opsZero Proposal
About opsZero
opsZero is a Kubernetes/Containers focused DevOps Agency building Cloud Infrastructure for startups, SMB and mid-market organizations with compliance requirements such as SOC2, HIPAA and PCI-DSS. With a decade of experience with Kubernetes and the Cloud including AWS, Azure and Google Cloud we have created production ready Cloud environments that can scale to handle any workload whether web or AI.
We work as your Kubernetes DevOps team doing everything from building new environments, setting up logging and monitoring, setting up CI/CD processes for your microservices and debugging any issue on the application side across any Cloud or On-Prem environments. We can either take over your existing Cloud infrastructure or build a new infrastructure with our Terraform modules.
Collaboration
| Resource | Description |
|---|---|
| Communication + Support | Submit a ticket, contact us via Slack, Teams, or schedule a video call. |
| Deployment Schedule | To schedule a deployment with us, just add it to our calendar. |
| Planning + Project Management | We are happy to integrate into any of your existing project management platforms, such as Jira, Asana, or GitHub. Our sprint planning is weekly on Monday night pacific and runs until the following Monday. Tell us if you need something by the following Monday. |
Sample Architecture
Standard Tools
-
Google Workspace or Azure AD (SSO): Configured as the identity provider.
-
Cloudflare: Setup for CDN, Zero Trust, Tunnel, and DNS.
-
GitHub: Deployments, CI/CD, and Secrets.
-
AWS/Azure/GCP: Kubernetes and databases. We minimize the Cloud-specific tooling you use to ensure portability across Cloud providers. All are configured for security posture that includes encryption at rest and ACL.
-
AI Workloads: Kubernetes optimized for AI Pipelines such as LLMs, PyTorch and TensorFlow with NVidia and Ampere optimized deployments.
-
BI: If you have external BI tooling like Metabase, Hevo, Fivetran, and Snowflake. We can set them up and connect to your AWS/Azure/GCP.
Terraform Catalog
We have built an extensive open source Terraform catalog that we use to build infrastructure. This code has been tested and focuses on compliance requirements.
| terraform-aws-airflow ↗ | Deploy Apache Airflow workflow orchestration on AWS EKS. |
| terraform-aws-aurora ↗ | Provision AWS Aurora RDS clusters with compliance-ready security settings. |
| terraform-aws-bitbucket-oidc ↗ | Configure OIDC trust between Bitbucket Pipelines and AWS for keyless deployments. |
| terraform-aws-cloudflare-security-group ↗ | Create AWS security groups allowing traffic from Cloudflare IP ranges. |
| terraform-aws-cloudwatch-to-s3-archiver ↗ | Archive AWS CloudWatch logs to S3 for long-term retention. |
| terraform-aws-compliance-hub ↗ | Enable AWS Security Hub and compliance standards for SOC2, HIPAA, and PCI. |
| terraform-aws-documentdb ↗ | Provision AWS DocumentDB (MongoDB-compatible) clusters with secure defaults. |
| terraform-aws-ecr ↗ | Create and manage AWS Elastic Container Registry repositories. |
| terraform-aws-eks-airbyte ↗ | Deploy Airbyte data integration platform on AWS EKS. |
| terraform-aws-eks-efs ↗ | Provision AWS EFS storage as a persistent volume on EKS. |
| terraform-aws-eks-mageai ↗ | Deploy Mage AI data pipeline orchestration on AWS EKS. |
| terraform-aws-eks-metabase ↗ | Deploy Metabase business intelligence tool on AWS EKS. |
| terraform-aws-eks-n8n ↗ | Deploy n8n workflow automation platform on AWS EKS. |
| terraform-aws-elasticache ↗ | Provision AWS ElastiCache Redis or Memcached clusters with secure defaults. |
| terraform-aws-elb-cloudwatch ↗ | Set up CloudWatch alarms and dashboards for AWS Elastic Load Balancers. |
| terraform-aws-github-security-group ↗ | Create AWS security groups allowing traffic from GitHub Actions IP ranges. |
| terraform-aws-iam ↗ | Manage AWS IAM users, groups, roles, and policies with MFA enforcement. |
| terraform-aws-iam-identity-center ↗ | Configure AWS IAM Identity Center (SSO) with permission sets and account assignments. |
| terraform-aws-instance ↗ | Provision AWS EC2 instances with secure defaults and compliance-ready settings. |
| terraform-aws-kubespot ↗ | Compliance-ready Kubernetes on AWS EKS with SOC2 and HIPAA support. |
| terraform-aws-memorydb ↗ | Provision AWS MemoryDB for Redis with high availability and compliance settings. |
| terraform-aws-mongodbatlas ↗ | Provision MongoDB Atlas clusters with AWS private endpoint integration. |
| terraform-aws-oidc-github ↗ | Configure OIDC trust between GitHub Actions and AWS for keyless deployments. |
| terraform-aws-oidc-gitlab ↗ | Configure OIDC trust between GitLab CI and AWS for keyless deployments. |
| terraform-aws-opensearch ↗ | Provision AWS OpenSearch clusters with fine-grained access control and encryption. |
| terraform-aws-rds ↗ | Provision AWS RDS databases with encryption, backups, and compliance settings. |
| terraform-aws-rds-cross-region-backup ↗ | Automate cross-region backups of AWS RDS snapshots for disaster recovery. |
| terraform-aws-redshift-serverless ↗ | Provision AWS Redshift Serverless namespaces and workgroups. |
| terraform-aws-s3 ↗ | Terraform module to create a default S3 bucket with logging and custom encryption settings. |
| terraform-aws-security-group ↗ | Create reusable AWS security groups with standard ingress and egress rules. |
| terraform-aws-sqs ↗ | Create AWS SQS queues with encryption and dead-letter queue support. |
| terraform-aws-ssm ↗ | Manage AWS Systems Manager Parameter Store secrets and session manager access. |
| terraform-aws-subnets ↗ | Create public and private subnets across AWS availability zones. |
| terraform-aws-vpc ↗ | Provision a production-ready AWS VPC with subnets, routing, and NAT gateways. |
| terraform-aws-workspaces ↗ | Provision AWS WorkSpaces virtual desktops with directory and security configuration. |
| terraform-azure-postgresql ↗ | Provision Azure Database for PostgreSQL with secure defaults. |
| terraform-azuread-mrmgr ↗ | Manage Azure Active Directory service principals and federated identity credentials. |
| terraform-azurerm-acs ↗ | Provision Azure Communication Services for email and SMS integration. |
| terraform-azurerm-entra-id ↗ | Manage Azure Entra ID users, groups, roles, and conditional access policies. |
| terraform-azurerm-flexible-postgresql ↗ | Provision Azure Flexible Server PostgreSQL with compliance-ready configuration. |
| terraform-azurerm-kubespot ↗ | Compliance-ready Kubernetes on Azure AKS with SOC2 and HIPAA support. |
| terraform-azurerm-subnet ↗ | Create and manage Azure virtual network subnets with service endpoint support. |
| terraform-azurerm-vnet ↗ | Provision Azure Virtual Networks with configurable address spaces and DNS settings. |
| terraform-azurerm-vnet-peering ↗ | Establish VNet peering between Azure Virtual Networks across regions. |
| terraform-cloudflare-domain ↗ | Manage Cloudflare DNS records, zones, and domain security settings. |
| terraform-datadog-helm-kubespot ↗ | Deploy and configure Datadog monitoring agent on Kubespot Kubernetes clusters. |
| terraform-github-mrmgr ↗ | Manage GitHub organization teams, repositories, and member permissions. |
| terraform-google-iam ↗ | Manages multiple IAM roles for resources on Google Cloud. |
| terraform-google-kubespot ↗ | Compliance-ready Kubernetes on Google Cloud GKE with SOC2 and HIPAA support. |
| terraform-google-mrmgr ↗ | Manage Google Cloud IAM service accounts and workload identity federation. |
| terraform-helm-aws-vault ↗ | Deploy HashiCorp Vault secrets manager on Kubernetes. |
| terraform-helm-celery-exporter ↗ | Deploy Celery metrics exporter for monitoring task queues on Kubernetes. |
| terraform-helm-kubespot ↗ | Deploy core opsZero Kubespot platform services on Kubernetes. |
| terraform-helm-meilisearch ↗ | Deploy Meilisearch fast search engine on Kubernetes. |
| terraform-helm-openreplay ↗ | Deploy OpenReplay session replay and analytics on Kubernetes. |
| terraform-helm-opentelemetry ↗ | Deploy OpenTelemetry collector for distributed tracing on Kubernetes. |
| terraform-helm-spicedb-operator ↗ | Deploy SpiceDB operator for fine-grained authorization on Kubernetes. |
| terraform-helm-splunk ↗ | Deploy Splunk log aggregation and monitoring on Kubernetes. |
| terraform-kubernetes-airflow ↗ | Deploy Apache Airflow workflow orchestration on Kubernetes. |
| terraform-kubernetes-socat ↗ | Deploy socat TCP proxy as a Kubernetes service for port forwarding. |
| terraform-template ↗ | Terraform module template with opsZero standard structure and compliance defaults. |
Compliance
opsZero Kubespot, provides out-of-the-box compliance, saving you thousands of dollars and hundreds of hours building a compliant environment from scratch. We provide compliance remediation services for the following frameworks. We are able to work within any compliance automation system and have experience with Drata, Secureframe, and Vanta among others. As an official Vanta partner, we can provide preferential rates and support for all Vanta products.
- SOC 2
- HIPAA
- PCI-DSS
- GDPR
- CCPA / USDP
- FedRamp / StateRamp
- CMMC
- ISO 27001
Work Process
Solution Architecture
We collaborate closely with your engineering team to design a robust and scalable infrastructure tailored to your specific business needs. This involves a comprehensive analysis of your requirements, considering various cloud provider options (AWS, Azure, GCP, Oracle etc.), evaluating suitable 3rd party tools, and factoring in budgetary constraints. We help you navigate the complexities of cloud infrastructure, ensuring the chosen architecture aligns with your long-term goals.
Onboarding and Environment Setup
Once the scope of work is defined and agreed upon, we initiate the onboarding process. This involves gaining necessary access to your existing infrastructure, if applicable. Alternatively, we can assist in spinning up entirely new cloud environments, configuring them according to the agreed-upon design. This stage focuses on minimizing disruption and ensuring a smooth transition.
Infrastructure as Code (IaC) with Containerization and Orchestration
We leverage Terraform to codify and containerize your infrastructure. This Infrastructure as Code approach allows us to automate the provisioning and management of your cloud resources. This offers several key advantages:
- Rapid Deployment: Quickly spin up new environments, replicating existing configurations with ease.
- Consistency: Maintain a consistent infrastructure state, minimizing configuration drift and reducing errors.
- Version Control: Track changes to your infrastructure code, enabling rollback to previous versions if needed.
- Disaster Recovery: Recreate your infrastructure quickly in case of outages or disasters.
We utilize Kubernetes as the container orchestrator, enabling portability across different cloud providers or even on-premises systems. This means your applications can be deployed and managed consistently, regardless of the underlying infrastructure. Kubernetes also provides advanced features for scaling, load balancing, and self-healing of your containerized applications.
Continuous Integration and Continuous Delivery (CI/CD) Pipelines
We establish robust CI/CD pipelines to automate the software development and deployment process. This includes automating the deployment of your applications to various environments (development, staging, production), reducing manual effort and minimizing deployment risks.
Systems Integrations, Observability, and AI Workloads
We integrate your systems with best-of-breed observability and AI-powered tools, focusing on well-tested open-source options where possible. This includes:
- Monitoring: Real-time monitoring of your infrastructure and applications, providing insights into performance, availability, and resource utilization.
- Logging: Centralized logging to capture application and system events, facilitating troubleshooting and analysis.
- Alerting: Configurable alerts to notify both teams of critical issues, enabling proactive intervention.
- AI Workloads: We set up and integrate AI tools, including PyTorch and TensorFlow, into your infrastructure. We handle the configuration and integration, and develop models tailored to your specific needs if required.
Ongoing Support and Optimization
Beyond the initial setup, we provide ongoing support, including:
- Upgrades and Maintenance: Regularly updating and maintaining your infrastructure and software to ensure security and performance.
- Cost/Resource Optimization: Continuously analyzing your cloud spending and resource utilization to identify opportunities for cost savings and efficiency improvements.
- Incident Response: SLA based incident response to address any issues that may arise, minimizing downtime and ensuring business continuity.
- Compliance Remediation: For organizations with regulatory requirements (e.g., HIPAA, PCI DSS, GDPR), we provide compliance remediation services to ensure your infrastructure meets the necessary standards. This includes gap analysis, implementation of controls, and ongoing monitoring.
Standardization
All our tools are open source and do not lock you into a proprietary system. We provide a standardized infrastructure repository, CI/CD, and deployment methodology across our customers to provide a streamlined process and optimize costs. This common core allows us to rapidly respond to and assist our customers resulting in a better quality of service.
Privacy & Security
All data is stored within your AWS account.
- Code is stored within an infrastructure repository controlled by your organization and you may revoke access at any time.
- Data will be deleted upon request.
- We only work using IAM users, not root accounts. Customers provide us with IAM user credentials that we use to work within your environments.
- No databases or customer data will be stored on local machines. All data dumps will happen within a Virtual Machine Instance within your Cloud environment never touching a local environment.
- Items stored locally
- AWS IAM Keys
- Git Repositories
- Access to the Cloud Environment is limited to those that need to know and we rotate IAM keys once a week.
- We follow SOC 2 guidelines for creating an audit trail by creating tickets for resolving issues before applying them.
Specific Tasks
- Migrations
- VMWare to Kubernetes
- Kubernetes Troubleshooting & Upgrades
- CI/CD Deployment
- Infrastructure as Code through Terraform
- Architecture Advisory
- Kubernetes Upgrades
- Security Upgrades
- Identity - Adding, removing, and configuring of IAM/SSO User Roles
- Compliance - auditing and remediation for SCO2, PCI, and HIPAA issues through Vanta.
- Application Tracing and Performance Monitoring - Setup and configuration of Datadog
- CI/CD pipeline optimization - Build time and cost reduction
- Kubernetes deployment monitoring
- Kubernetes cluster monitoring, upgrades, and node cycling
- Compute instance optimization
- Database storage monitoring and password rotations
- Reserved instance purchasing
- Cloud Native architecture consulting - effective use of Spot Instances, ARM Instances, and Autoscaling
- Storage and Bandwidth cost optimizations
- Kubernetes limit and request tuning
- Terraform state drift management
Pricing
Seed$1250 Per month | Most Popular Startup$2500 Per month | Growth$5000 Per month | |
|---|---|---|---|
| DevOps | |||
| Hours Included | 20 hours per month | 40 hours per month | 80 hours per month |
| Additional | $150/hour | $125/hour | $100/hour |
| Engineer | Partial | Partial | Dedicated |
| SLA | 8-5pm PT Weekdays 60 min response time | 24/7 30 min response time | 24/7 15 min response time |
| Support | Slack | Slack Microsoft Teams Google Chat | Slack Microsoft Teams Google Chat |
| Cloud | AWS GCP Azure | AWS GCP Azure Bare Metal/Edge | AWS GCP Azure Bare Metal/Edge Any |
| GovCloud | ✖ | ✖ | ✔️ |
| IaaC | Terraform | Terraform | Terraform |
| Kubernetes | |||
| Features | 2 Clusters 4 Apps | 4 Clusters 8 Apps | Unlimited Clusters Unlimited Apps |
| Updates and Patches | Continuous | Continuous | Continuous |
| CI/CD | GitHub Actions | GitHub Actions GitLab BitBucket | GitHub Actions GitLab BitBucket Jenkins |
| Secrets | GitHub Secrets | GitHub Secrets AWS Secret Manager Google Secret Manager Azure Key Vault Doppler | GitHub Secrets AWS Secret Manager Google Secret Manager Azure Key Vault Doppler |
| Identity | |||
| SSO | Google Okta Entra | Google Okta Entra | |
| Compliance | |||
| Compliance Frameworks | CIS Benchmark HIPAA | CIS Benchmark HIPAA | CIS Benchmark HIPAA PCI-DSS SOC 2 CMMC |
| Compliance Platform | Vanta Drata | Vanta Drata Secureframe | Any |
| Vanta Task Management | ✖ | ✔ | ✔ |
| Drata Task Management | ✖ | ✔ | ✔ |
| Compliance Remediation | ✖ | ✔ (Single) | ✔ (Multiple) |
| Included Integrations | Nginx Cert Manager Prometheus Grafana Keda | Nginx Cert Manager Prometheus Grafana Keda | Nginx Cert Manager Prometheus Grafana Keda |
| DBA | |||
| Database | 1 per cluster | 2 per cluster | Unlimited |
| Data Warehouse | ✖ None | 1 Cluster | Unlimited |
| FinOps | |||
| Savings Plans (AWS) | ✔ | ✔ | ✔ |
Partners
- Advantage Partners. Pentesting and SOC2 Auditing.
- 1280 Labs. Developers as a Service
- Helium Ventures. Sell your business