Infrastructure engineering · by GeekyAnts
Own the layer under
your product.
bolt.sh plans, builds and runs infrastructure — networks, CDNs, private clouds, GPU inference and the fleet of devices around it. From BGP and anycast to OpenStack and zero-touch MDM.
GeekyAnts ships for
- PayPoint
- IPv4 block we own and announce
- /24
- GeekyAnts founded
- 2006
- Clutch rating
- 4.9/5
- Delivery regions
- 3
ARIN-assigned, anycast across POPs
ISO-certified, 200–500 engineers
106 verified reviews
US · India · UK
What we do
Eight practices, one estate.
Engagements usually start in one of these and end up touching three. We sell them separately because that is how budgets work, not because they are separate problems.
Infrastructure Management
We take the estate you already have and make it legible, automated and boring.
- Full estate discovery — accounts, prefixes, hypervisors, circuits, secrets
- Infrastructure as code migration with Terraform and Ansible
- Capacity and cost modelling per workload, not per invoice
- Patch, backup and disaster-recovery programmes that are actually tested
Network Engineering & BGP
Routing, peering and address space — designed on paper, built as code, proven by withdrawal tests.
- Network topology design — single site, multi-region, hybrid and on-prem
- ASN and IPv4/IPv6 allocation, RIR paperwork, IRR and RPKI ROA setup
- eBGP and iBGP sessions on BIRD, FRR or vendor hardware
- Transit, peering and IX strategy — who to buy from and what to announce
CDN & Edge Delivery
Your own content network on your own address space — or a sane configuration of someone else's.
- Anycast CDN design on your own or our announced address space
- POP buildout on cloud, bare metal or colocation footprints
- Cache topology, tiering and origin shielding
- TLS termination, QUIC/HTTP3, and certificate automation at the edge
Security & Compliance
Reduce the number of ways in, then prove what happened on the ones that remain.
- Attack-surface review across network, cloud, endpoint and identity
- Segmentation and zero-trust access design, replacing flat VPNs
- Host, container and image hardening with CIS-aligned baselines
- Secrets management, key rotation and mTLS between services
On-Prem & Private Cloud
A private cloud that behaves like a public one — self-service, API-driven, and yours.
- Colocation and hardware specification — compute, storage, network, power
- OpenStack and Proxmox private cloud buildout with self-service tenancy
- Software-defined storage with Ceph, plus backup and offsite replication
- Hybrid connectivity between on-prem, colo and public cloud regions
On-Prem AI Inference
Run your models on hardware you control — for cost, for latency, or because the data cannot leave.
- GPU hardware specification sized against your real token volume
- Model serving with vLLM, TensorRT-LLM, Triton or Ray Serve
- Multi-tenant GPU scheduling with MIG, time-slicing and queue isolation
- Quantisation and batching strategy tuned for your latency target
Device & Asset Management
Every laptop and phone enrolled, encrypted, patched and accounted for — from unboxing to offboarding.
- Zero-touch enrolment for macOS, Windows, iOS and Android fleets
- Compliance baselines — disk encryption, screen lock, patch level, firewall
- Application delivery, licence tracking and self-service catalogues
- Asset lifecycle from procurement through refresh to secure disposal
Observability & SRE
Know it broke before the customer does — and know which layer, in one click.
- Metrics, logs and traces unified across cloud, on-prem and edge
- SLO definition and error-budget policy that engineering agrees to
- Alert rationalisation — fewer pages, each one actionable
- Network and BGP-aware monitoring, not just host and container metrics
Why us
We operate what we recommend.
Infrastructure advice from people who have never held the pager is expensive to follow.
We run our own network
Our own IPv4 block, our own ASN, our own eBGP sessions on BIRD across AWS and Vultr footprints. We made the mistakes on our own infrastructure before touching yours.
Full stack, not one layer
Routing, edge, hypervisor, storage, GPUs, endpoints and the observability over all of it. Most incidents live between layers, which is exactly where single-discipline vendors stop.
Backed by GeekyAnts
An ISO-certified consultancy operating since 2006 across the US, India and UK — with the delivery process, contracts and bench depth a serious engagement needs.
Builds
Systems we built and still run.
Written by the engineers who built them, including the parts that broke.
All case studiesGeekyAnts internal platform
Standing up on-prem LLM inference next to the private cloud
Serving open-weight models on owned GPUs with vLLM — sizing against KV cache, multi-tenant scheduling, and an OpenAI-compatible gateway in front.
- vLLM
- Continuous batching and prefix caching
- No egress
- Prompts and documents stay in-network
- OpenAI API
- Drop-in gateway for existing code
- Quota
- Per-team token accounting
bolt.sh platform
Building our own anycast CDN on a /24 we own
We acquired IPv4 space, got an ASN, announced the same prefix from POPs on AWS and Vultr with BIRD, and ran the edge ourselves. Here is what it took and what broke.
- /24
- IPv4 block we own and announce
- 2 clouds
- AWS and Vultr in one anycast fabric
- RPKI
- Signed ROAs on every announcement
- BIRD 2
- eBGP sessions we operate ourselves
Stack
The tools, named.
No proprietary black box. Everything we build, you can operate without us.
Network
- BIRD 2
- eBGP / iBGP
- Anycast
- RPKI / ROA
- IRR
- VXLAN
- WireGuard
- IPv6
Edge & CDN
- NGINX
- Varnish
- HAProxy
- Envoy
- QUIC / HTTP3
- Anycast DNS
- GeoDNS
Compute
- OpenStack
- Proxmox
- KVM
- Kubernetes
- k3s
- Talos
- Docker
Cloud
- AWS
- Vultr
- Azure
- Equinix Metal
- Hetzner
- Colocation
Inference
- vLLM
- TensorRT-LLM
- Ollama
- Triton
- NVIDIA MIG
- Ray Serve
Observability
- Prometheus
- Grafana
- Loki
- Tempo
- Thanos
- Alertmanager
- Netdata
Security
- Zero Trust
- Vault
- Wazuh
- CrowdSec
- Falco
- OpenVAS
- mTLS
Fleet
- Kandji
- SureMDM
- Intune
- Jamf
- Okta
- Google Workspace
Automation
- Terraform
- Ansible
- Pulumi
- Packer
- ArgoCD
- GitLab CI
Engagement
Four ways to start.
Most clients begin with an audit because it is fixed-scope and the output is useful regardless of what happens next.
2–3 weeks
Infrastructure Audit
Fixed-scope review of what you run today. Topology, failure domains, spend, exposure and an ordered remediation plan.
- Network & dependency map
- Risk register
- Cost teardown
- Prioritised roadmap
6–12 weeks
Build Sprint
A dedicated squad builds and ships the thing — POP rollout, private cloud, inference cluster, MDM programme.
- Running system
- Terraform / Ansible repo
- Runbooks
- Handover training
Monthly retainer
Managed Run
We hold the pager. Monitoring, patching, capacity planning, incident response and a monthly service review.
- 24×7 on-call
- SLA-backed response
- Monthly report
- Quarterly DR test
Rolling
Staff Augmentation
Embedded network, platform or SRE engineers inside your team, under your process and your ticket queue.
- Named engineers
- Your tooling
- Your standups
- No ramp tax
Pricing depends on scope and region. How we work →
Dedicated servers on our own network.
Bare metal and GPU nodes behind our anycast edge, with the infrastructure practice attached — not a control panel and a support queue. Join the waitlist to shape the specification.
See the plan- Bare metal and GPU nodes
- Our address space, your reputation
- Managed or unmanaged
- Transparent capacity, no overselling
Where on-prem inference actually beats the API bill
A framework for deciding whether to buy GPUs — utilisation, KV cache maths, the hidden operational cost, and the three cases where the answer is obviously yes.
The RPKI and IRR checklist nobody hands you with your first prefix
You received an allocation. Here are the records, filters and tests that decide whether the internet accepts your routes or quietly drops them.
Anycast without the hand-waving
What anycast actually gives you, what it costs operationally, and the four failure modes that surprise teams building their first multi-POP edge.
Next step
Tell us what breaks at 3am.
A 30-minute call with the engineers who would do the work — not a sales desk. We will tell you whether this is a bolt.sh problem or something you can fix in-house.