone books the Setup.
Which cluster types do you set up?
Amazon EKS, Azure AKS, or Google GKE - whichever fits your existing cloud account. We set up one cluster per engagement at the core price; additional clusters are available via the Multi-cluster add-on.
Why is the core scope so lean?
Most production clusters need a similar baseline: cluster + IaC + networking + RBAC. We price that baseline at a sub-procurement-threshold $2,995 so it is a fast yes. Anything beyond that baseline (observability, GitOps, compliance, migration, multi-cluster) is a defined add-on with its own price - you only pay for what you need.
Do I need to take the Audit first?
No. The Setup is a standalone product. That said, most teams who buy Setup either ran the Audit first (which surfaced gaps the Setup remediates) or are starting fresh on Kubernetes. If you have an existing cluster you are unsure about, the $495 Audit will tell you whether a fresh Setup or targeted fixes are the right move.
What does '1 week' actually mean?
5 working days of senior engineer effort, typically within 7-10 calendar days of the kickoff call. Add-ons extend the timeline (each add-on has a listed delta).
Who owns the Terraform code?
You do. The Terraform repo is yours from day one. We commit to your Git, document everything, and hand over operational control at the end of the engagement.
What if my cloud account is not set up yet?
We can advise on the initial cloud account structure as part of the kickoff, but the Setup price assumes you have an active AWS, Azure, or GCP account ready. If you need help setting up the cloud account itself, we will scope that separately.
Do you sign an NDA?
Yes. Standard mutual NDA signed before the kickoff call. We can sign your paper if your legal team prefers.
What happens after the handover?
Your team owns the cluster. If you want ongoing operational support, we offer a separate managed-services retainer. The Setup itself includes 14 days of post-handover Slack Q&A access to make sure nothing breaks during your team's onboarding.
Get a production cluster for $2,995
20-minute fit call first. We confirm your cloud account is ready, scope the work, and answer your questions.