Eight services in three areas, one goal: software and infrastructure your team can evolve on its own.
EN
Engineering
Software and systems that are easier to change: code, migrations, connected systems.
Refactoring and code quality
I make existing software easier to understand and change. Tests first around current behaviour, then small steps: clear module boundaries, fewer dependencies, less technical debt. The system stays in production the whole time.
- Technical debt map and priorities
- Characterisation tests before touching code
- Extracting modules and services where it makes sense
- Pairing with the team on reviews
Details, examples and deliverables
For each application I pick the right strategy among the "7 Rs" of migration (rehost, replatform, refactor, repurchase, relocate, retain, retire). Replatforming moves the application with limited optimisations: containerisation, managed databases, an updated operating system. Refactoring rethinks the architecture and costs more: I only propose it when it is needed.
- Inventory and strategy choice per application
- Migration without stopping the service
- Containerisation and managed services
- A rollback plan
Details, examples and deliverables
Assessment and second opinion
An independent review of architecture, cloud costs, security and reliability. It ends with a short document: what is fine, what is at risk, what to do first. It is the simplest way to start working together.
- Architecture and infrastructure review
- Cloud cost analysis (FinOps)
- Priority list and action plan
- Also useful before an audit or a tender
Details, examples and deliverables
Home automation and IoT
I design and build home automation and IoT systems: sensors, actuators, protocols (MQTT, Zigbee, Modbus), local automations, data collection and dashboards, cloud integration. Where it makes sense I bring the same cloud native discipline to the edge: safe updates, observability, lightweight containers and compact clusters. Security, privacy and working without internet come first.
- Home automation for homes, offices and hospitality venues
- Gateways, MQTT, Home Assistant and Node-RED
- Edge computing with containers and lightweight Kubernetes
- Safe updates and network-isolated devices
Details, examples and deliverables
TRA
Orchestration
Platforms and automation that take everything to production repeatably.
Kubernetes and cloud native platforms
I design and build Kubernetes clusters and cloud native platforms: architecture, networking, storage, observability, security, upgrades. It fits teams starting from scratch and teams with a cluster nobody dares to touch.
- Architecture and sizing (managed or self-managed)
- Security: access, secrets, network policies, images
- Cloud native stack: Helm, Prometheus and Grafana, service mesh, ingress, registries, policy
- Observability and alerts that matter
- Upgrades and disaster recovery that have been tested
Details, examples and deliverables
Red Hat OpenShift Container Platform
I move applications to Red Hat OpenShift Container Platform and make them run well: cluster architecture, installation and upgrades, security (SCC, RBAC, network policies), operators, pipelines and GitOps, observability. Also useful for teams coming from plain Kubernetes who must adapt to OpenShift, or from virtual machines who want to containerise.
- Cluster architecture, installation and upgrades
- Security and compliance: SCC, RBAC, images, secrets
- Operators, OpenShift Pipelines and GitOps
- Migrating applications from VMs or from Kubernetes
Details, examples and deliverables
Orchestration and automation
I turn manual steps into repeatable processes: release pipelines (Jenkins and others), configuration with Ansible, infrastructure as code, GitOps, identical environments from development to production. The goal is to make releasing boring.
- CI/CD pipelines and release strategies
- Jenkins, GitHub Actions and GitLab CI; Terraform/OpenTofu; GitOps (Argo CD, Flux)
- Ansible playbooks and roles for servers, network and applications
- Ephemeral environments and internal developer platforms
- Cloud costs under control
Details, examples and deliverables
Who is the consulting for?
SMEs, startups and engineering teams with software or infrastructure to modernise, or that want to put AI agents in production without first building a dedicated department.
Do you only work in Pavia?
No. I am based in Pavia and work on site in Lombardy by appointment; the rest of the work is remote, across Italy and Europe.
What is the difference between replatforming and refactoring?
Replatforming moves an application to the cloud with limited optimisations (for example containers or a managed database) without changing its architecture. Refactoring redesigns it to take advantage of the cloud: more benefit, higher cost, done only when needed.
Is an AI agent safe for company data?
It depends on how it is built. I work with least-privilege permissions, data separation, logs of what the agent does and human approval for sensitive actions. There is always a measurable evaluation before production.
How much does it cost?
It depends on the scope. After the first call you receive a written proposal with timing and cost. A short assessment is the simplest way to start.
Does the work stay with me?
Yes: code, configuration and documentation live in your repositories and your accounts. The goal is that your team can maintain them alone.