Skip to content

Services

Eight practices. One estate.

We sell these separately because that is how budgets work. In practice an engagement that starts in one of them touches three before it is finished — which is the point of buying them from the same team.

Infrastructure Management

We take the estate you already have and make it legible, automated and boring.

  • Full estate discovery — accounts, prefixes, hypervisors, circuits, secrets
  • Infrastructure as code migration with Terraform and Ansible
  • Capacity and cost modelling per workload, not per invoice
  • Patch, backup and disaster-recovery programmes that are actually tested

Network Engineering & BGP

Routing, peering and address space — designed on paper, built as code, proven by withdrawal tests.

  • Network topology design — single site, multi-region, hybrid and on-prem
  • ASN and IPv4/IPv6 allocation, RIR paperwork, IRR and RPKI ROA setup
  • eBGP and iBGP sessions on BIRD, FRR or vendor hardware
  • Transit, peering and IX strategy — who to buy from and what to announce

CDN & Edge Delivery

Your own content network on your own address space — or a sane configuration of someone else's.

  • Anycast CDN design on your own or our announced address space
  • POP buildout on cloud, bare metal or colocation footprints
  • Cache topology, tiering and origin shielding
  • TLS termination, QUIC/HTTP3, and certificate automation at the edge

Security & Compliance

Reduce the number of ways in, then prove what happened on the ones that remain.

  • Attack-surface review across network, cloud, endpoint and identity
  • Segmentation and zero-trust access design, replacing flat VPNs
  • Host, container and image hardening with CIS-aligned baselines
  • Secrets management, key rotation and mTLS between services

On-Prem & Private Cloud

A private cloud that behaves like a public one — self-service, API-driven, and yours.

  • Colocation and hardware specification — compute, storage, network, power
  • OpenStack and Proxmox private cloud buildout with self-service tenancy
  • Software-defined storage with Ceph, plus backup and offsite replication
  • Hybrid connectivity between on-prem, colo and public cloud regions

On-Prem AI Inference

Run your models on hardware you control — for cost, for latency, or because the data cannot leave.

  • GPU hardware specification sized against your real token volume
  • Model serving with vLLM, TensorRT-LLM, Triton or Ray Serve
  • Multi-tenant GPU scheduling with MIG, time-slicing and queue isolation
  • Quantisation and batching strategy tuned for your latency target

Device & Asset Management

Every laptop and phone enrolled, encrypted, patched and accounted for — from unboxing to offboarding.

  • Zero-touch enrolment for macOS, Windows, iOS and Android fleets
  • Compliance baselines — disk encryption, screen lock, patch level, firewall
  • Application delivery, licence tracking and self-service catalogues
  • Asset lifecycle from procurement through refresh to secure disposal

Observability & SRE

Know it broke before the customer does — and know which layer, in one click.

  • Metrics, logs and traces unified across cloud, on-prem and edge
  • SLO definition and error-budget policy that engineering agrees to
  • Alert rationalisation — fewer pages, each one actionable
  • Network and BGP-aware monitoring, not just host and container metrics

Method

The same five steps, every time.

Whether it is a POP rollout or an MDM programme, the sequence does not change. Skipping a step is how projects end up undocumented and unowned.

  1. 01

    Map

    We inventory what exists — ASNs, prefixes, circuits, hypervisors, images, endpoints, secrets. Most engagements start by discovering things nobody documented.

  2. 02

    Model

    Target topology and failure domains on paper first. Blast radius, capacity headroom, and the cost per unit of traffic or token.

  3. 03

    Build

    Everything as code — Terraform for provisioning, Ansible for config, Git for review. No hand-edited routers, no snowflake hosts.

  4. 04

    Prove

    Failover drills, route withdrawal tests, restore-from-backup, load tests against the real edge. If it has not failed under supervision, it is not done.

  5. 05

    Run

    Dashboards, SLOs, alert routing and runbooks — handed over to your team, or operated by ours on retainer.

Stack

Named tools, no black boxes.

Everything we build can be operated by your team without us. That is a design constraint, not a nice-to-have.

Network

  • BIRD 2
  • eBGP / iBGP
  • Anycast
  • RPKI / ROA
  • IRR
  • VXLAN
  • WireGuard
  • IPv6

Edge & CDN

  • NGINX
  • Varnish
  • HAProxy
  • Envoy
  • QUIC / HTTP3
  • Anycast DNS
  • GeoDNS

Compute

  • OpenStack
  • Proxmox
  • KVM
  • Kubernetes
  • k3s
  • Talos
  • Docker

Cloud

  • AWS
  • Vultr
  • Azure
  • Equinix Metal
  • Hetzner
  • Colocation

Inference

  • vLLM
  • TensorRT-LLM
  • Ollama
  • Triton
  • NVIDIA MIG
  • Ray Serve

Observability

  • Prometheus
  • Grafana
  • Loki
  • Tempo
  • Thanos
  • Alertmanager
  • Netdata

Security

  • Zero Trust
  • Vault
  • Wazuh
  • CrowdSec
  • Falco
  • OpenVAS
  • mTLS

Fleet

  • Kandji
  • SureMDM
  • Intune
  • Jamf
  • Okta
  • Google Workspace

Automation

  • Terraform
  • Ansible
  • Pulumi
  • Packer
  • ArgoCD
  • GitLab CI

Honest scoping

Things we will tell you not to buy.

We would rather lose a project than sell one that does not pay for itself.

  • Build your own CDN when a commercial one with fixed cache keys would cost a fraction and take two weeks.
  • Buy GPUs when your inference utilisation would sit below a third and no residency rule applies.
  • Leave public cloud when your workloads are spiky and your egress is modest.
  • Get your own ASN and address space when you run a single-region product on one provider.

Next step

Tell us what breaks at 3am.

A 30-minute call with the engineers who would do the work — not a sales desk. We will tell you whether this is a bolt.sh problem or something you can fix in-house.