Services
Eight practices. One estate.
We sell these separately because that is how budgets work. In practice an engagement that starts in one of them touches three before it is finished — which is the point of buying them from the same team.
Infrastructure Management
We take the estate you already have and make it legible, automated and boring.
- Full estate discovery — accounts, prefixes, hypervisors, circuits, secrets
- Infrastructure as code migration with Terraform and Ansible
- Capacity and cost modelling per workload, not per invoice
- Patch, backup and disaster-recovery programmes that are actually tested
Network Engineering & BGP
Routing, peering and address space — designed on paper, built as code, proven by withdrawal tests.
- Network topology design — single site, multi-region, hybrid and on-prem
- ASN and IPv4/IPv6 allocation, RIR paperwork, IRR and RPKI ROA setup
- eBGP and iBGP sessions on BIRD, FRR or vendor hardware
- Transit, peering and IX strategy — who to buy from and what to announce
CDN & Edge Delivery
Your own content network on your own address space — or a sane configuration of someone else's.
- Anycast CDN design on your own or our announced address space
- POP buildout on cloud, bare metal or colocation footprints
- Cache topology, tiering and origin shielding
- TLS termination, QUIC/HTTP3, and certificate automation at the edge
Security & Compliance
Reduce the number of ways in, then prove what happened on the ones that remain.
- Attack-surface review across network, cloud, endpoint and identity
- Segmentation and zero-trust access design, replacing flat VPNs
- Host, container and image hardening with CIS-aligned baselines
- Secrets management, key rotation and mTLS between services
On-Prem & Private Cloud
A private cloud that behaves like a public one — self-service, API-driven, and yours.
- Colocation and hardware specification — compute, storage, network, power
- OpenStack and Proxmox private cloud buildout with self-service tenancy
- Software-defined storage with Ceph, plus backup and offsite replication
- Hybrid connectivity between on-prem, colo and public cloud regions
On-Prem AI Inference
Run your models on hardware you control — for cost, for latency, or because the data cannot leave.
- GPU hardware specification sized against your real token volume
- Model serving with vLLM, TensorRT-LLM, Triton or Ray Serve
- Multi-tenant GPU scheduling with MIG, time-slicing and queue isolation
- Quantisation and batching strategy tuned for your latency target
Device & Asset Management
Every laptop and phone enrolled, encrypted, patched and accounted for — from unboxing to offboarding.
- Zero-touch enrolment for macOS, Windows, iOS and Android fleets
- Compliance baselines — disk encryption, screen lock, patch level, firewall
- Application delivery, licence tracking and self-service catalogues
- Asset lifecycle from procurement through refresh to secure disposal
Observability & SRE
Know it broke before the customer does — and know which layer, in one click.
- Metrics, logs and traces unified across cloud, on-prem and edge
- SLO definition and error-budget policy that engineering agrees to
- Alert rationalisation — fewer pages, each one actionable
- Network and BGP-aware monitoring, not just host and container metrics
Method
The same five steps, every time.
Whether it is a POP rollout or an MDM programme, the sequence does not change. Skipping a step is how projects end up undocumented and unowned.
- 01
Map
We inventory what exists — ASNs, prefixes, circuits, hypervisors, images, endpoints, secrets. Most engagements start by discovering things nobody documented.
- 02
Model
Target topology and failure domains on paper first. Blast radius, capacity headroom, and the cost per unit of traffic or token.
- 03
Build
Everything as code — Terraform for provisioning, Ansible for config, Git for review. No hand-edited routers, no snowflake hosts.
- 04
Prove
Failover drills, route withdrawal tests, restore-from-backup, load tests against the real edge. If it has not failed under supervision, it is not done.
- 05
Run
Dashboards, SLOs, alert routing and runbooks — handed over to your team, or operated by ours on retainer.
Stack
Named tools, no black boxes.
Everything we build can be operated by your team without us. That is a design constraint, not a nice-to-have.
Network
- BIRD 2
- eBGP / iBGP
- Anycast
- RPKI / ROA
- IRR
- VXLAN
- WireGuard
- IPv6
Edge & CDN
- NGINX
- Varnish
- HAProxy
- Envoy
- QUIC / HTTP3
- Anycast DNS
- GeoDNS
Compute
- OpenStack
- Proxmox
- KVM
- Kubernetes
- k3s
- Talos
- Docker
Cloud
- AWS
- Vultr
- Azure
- Equinix Metal
- Hetzner
- Colocation
Inference
- vLLM
- TensorRT-LLM
- Ollama
- Triton
- NVIDIA MIG
- Ray Serve
Observability
- Prometheus
- Grafana
- Loki
- Tempo
- Thanos
- Alertmanager
- Netdata
Security
- Zero Trust
- Vault
- Wazuh
- CrowdSec
- Falco
- OpenVAS
- mTLS
Fleet
- Kandji
- SureMDM
- Intune
- Jamf
- Okta
- Google Workspace
Automation
- Terraform
- Ansible
- Pulumi
- Packer
- ArgoCD
- GitLab CI
Honest scoping
Things we will tell you not to buy.
We would rather lose a project than sell one that does not pay for itself.
- Build your own CDN when a commercial one with fixed cache keys would cost a fraction and take two weeks.
- Buy GPUs when your inference utilisation would sit below a third and no residency rule applies.
- Leave public cloud when your workloads are spiky and your egress is modest.
- Get your own ASN and address space when you run a single-region product on one provider.
Next step
Tell us what breaks at 3am.
A 30-minute call with the engineers who would do the work — not a sales desk. We will tell you whether this is a bolt.sh problem or something you can fix in-house.