[ AWS & Cloud  /  AWS Server Setup ]

AWS, set up properly the first time.

A production environment that survives its first traffic spike, its first failed deploy and its first security review. Built as infrastructure-as-code so you can read it, change it, and never depend on me again.

Fixed scope · Typically 2-3 weeks · Terraform handed over

2-3 wkstypical delivery
100%infrastructure as code
Zeroconsole-only resources
Docsincluded, not extra

[ Why teams call ]

The setups I get called in to replace.

Almost every rescue starts as somebody's weekend project that quietly became production.

One big server, no plan

App, database and uploads all on a single instance, with no backup anyone has actually restored.

Wide-open security groups

Database ports exposed to 0.0.0.0/0 because that was the fastest way to make it work.

Click-ops infrastructure

Everything built by hand in the console. Nobody can rebuild it, and nobody dares change it.

No staging environment

Every deploy is a production experiment, and every rollback is a manual scramble.

No monitoring

You find out the site is down when a customer emails you about it.

Costs with no ceiling

No budgets, no tags, no alerts. The bill is a surprise every month.

[ How it works ]

Scoped, built, handed over.

01  —  Week 1

Architecture

We agree the shape: networking, compute model, database, environments and budget. You get a written architecture note and a fixed price before any building starts.

02  —  Week 2

Build

Everything written as Terraform in your repository: VPC, subnets, security groups, compute, database, TLS, backups, alarms and the deployment pipeline.

03  —  Week 3

Cutover & handover

We deploy the real workload, verify under load, then walk your team through the runbook: how to deploy, how to roll back, and what every alarm means.

[ What actually changes ]

What you actually get.

Every item below is delivered as code in your own repository, not as screenshots of my console.

Foundation

  • VPC and subnets — public, private and database tiers across multiple availability zones.
  • Least-privilege IAM — roles per workload, no long-lived access keys sitting in env files.
  • Compute — EC2 with auto scaling, ECS Fargate or EKS, chosen to fit the team, not the trend.
  • Managed database — RDS or Aurora with automated backups and a tested restore procedure.
  • TLS and DNS — certificates that renew themselves, sane record management, HTTP to HTTPS.

Day-two readiness

  • CI/CD pipeline — build, test and deploy on merge, with a one-command rollback.
  • Monitoring and alarms — CPU, memory, error rate, latency and disk, routed to email or chat.
  • Centralized logging — application and access logs with retention that fits your budget.
  • Backups and recovery — automated, and restored once in front of you so you know it works.
  • Runbook and diagram — written documentation your next engineer can actually follow.

[ Example engagement ]

From one hand-built box to a real environment.

A growing product running on a single instance with manual deploys, moved to a multi-AZ setup with automated pipelines and tested backups. No downtime during cutover.

Illustrative example of a typical engagement. Figures vary with the state of your systems and are not a guarantee of a specific outcome.

3 wksstart to cutover
0 mindowntime at switch
100%defined as code
2 envsstaging and production

[ Fixed scope · fixed price ]

Know the number before you commit.

Send me your stack and traffic expectations. You get an architecture recommendation and a fixed price, at no cost and with no obligation.

Get a scope

[ Pricing ]

Pricing that fits your budget.

Tell me the number you have to work with. I'll tell you honestly what's achievable within it — and if it isn't enough, I'll say so before we start rather than halfway through.

Fixed project price

Scope agreed in writing, price agreed in writing, before any work starts. No hourly creep and no invoice you haven't already approved.

Monthly retainer

For ongoing work — maintenance, monitoring, updates and small changes. Month to month, cancel whenever, no minimum term.

Hourly for small jobs

For a single bug or a short task where writing a full scope would cost more than simply doing the work.

Budget too tight for the whole thing? I'll often suggest doing the highest-value part first and the rest later, rather than doing all of it badly.

[ Questions ]

Common questions.

Do I need Kubernetes?

Usually not. Most teams under a dozen services are better served by ECS Fargate or plain auto-scaled instances — far less operational overhead for the same reliability. I will recommend Kubernetes only when your team is already able to run it.

Can you work with our existing AWS account?

Yes. I can build into your existing account alongside what is already running, or set up a clean account structure and migrate workloads across gradually.

What if we do not use Terraform?

Then you will after this, and that is deliberate. Infrastructure defined in code is the difference between an environment you own and an environment you are afraid of. I will train your team on the parts they need.

How much does it cost to run?

That depends on traffic and data, but you get a monthly estimate as part of the architecture note, before any building starts. Budgets and cost alarms are part of the build, not an upsell.

Do you offer ongoing support?

Yes, as an optional monthly retainer. Plenty of clients take the handover and run it themselves, which is the intended outcome.

[ Let's talk ]

Tell me what you're building.

Describe it in a few lines and you'll get a straight answer on scope, cost and timeline โ€” same working day, from the person who'd actually build it.