Skip to content

Your Azure estate, rebuilt as code you own.

Management groups, landing-zone subscriptions, hub-and-spoke networking and CIS Azure guardrails, shipped as Terraform through pull requests. Migration runs in governed waves, and the repository, the state and the documentation are yours from day one.

5 modules
Terraform library, validated clean
10 runbooks
Written alongside the build
60%
Faster developer onboarding
24h
Exit Kit handover to any vendor

Module and runbook counts come from the ITSailor delivery kit shown below. The 60% figure is founder casework: a documentation-as-code rebuild at a scaling engineering team, detailed in the field notes.

The problem

Your infrastructure is a liability, not an asset.

Legacy servers, portal-click deployments, and zero governance. The cloud was supposed to fix this, but without a foundation it just moved the mess to someone else's data centre.

Legacy on-prem sprawl

Aging hypervisors, end-of-life firmware, single points of failure everywhere. The refresh cycle costs more than the cloud migration you have been postponing for two years.

No landing zone discipline

Azure subscriptions created ad-hoc by different teams. No naming convention, no RBAC baseline, no network segmentation. Every new workload makes the mess worse.

Manual deployments

Infrastructure changes happen via portal clicks. No audit trail, no rollback, no review process. One misconfigured NSG rule and the production database is internet-facing.

The mechanism

The blueprint, and the kit that ships it.

This is the topology the Terraform modules deploy, and the actual template set the engagement runs on: ADRs for the irreversible decisions, modules for the build, runbooks for the operating life. When a prospect asks "what do we actually get?", this is the answer, folder by folder.

Loading the interactive console

The documentation rule

Documentation that doesn't live in the repository next to the code isn't documentation. It's a wishlist that was already out of date the day it was published.
- Michal Jatczak, founder · ITSailor
Field notes

Where the docs-as-code rule was earned.

Before ITSailor, the founder inherited an engineering team scaling fast on infrastructure documented across five dead Confluence spaces and a pile of Google Docs. Nobody knew what the environments actually looked like, and onboarding a new developer took weeks.

Case: documentation as code

The build. The old wiki was killed. Markdown files moved into Git next to the code and the Terraform configs, rendered centrally for every team. Infrastructure changes could no longer pass code review without the matching doc update in the same pull request.

60%
Cut in new-developer onboarding time
1 source
Of truth across the infrastructure

The part that went wrong

Project managers hated writing Markdown through GitHub and kept breaking builds with unclosed tags. The fix was a simple WYSIWYG editor built just for them, because a documentation system people avoid is the old wiki with extra steps.

What that build changed

Every ITSailor landing zone now ships its documentation the same way: ADRs, runbooks and module READMEs living in the repository, versioned with the Terraform they describe. The Exit Kit is the end state of that discipline. If the docs are good enough for your next vendor, they are good enough for you.

When the platform is up

A landing zone you can rebuild is only half the story. Proving you can recover it, with immutable backups and drilled runbooks, is the Operational Resilience & DR narrative.

Operational Resilience & DR
Productized engagements

Three fixed-scope tiers. No T&M.

Assess first, build second, operate if you want to. Every tier is agreed before work starts, with no hourly billing anywhere.

Cloud Readiness Assessment

Where are you today? What does migration actually cost?

Scoped to youFixed fee · 2 weeks
  • Workload inventory and dependency mapping
  • Azure cost projection (reserved vs pay-as-you-go)
  • Network topology design (hub-spoke / VWAN)
  • Compliance gap analysis (DORA / NIS2 / ISO 27001)
  • Executive-ready migration plan + 60-minute walkthrough

Outcome

Go / no-go decision backed by real numbers, not vendor slides.

Scope the assessment
Most popular

Landing Zone & Migration

Ship the foundation. Move the workloads in governed waves.

Scoped to youFixed fee · 6-8 weeks
  • Azure landing zone (CAF-aligned) via the Terraform module library
  • Hub-and-spoke networking with ExpressRoute / VPN
  • RBAC baseline + PIM for privileged access
  • First 5 workloads migrated (VM, SQL, App Service)
  • ADR set, 10 runbooks, control-mapping matrix and Exit Kit in your repo

Outcome

A production-grade Azure foundation as code you own and can extend.

Scope the build

Managed Cloud Operations

We run the platform. You run the business.

Scoped to youMonthly retainer · 6 months min.
  • Alert triage and incident response
  • Monthly cost optimisation review
  • Terraform drift detection and remediation
  • Quarterly architecture review
  • Compliance evidence pack refreshed per audit cycle

Outcome

The platform stays governed and evidenced without hiring a platform team.

Talk about operations
Under the hood

Terraform

All infrastructure as code. Every change is a pull request, every deployment is auditable.

Azure Landing Zone (CAF)

Cloud Adoption Framework-aligned foundation: management groups, policies, networking.

GitHub Actions + OIDC

CI/CD for infrastructure. Plan, review, apply, with no long-lived credentials in the pipeline.

Azure Monitor + Grafana

Unified observability. Metrics, logs, alerts, all in one dashboard.

Steampipe + Powerpipe

Continuous compliance benchmarks: CIS, NIST 800-53, NIS2 controls.

SEAWALL FinOps Engine

Cost guardrails, anomaly detection, budget alerts. Integrated from day one.

Malta & EU compliance

DORA, NIS2 and ISO 27001, mapped per control.

The control-mapping matrix in the delivery kit is where these mappings live: one row per deployed control, one column per clause your auditor will ask about.

DORAArt. 9

ICT protection and prevention. Landing zone policies, RBAC and network segmentation map to the control objectives, row by row in the control-mapping matrix.

NIS2Art. 21

Cyber security risk management. Infrastructure governance, change control through pull requests, and monitoring documented in the handover pack.

ISO 27001A.5 / A.8

Asset management, access control, operations security. Mapped per resource and per policy assignment.

Provisioned stack

Licences that can sit under Cloud Infrastructure Modernization.

ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.

Microsoft

Microsoft Entra ID P2

€10.44 / user / month

Monthly commit

Microsoft

Microsoft Azure Plan

Usage-based, quoted

Pay-as-you-go consumption

Pay-as-you-go Azure consumption billed at Microsoft list price through Pax8 CSP, on one invoice. Scoped, governed and cost-reported alongside your landing zone; transferable to an Enterprise Agreement or direct billing via the Exit Kit.

Nord Security

NordLayer Business VPN (ZTNA)

Usage-based, quoted

Monthly commit

Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user network-access platform: apps plus browser extension, ZTNA/SASE, central gateway and logs. Business-correct alternative to consumer VPNs (Surfshark/NordVPN). Sold quoted/usage-based.

FAQ

Honest answers to the questions buyers actually ask.

What do we actually get at the end?

+

A delivery kit, not a deck: an architecture-decision record set, five Terraform modules in your GitHub organisation, ten written runbooks, a DORA / NIS2 / ISO 27001 control-mapping matrix and the Exit Kit with a Terraform state hand-off. The template set is real enough that this page shows it, folder by folder.

We have some workloads on-prem and some in Azure already. Can you work with that?

+

Yes. Hybrid is the default state for most clients we work with. The landing zone includes hub-spoke networking with site-to-site VPN or ExpressRoute, so on-prem workloads communicate with Azure securely, and there is a dedicated brownfield-onboarding runbook for the subscriptions you already have. We migrate in waves, no big bang required.

How does the landing zone differ from just creating an Azure subscription?

+

A landing zone is a governed foundation: management groups, policy assignments, RBAC baseline, networking topology, logging and cost controls, all deployed as code. A bare subscription is a blank canvas with no guardrails, and every team that touches it paints something different.

What about multi-cloud? We also use AWS / GCP.

+

We specialise in Azure and the Microsoft stack. For multi-cloud architectures we design the Azure leg and integrate with your existing AWS/GCP via Terraform workspaces and cross-cloud networking. We do not pretend to be experts in every cloud. We go deep on one.

We are regulated. How does this map to DORA?

+

Every landing zone control carries an explicit mapping to DORA Article 9, NIS2 Article 21 and ISO 27001 Annex A.5/A.8 in the control-mapping matrix. The migration closes with an evidence pack formatted for your next supervisory review or internal audit.

Who does the work?

+

One senior engineer, the same one you meet on the discovery call. No account managers, no offshore hand-off, no junior rotation. You get a single Slack channel and a direct line to the person writing the Terraform.

Get the estate into a repository, starting with the part that changes most.

The workshop picks the first workload worth codifying, agrees the review path for a change, and says which portal clicks are staying.