How we work
Fixed-scope start, documented finish.
Infrastructure engagements fail in predictable ways — unclear scope, no handover, and a vendor who becomes load-bearing. We design against all three.
Engagement models
Four ways to start.
Most clients begin with an audit. It is fixed-scope, it takes two to three weeks, and the output is useful whether or not you continue with us.
Infrastructure Audit
2–3 weeksFixed-scope review of what you run today. Topology, failure domains, spend, exposure and an ordered remediation plan.
- Network & dependency map
- Risk register
- Cost teardown
- Prioritised roadmap
Build Sprint
6–12 weeksA dedicated squad builds and ships the thing — POP rollout, private cloud, inference cluster, MDM programme.
- Running system
- Terraform / Ansible repo
- Runbooks
- Handover training
Managed Run
Monthly retainerWe hold the pager. Monitoring, patching, capacity planning, incident response and a monthly service review.
- 24×7 on-call
- SLA-backed response
- Monthly report
- Quarterly DR test
Staff Augmentation
RollingEmbedded network, platform or SRE engineers inside your team, under your process and your ticket queue.
- Named engineers
- Your tooling
- Your standups
- No ramp tax
Process
Map, model, build, prove, run.
The sequence does not change with the subject matter. A POP rollout and an MDM programme go through the same five steps, because skipping one is how projects end up undocumented and unowned.
- 01
Map
We inventory what exists — ASNs, prefixes, circuits, hypervisors, images, endpoints, secrets. Most engagements start by discovering things nobody documented.
- 02
Model
Target topology and failure domains on paper first. Blast radius, capacity headroom, and the cost per unit of traffic or token.
- 03
Build
Everything as code — Terraform for provisioning, Ansible for config, Git for review. No hand-edited routers, no snowflake hosts.
- 04
Prove
Failover drills, route withdrawal tests, restore-from-backup, load tests against the real edge. If it has not failed under supervision, it is not done.
- 05
Run
Dashboards, SLOs, alert routing and runbooks — handed over to your team, or operated by ours on retainer.
Principles
Four rules we do not negotiate.
These exist because we have been on the other side of engagements that ignored them.
Everything as code
No hand-edited routers, no snowflake hosts, no configuration that exists only in someone’s shell history. If it is not in a repository with a review history, it does not count as done.
You keep the keys
We work in your accounts, your repositories and your identity provider. Access is scoped and time-bound, and it is revoked on the last day of the engagement without us having to be asked.
Tested, not asserted
Failover drills, route withdrawal tests, restore-from-backup, load tests against the real edge. A capability that has never been exercised under supervision is a hypothesis.
Handover is a deliverable
Runbooks, architecture notes and training sessions are scoped into the work, not offered afterwards. The exit test is whether your team can operate it without us.
Commercials
The questions procurement asks.
How do you price?
Audits are fixed price. Build sprints are time and materials against an agreed scope with a not-to-exceed ceiling, or fixed price where the scope is genuinely fixed. Managed run is a monthly retainer sized by estate and response target. Staff augmentation is a monthly rate per engineer.
What timezone do you work in?
We staff from India, the UK and the US, so engagements run with meaningful overlap to European and North American hours. On-call rotations follow the sun rather than asking one region to cover everything.
Can you work under our change management and security review?
Yes. Your ticket queue, your change windows, your approval chain. We go through vendor security review regularly — GeekyAnts is ISO-certified and we can provide the usual documentation set.
What happens to the work if we stop the engagement?
You keep it. Repositories, runbooks and documentation live in your organisation from day one, not ours. There is no proprietary layer you need us for, which is a deliberate design constraint.
Do you subcontract?
No. Engineers on your engagement are GeekyAnts staff, named in the statement of work. If we need a specialist we do not have, we say so and help you find one.
What does a first call look like?
Thirty minutes with an engineer who would be on the work. We ask what you run, what is going wrong and what is driving the timeline. You get an honest read on whether this is worth paying for — including when the answer is no.
Next step
Tell us what breaks at 3am.
A 30-minute call with the engineers who would do the work — not a sales desk. We will tell you whether this is a bolt.sh problem or something you can fix in-house.