Skip to content
champbit

AWS & cloud infrastructure

AWS, set up so it stops being a mystery

Most AWS accounts grow by accident. Someone spins up an instance for a trial, a contractor adds a bucket, a service gets replaced but never turned off. Two years later nobody can say what half the bill is for. We go in, work out what is actually running, and leave you with infrastructure you can reason about.

What this covers

The whole account, not just the servers

Some clients bring us one migration and never speak to us again. Others hand over the account entirely. Both are fine.

Migration to AWS

Moving off shared hosting, a colocation rack, or another cloud. We lift what makes sense to lift and rebuild what doesn't, then plan the cutover so the switch happens once and at a time you chose.

Networking and access

VPCs, subnets, security groups and IAM roles scoped to what people actually need. This is usually where we find the root credentials that got shared around in 2019 and never rotated.

Compute and databases

EC2, ECS and Fargate, Lambda, RDS and Aurora. Right-sized rather than guessed at, with autoscaling where load genuinely varies and fixed capacity where it doesn't.

Backups and recovery

Automated snapshots, retention that meets whatever rule you are held to, and a restore actually performed in front of you. A backup nobody has restored from is a theory.

Monitoring and alerting

CloudWatch alarms that fire on things that matter and stay quiet otherwise. Alerts everyone has learned to ignore are worse than no alerts.

Infrastructure as code

Terraform, so the account can be reviewed, rebuilt and changed deliberately instead of remembered. It also means a second person can check a change before it reaches production.

Cost review

Orphaned volumes, oversized instances, storage sitting in the wrong tier, commitments you should have bought and ones you shouldn't. Usually the fastest thing to pay for itself.

Ongoing operations

Patching, certificate renewals, capacity checks and the occasional two-in-the-morning problem. Available as a monthly arrangement if you would rather not carry it.

Where we come in

The three calls we get most

"The bill went up again and nobody knows why."

Costs drifting month over month with no matching growth in customers or traffic. Nearly always a mix of forgotten resources, wrong instance families and data transfer nobody modelled.

"The person who set it up has left."

No documentation, no infrastructure as code, and a deploy process that lived in one person's terminal history. We reverse-engineer it into something written down.

"We have to be off the old host by March."

A migration with a hard date attached, usually a contract ending or a data centre closing. These are mostly a planning problem, and the planning is the part people skip.

How it works

We read the account before we change it

Nothing gets touched on day one. The first piece of work is always reading: what is running, what it costs, what depends on what, and what would happen if any of it stopped. You get that back as a written picture with the risks ranked, and it is yours whether or not you carry on with us.

Then we agree what changes, in what order, and what the rollback is for each step. Most of the value usually sits in the first two or three items, so we do those first rather than saving them for a grand re-architecture that may never get approved.

Work happens in your AWS account, under a role you create and can revoke. Everything we build is Terraform in your repository. If you replace us next year, the next person inherits a documented account rather than an archaeology project.

A word on re-architecting

Not every workload should be containerised, and serverless is not free. Plenty of businesses are well served by a couple of properly configured instances and a managed database. We will tell you when the boring option is the right one, even though it bills fewer hours.

Tools

What we work with

Standard AWS services and standard tooling. Nothing proprietary sitting between you and your own infrastructure.

Answers

Questions about AWS work

Do we have to move everything to AWS at once?

No, and you usually shouldn't. Most migrations run in phases with the old and new systems live together for a period. It costs slightly more for a few weeks and removes almost all of the risk.

Can you work in our existing AWS account?

Yes. We work through a role you create with the permissions the job needs, and you can revoke it at any point. We don't need or want your root credentials.

What happens if we want to leave later?

You keep everything. The account is yours, the Terraform is in your repository, and we use standard AWS services rather than a wrapper only we understand. Handover is a conversation, not a negotiation.

How much can a cost review realistically save?

It depends entirely on how the account grew, so we won't quote you a percentage. What we will do is show you the itemised findings before you commit to changing anything.

Do you handle compliance requirements?

We implement the technical controls — encryption, logging, access boundaries, retention, audit trails — and document what was done. We are not auditors and won’t certify you ourselves.

Can you just be on call for when things break?

Yes, as a managed arrangement. We'd want to review the account first, because agreeing to support infrastructure we've never seen isn't fair to either of us.

Related

Often needed alongside this

Get in touch

Send us the bill and we'll tell you what's on it.

A short email is enough to start. If a cost review is what you need, say so and we'll tell you what access we'd want to do one.

[email protected]