Your Azure estate, rebuilt as code you own.
Management groups, landing-zone subscriptions, hub-and-spoke networking and CIS Azure guardrails, shipped as Terraform through pull requests. Migration runs in governed waves, and the repository, the state and the documentation are yours from day one.
Module and runbook counts come from the ITSailor delivery kit shown below. The 60% figure is founder casework: a documentation-as-code rebuild at a scaling engineering team, detailed in the field notes.
Your infrastructure is a liability, not an asset.
Legacy servers, portal-click deployments, and zero governance. The cloud was supposed to fix this, but without a foundation it just moved the mess to someone else's data centre.
Legacy on-prem sprawl
Aging hypervisors, end-of-life firmware, single points of failure everywhere. The refresh cycle costs more than the cloud migration you have been postponing for two years.
No landing zone discipline
Azure subscriptions created ad-hoc by different teams. No naming convention, no RBAC baseline, no network segmentation. Every new workload makes the mess worse.
Manual deployments
Infrastructure changes happen via portal clicks. No audit trail, no rollback, no review process. One misconfigured NSG rule and the production database is internet-facing.
The blueprint, and the kit that ships it.
This is the topology the Terraform modules deploy, and the actual template set the engagement runs on: ADRs for the irreversible decisions, modules for the build, runbooks for the operating life. When a prospect asks "what do we actually get?", this is the answer, folder by folder.
The documentation rule
“Documentation that doesn't live in the repository next to the code isn't documentation. It's a wishlist that was already out of date the day it was published.”
Where the docs-as-code rule was earned.
Before ITSailor, the founder inherited an engineering team scaling fast on infrastructure documented across five dead Confluence spaces and a pile of Google Docs. Nobody knew what the environments actually looked like, and onboarding a new developer took weeks.
The build. The old wiki was killed. Markdown files moved into Git next to the code and the Terraform configs, rendered centrally for every team. Infrastructure changes could no longer pass code review without the matching doc update in the same pull request.
The part that went wrong
Project managers hated writing Markdown through GitHub and kept breaking builds with unclosed tags. The fix was a simple WYSIWYG editor built just for them, because a documentation system people avoid is the old wiki with extra steps.
What that build changed
Every ITSailor landing zone now ships its documentation the same way: ADRs, runbooks and module READMEs living in the repository, versioned with the Terraform they describe. The Exit Kit is the end state of that discipline. If the docs are good enough for your next vendor, they are good enough for you.
When the platform is up
A landing zone you can rebuild is only half the story. Proving you can recover it, with immutable backups and drilled runbooks, is the Operational Resilience & DR narrative.
Operational Resilience & DRThree fixed-scope tiers. No T&M.
Assess first, build second, operate if you want to. Every tier is agreed before work starts, with no hourly billing anywhere.
Cloud Readiness Assessment
Where are you today? What does migration actually cost?
- Workload inventory and dependency mapping
- Azure cost projection (reserved vs pay-as-you-go)
- Network topology design (hub-spoke / VWAN)
- Compliance gap analysis (DORA / NIS2 / ISO 27001)
- Executive-ready migration plan + 60-minute walkthrough
Outcome
Go / no-go decision backed by real numbers, not vendor slides.
Landing Zone & Migration
Ship the foundation. Move the workloads in governed waves.
- Azure landing zone (CAF-aligned) via the Terraform module library
- Hub-and-spoke networking with ExpressRoute / VPN
- RBAC baseline + PIM for privileged access
- First 5 workloads migrated (VM, SQL, App Service)
- ADR set, 10 runbooks, control-mapping matrix and Exit Kit in your repo
Outcome
A production-grade Azure foundation as code you own and can extend.
Managed Cloud Operations
We run the platform. You run the business.
- Alert triage and incident response
- Monthly cost optimisation review
- Terraform drift detection and remediation
- Quarterly architecture review
- Compliance evidence pack refreshed per audit cycle
Outcome
The platform stays governed and evidenced without hiring a platform team.
Terraform
All infrastructure as code. Every change is a pull request, every deployment is auditable.
Azure Landing Zone (CAF)
Cloud Adoption Framework-aligned foundation: management groups, policies, networking.
GitHub Actions + OIDC
CI/CD for infrastructure. Plan, review, apply, with no long-lived credentials in the pipeline.
Azure Monitor + Grafana
Unified observability. Metrics, logs, alerts, all in one dashboard.
Steampipe + Powerpipe
Continuous compliance benchmarks: CIS, NIST 800-53, NIS2 controls.
SEAWALL FinOps Engine
Cost guardrails, anomaly detection, budget alerts. Integrated from day one.
DORA, NIS2 and ISO 27001, mapped per control.
The control-mapping matrix in the delivery kit is where these mappings live: one row per deployed control, one column per clause your auditor will ask about.
ICT protection and prevention. Landing zone policies, RBAC and network segmentation map to the control objectives, row by row in the control-mapping matrix.
Cyber security risk management. Infrastructure governance, change control through pull requests, and monitoring documented in the handover pack.
Asset management, access control, operations security. Mapped per resource and per policy assignment.
Licences that can sit under Cloud Infrastructure Modernization.
ITSailor sells Microsoft and selected marketplace licences through Pax8 at vendor list price. Our margin is the Pax8 wholesale discount; service work is quoted or packaged separately.
Microsoft
Microsoft Entra ID P2
€10.44 / user / month
Monthly commit
Microsoft
Microsoft Azure Plan
Usage-based, quoted
Pay-as-you-go consumption
Pay-as-you-go Azure consumption billed at Microsoft list price through Pax8 CSP, on one invoice. Scoped, governed and cost-reported alongside your landing zone; transferable to an Enterprise Agreement or direct billing via the Exit Kit.
Nord Security
NordLayer Business VPN (ZTNA)
Usage-based, quoted
Monthly commit
Usage-billed on Pax8 (no fixed rate card via API - the /pricing endpoint 404s). Per-user network-access platform: apps plus browser extension, ZTNA/SASE, central gateway and logs. Business-correct alternative to consumer VPNs (Surfshark/NordVPN). Sold quoted/usage-based.
Built from three standing services.
Azure Cloud Infrastructure
The landing-zone engagement itself: subscription design, networking, identity, IaC, governance.
View serviceCloud & M365 Migrations
Workload and tenant moves in governed waves, with rollback points instead of big-bang weekends.
View serviceFinOps & Cost Management
The cost discipline for the platform you just built, backed by the SEAWALL engine.
View serviceHonest answers to the questions buyers actually ask.
What do we actually get at the end?
+
A delivery kit, not a deck: an architecture-decision record set, five Terraform modules in your GitHub organisation, ten written runbooks, a DORA / NIS2 / ISO 27001 control-mapping matrix and the Exit Kit with a Terraform state hand-off. The template set is real enough that this page shows it, folder by folder.
We have some workloads on-prem and some in Azure already. Can you work with that?
+
Yes. Hybrid is the default state for most clients we work with. The landing zone includes hub-spoke networking with site-to-site VPN or ExpressRoute, so on-prem workloads communicate with Azure securely, and there is a dedicated brownfield-onboarding runbook for the subscriptions you already have. We migrate in waves, no big bang required.
How does the landing zone differ from just creating an Azure subscription?
+
A landing zone is a governed foundation: management groups, policy assignments, RBAC baseline, networking topology, logging and cost controls, all deployed as code. A bare subscription is a blank canvas with no guardrails, and every team that touches it paints something different.
What about multi-cloud? We also use AWS / GCP.
+
We specialise in Azure and the Microsoft stack. For multi-cloud architectures we design the Azure leg and integrate with your existing AWS/GCP via Terraform workspaces and cross-cloud networking. We do not pretend to be experts in every cloud. We go deep on one.
We are regulated. How does this map to DORA?
+
Every landing zone control carries an explicit mapping to DORA Article 9, NIS2 Article 21 and ISO 27001 Annex A.5/A.8 in the control-mapping matrix. The migration closes with an evidence pack formatted for your next supervisory review or internal audit.
Who does the work?
+
One senior engineer, the same one you meet on the discovery call. No account managers, no offshore hand-off, no junior rotation. You get a single Slack channel and a direct line to the person writing the Terraform.
Get the estate into a repository, starting with the part that changes most.
The workshop picks the first workload worth codifying, agrees the review path for a change, and says which portal clicks are staying.