Skip to main content

opsZero Proposal

About opsZero

opsZero is a Kubernetes/Containers focused DevOps Agency building Cloud Infrastructure for startups, SMB and mid-market organizations with compliance requirements such as SOC2, HIPAA and PCI-DSS. With a decade of experience with Kubernetes and the Cloud including AWS, Azure and Google Cloud we have created production ready Cloud environments that can scale to handle any workload whether web or AI.

We work as your Kubernetes DevOps team doing everything from building new environments, setting up logging and monitoring, setting up CI/CD processes for your microservices and debugging any issue on the application side across any Cloud or On-Prem environments. We can either take over your existing Cloud infrastructure or build a new infrastructure with our Terraform modules.

Collaboration

ResourceDescription
Communication + SupportSubmit a ticket, contact us via Slack, Teams, or schedule a video call.
Deployment ScheduleTo schedule a deployment with us, just add it to our calendar.
Planning + Project ManagementWe are happy to integrate into any of your existing project management platforms, such as Jira, Asana, or GitHub. Our sprint planning is weekly on Monday night pacific and runs until the following Monday. Tell us if you need something by the following Monday.

Sample Architecture

Standard Tools

  1. Google Workspace or Azure AD (SSO): Configured as the identity provider.

  2. Cloudflare: Setup for CDN, Zero Trust, Tunnel, and DNS.

  3. GitHub: Deployments, CI/CD, and Secrets.

  4. AWS/Azure/GCP: Kubernetes and databases. We minimize the Cloud-specific tooling you use to ensure portability across Cloud providers. All are configured for security posture that includes encryption at rest and ACL.

  5. AI Workloads: Kubernetes optimized for AI Pipelines such as LLMs, PyTorch and TensorFlow with NVidia and Ampere optimized deployments.

  6. BI: If you have external BI tooling like Metabase, Hevo, Fivetran, and Snowflake. We can set them up and connect to your AWS/Azure/GCP.

Terraform Catalog

We have built an extensive open source Terraform catalog that we use to build infrastructure. This code has been tested and focuses on compliance requirements.

terraform-aws-airflow Deploy Apache Airflow workflow orchestration on AWS EKS.
terraform-aws-aurora Provision AWS Aurora RDS clusters with compliance-ready security settings.
terraform-aws-bitbucket-oidc Configure OIDC trust between Bitbucket Pipelines and AWS for keyless deployments.
terraform-aws-cloudflare-security-group Create AWS security groups allowing traffic from Cloudflare IP ranges.
terraform-aws-cloudwatch-to-s3-archiver Archive AWS CloudWatch logs to S3 for long-term retention.
terraform-aws-compliance-hub Enable AWS Security Hub and compliance standards for SOC2, HIPAA, and PCI.
terraform-aws-documentdb Provision AWS DocumentDB (MongoDB-compatible) clusters with secure defaults.
terraform-aws-ecr Create and manage AWS Elastic Container Registry repositories.
terraform-aws-eks-airbyte Deploy Airbyte data integration platform on AWS EKS.
terraform-aws-eks-efs Provision AWS EFS storage as a persistent volume on EKS.
terraform-aws-eks-mageai Deploy Mage AI data pipeline orchestration on AWS EKS.
terraform-aws-eks-metabase Deploy Metabase business intelligence tool on AWS EKS.
terraform-aws-eks-n8n Deploy n8n workflow automation platform on AWS EKS.
terraform-aws-elasticache Provision AWS ElastiCache Redis or Memcached clusters with secure defaults.
terraform-aws-elb-cloudwatch Set up CloudWatch alarms and dashboards for AWS Elastic Load Balancers.
terraform-aws-github-security-group Create AWS security groups allowing traffic from GitHub Actions IP ranges.
terraform-aws-iam Manage AWS IAM users, groups, roles, and policies with MFA enforcement.
terraform-aws-iam-identity-center Configure AWS IAM Identity Center (SSO) with permission sets and account assignments.
terraform-aws-instance Provision AWS EC2 instances with secure defaults and compliance-ready settings.
terraform-aws-kubespot Compliance-ready Kubernetes on AWS EKS with SOC2 and HIPAA support.
terraform-aws-memorydb Provision AWS MemoryDB for Redis with high availability and compliance settings.
terraform-aws-mongodbatlas Provision MongoDB Atlas clusters with AWS private endpoint integration.
terraform-aws-oidc-github Configure OIDC trust between GitHub Actions and AWS for keyless deployments.
terraform-aws-oidc-gitlab Configure OIDC trust between GitLab CI and AWS for keyless deployments.
terraform-aws-opensearch Provision AWS OpenSearch clusters with fine-grained access control and encryption.
terraform-aws-rds Provision AWS RDS databases with encryption, backups, and compliance settings.
terraform-aws-rds-cross-region-backup Automate cross-region backups of AWS RDS snapshots for disaster recovery.
terraform-aws-redshift-serverless Provision AWS Redshift Serverless namespaces and workgroups.
terraform-aws-s3 Terraform module to create a default S3 bucket with logging and custom encryption settings.
terraform-aws-security-group Create reusable AWS security groups with standard ingress and egress rules.
terraform-aws-sqs Create AWS SQS queues with encryption and dead-letter queue support.
terraform-aws-ssm Manage AWS Systems Manager Parameter Store secrets and session manager access.
terraform-aws-subnets Create public and private subnets across AWS availability zones.
terraform-aws-vpc Provision a production-ready AWS VPC with subnets, routing, and NAT gateways.
terraform-aws-workspaces Provision AWS WorkSpaces virtual desktops with directory and security configuration.
terraform-azure-postgresql Provision Azure Database for PostgreSQL with secure defaults.
terraform-azuread-mrmgr Manage Azure Active Directory service principals and federated identity credentials.
terraform-azurerm-acs Provision Azure Communication Services for email and SMS integration.
terraform-azurerm-entra-id Manage Azure Entra ID users, groups, roles, and conditional access policies.
terraform-azurerm-flexible-postgresql Provision Azure Flexible Server PostgreSQL with compliance-ready configuration.
terraform-azurerm-kubespot Compliance-ready Kubernetes on Azure AKS with SOC2 and HIPAA support.
terraform-azurerm-subnet Create and manage Azure virtual network subnets with service endpoint support.
terraform-azurerm-vnet Provision Azure Virtual Networks with configurable address spaces and DNS settings.
terraform-azurerm-vnet-peering Establish VNet peering between Azure Virtual Networks across regions.
terraform-cloudflare-domain Manage Cloudflare DNS records, zones, and domain security settings.
terraform-datadog-helm-kubespot Deploy and configure Datadog monitoring agent on Kubespot Kubernetes clusters.
terraform-github-mrmgr Manage GitHub organization teams, repositories, and member permissions.
terraform-google-iam Manages multiple IAM roles for resources on Google Cloud.
terraform-google-kubespot Compliance-ready Kubernetes on Google Cloud GKE with SOC2 and HIPAA support.
terraform-google-mrmgr Manage Google Cloud IAM service accounts and workload identity federation.
terraform-helm-aws-vault Deploy HashiCorp Vault secrets manager on Kubernetes.
terraform-helm-celery-exporter Deploy Celery metrics exporter for monitoring task queues on Kubernetes.
terraform-helm-kubespot Deploy core opsZero Kubespot platform services on Kubernetes.
terraform-helm-meilisearch Deploy Meilisearch fast search engine on Kubernetes.
terraform-helm-openreplay Deploy OpenReplay session replay and analytics on Kubernetes.
terraform-helm-opentelemetry Deploy OpenTelemetry collector for distributed tracing on Kubernetes.
terraform-helm-spicedb-operator Deploy SpiceDB operator for fine-grained authorization on Kubernetes.
terraform-helm-splunk Deploy Splunk log aggregation and monitoring on Kubernetes.
terraform-kubernetes-airflow Deploy Apache Airflow workflow orchestration on Kubernetes.
terraform-kubernetes-socat Deploy socat TCP proxy as a Kubernetes service for port forwarding.
terraform-template Terraform module template with opsZero standard structure and compliance defaults.

Compliance

opsZero Kubespot, provides out-of-the-box compliance, saving you thousands of dollars and hundreds of hours building a compliant environment from scratch. We provide compliance remediation services for the following frameworks. We are able to work within any compliance automation system and have experience with Drata, Secureframe, and Vanta among others. As an official Vanta partner, we can provide preferential rates and support for all Vanta products.

  • SOC 2
  • HIPAA
  • PCI-DSS
  • GDPR
  • CCPA / USDP
  • FedRamp / StateRamp
  • CMMC
  • ISO 27001

Work Process

Solution Architecture

We collaborate closely with your engineering team to design a robust and scalable infrastructure tailored to your specific business needs. This involves a comprehensive analysis of your requirements, considering various cloud provider options (AWS, Azure, GCP, Oracle etc.), evaluating suitable 3rd party tools, and factoring in budgetary constraints. We help you navigate the complexities of cloud infrastructure, ensuring the chosen architecture aligns with your long-term goals.

Onboarding and Environment Setup

Once the scope of work is defined and agreed upon, we initiate the onboarding process. This involves gaining necessary access to your existing infrastructure, if applicable. Alternatively, we can assist in spinning up entirely new cloud environments, configuring them according to the agreed-upon design. This stage focuses on minimizing disruption and ensuring a smooth transition.

Infrastructure as Code (IaC) with Containerization and Orchestration

We leverage Terraform to codify and containerize your infrastructure. This Infrastructure as Code approach allows us to automate the provisioning and management of your cloud resources. This offers several key advantages:

  • Rapid Deployment: Quickly spin up new environments, replicating existing configurations with ease.
  • Consistency: Maintain a consistent infrastructure state, minimizing configuration drift and reducing errors.
  • Version Control: Track changes to your infrastructure code, enabling rollback to previous versions if needed.
  • Disaster Recovery: Recreate your infrastructure quickly in case of outages or disasters.

We utilize Kubernetes as the container orchestrator, enabling portability across different cloud providers or even on-premises systems. This means your applications can be deployed and managed consistently, regardless of the underlying infrastructure. Kubernetes also provides advanced features for scaling, load balancing, and self-healing of your containerized applications.

Continuous Integration and Continuous Delivery (CI/CD) Pipelines

We establish robust CI/CD pipelines to automate the software development and deployment process. This includes automating the deployment of your applications to various environments (development, staging, production), reducing manual effort and minimizing deployment risks.

Systems Integrations, Observability, and AI Workloads

We integrate your systems with best-of-breed observability and AI-powered tools, focusing on well-tested open-source options where possible. This includes:

  • Monitoring: Real-time monitoring of your infrastructure and applications, providing insights into performance, availability, and resource utilization.
  • Logging: Centralized logging to capture application and system events, facilitating troubleshooting and analysis.
  • Alerting: Configurable alerts to notify both teams of critical issues, enabling proactive intervention.
  • AI Workloads: We set up and integrate AI tools, including PyTorch and TensorFlow, into your infrastructure. We handle the configuration and integration, and develop models tailored to your specific needs if required.

Ongoing Support and Optimization

Beyond the initial setup, we provide ongoing support, including:

  • Upgrades and Maintenance: Regularly updating and maintaining your infrastructure and software to ensure security and performance.
  • Cost/Resource Optimization: Continuously analyzing your cloud spending and resource utilization to identify opportunities for cost savings and efficiency improvements.
  • Incident Response: SLA based incident response to address any issues that may arise, minimizing downtime and ensuring business continuity.
  • Compliance Remediation: For organizations with regulatory requirements (e.g., HIPAA, PCI DSS, GDPR), we provide compliance remediation services to ensure your infrastructure meets the necessary standards. This includes gap analysis, implementation of controls, and ongoing monitoring.

Standardization

All our tools are open source and do not lock you into a proprietary system. We provide a standardized infrastructure repository, CI/CD, and deployment methodology across our customers to provide a streamlined process and optimize costs. This common core allows us to rapidly respond to and assist our customers resulting in a better quality of service.

Privacy & Security

All data is stored within your AWS account.

  • Code is stored within an infrastructure repository controlled by your organization and you may revoke access at any time.
  • Data will be deleted upon request.
  • We only work using IAM users, not root accounts. Customers provide us with IAM user credentials that we use to work within your environments.
  • No databases or customer data will be stored on local machines. All data dumps will happen within a Virtual Machine Instance within your Cloud environment never touching a local environment.
  • Items stored locally
  • AWS IAM Keys
  • Git Repositories
  • Access to the Cloud Environment is limited to those that need to know and we rotate IAM keys once a week.
  • We follow SOC 2 guidelines for creating an audit trail by creating tickets for resolving issues before applying them.

Specific Tasks

  • Migrations
  • VMWare to Kubernetes
  • Kubernetes Troubleshooting & Upgrades
  • CI/CD Deployment
  • Infrastructure as Code through Terraform
  • Architecture Advisory
  • Kubernetes Upgrades
  • Security Upgrades
  • Identity - Adding, removing, and configuring of IAM/SSO User Roles
  • Compliance - auditing and remediation for SCO2, PCI, and HIPAA issues through Vanta.
  • Application Tracing and Performance Monitoring - Setup and configuration of Datadog
  • CI/CD pipeline optimization - Build time and cost reduction
  • Kubernetes deployment monitoring
  • Kubernetes cluster monitoring, upgrades, and node cycling
  • Compute instance optimization
  • Database storage monitoring and password rotations
  • Reserved instance purchasing
  • Cloud Native architecture consulting - effective use of Spot Instances, ARM Instances, and Autoscaling
  • Storage and Bandwidth cost optimizations
  • Kubernetes limit and request tuning
  • Terraform state drift management

Pricing

Seed

$1250

Per month

Growth

$5000

Per month

DevOps
Hours Included20 hours per month40 hours per month80 hours per month
Additional$150/hour$125/hour$100/hour
Engineer
Partial

Partial

Dedicated
SLA8-5pm PT Weekdays
60 min response time
24/7
30 min response time
24/7
15 min response time
SupportSlack
Slack
Microsoft Teams
Google Chat
Slack
Microsoft Teams
Google Chat
CloudAWS
GCP
Azure
AWS
GCP
Azure
Bare Metal/Edge
AWS
GCP
Azure
Bare Metal/Edge
Any
GovCloud✔️
IaaCTerraformTerraformTerraform
Kubernetes
Features2 Clusters
4 Apps
4 Clusters
8 Apps
Unlimited Clusters
Unlimited Apps
Updates and PatchesContinuousContinuousContinuous
CI/CDGitHub ActionsGitHub Actions
GitLab
BitBucket
GitHub Actions
GitLab
BitBucket
Jenkins
SecretsGitHub SecretsGitHub Secrets
AWS Secret Manager
Google Secret Manager
Azure Key Vault
Doppler
GitHub Secrets
AWS Secret Manager
Google Secret Manager
Azure Key Vault
Doppler
Identity
SSOGoogleGoogle
Okta
Entra
Google
Okta
Entra
Compliance
Compliance FrameworksCIS Benchmark
HIPAA
CIS Benchmark
HIPAA
CIS Benchmark
HIPAA
PCI-DSS
SOC 2
CMMC
Compliance PlatformVanta
Drata
Vanta
Drata
Secureframe
Any
Vanta Task Management
Drata Task Management
Compliance Remediation✔ (Single)✔ (Multiple)
Included IntegrationsNginx
Cert Manager
Prometheus
Grafana
Keda
Nginx
Cert Manager
Prometheus
Grafana
Keda
Nginx
Cert Manager
Prometheus
Grafana
Keda
DBA
Database1 per cluster2 per clusterUnlimited
Data Warehouse✖ None1 ClusterUnlimited
FinOps
Savings Plans (AWS)

Partners

  • Advantage Partners. Pentesting and SOC2 Auditing.
  • 1280 Labs. Developers as a Service
  • Helium Ventures. Sell your business