Cloud strategy · Platform engineering · DevOps · FinOps
Ship fast. Pass every audit.
I design and build cloud platforms for regulated environments: Kubernetes, CI/CD, GitOps, compliance-as-code. From the board paper to the running cluster, strategy and implementation from one hand.
The newest layer is the one for AI work: model gateway, sandboxes, guardrails. See the Agentic Workflows service for how entire processes run on top of it.
12+
5+
14+
BaFin
The Problem
✕ Every team builds its own pipeline
Ten teams, ten deploy paths, none documented. Every outage needs the one person who built it. Every audit turns into archaeology.
✕ Compliance slows you down because it's manual
Evidence assembled by hand, approvals over email, configuration drifting. Yet regulation is automatable, if the platform is built for it.
What you get
Built in banks, utilities and industry
Hybrid cloud securities platform in transaction banking: CI/CD platform, AppOps build-up, DORA automation, AI guardrails. Plus utilities, energy software and international industry.
The stack that comes with it: Kubernetes (EKS/AKS), GitLab CI, ArgoCD, Terraform, Helm, OPA/Kyverno, Prometheus, Kafka — run in production, not just evaluated.
Strategy through operations
Assessment, target picture, business case, migration, operations. I don't hand over after the slide deck — I stay until it runs.
Compliance as code
Policies instead of PDF mandates (OPA/Kyverno), audit-ready landing zones. At a bank I automated DORA inventory maintenance: the CMDB fills itself from GitLab, ArgoCD and Kubernetes.
Golden paths instead of ticket ops
Internal developer platforms with standard paths. Teams ship on their own, safely, without touching cluster configuration.
The foundation for AI work
Model gateway, sandboxes, egress control, audit logging. I'm building it right now inside a BaFin-regulated bank.
Where I help
Good for developers, good for governance
That's my difference: I mediate between engineering and compliance, convince both sides of solutions that hold — and build them myself. End to end, automation first.
From business case to running platform
Landscape assessment with 6R, target architecture, roadmap — and then the migration itself. Multi-region, hybrid, AWS and Azure.
A platform teams actually like using
Golden paths via Helm and Terraform. Self-service instead of a ticket queue.
Audit trail built in
GitLab CI, ArgoCD, automated quality and policy gates — evidence is produced while shipping.
Evidence that maintains itself
DORA, ISO 27001, BaFin: inventories, vulnerabilities and deployment artifacts flow into the CMDB automatically.
Cloud spend down, in KPIs
Compute patterns, storage lifecycle, network flows. Cost reduction through rightsizing and architecture — tracked as KPIs in the monthly report.
From AI pilot to production
Central model access, sandboxes, guardrails, usage reporting. Explored in depth in the Agentic Workflows service.
Engagement models
Assessment & Target Picture
Understand first, build second.
- ✓Landscape assessment with 6R classification
- ✓Target architecture and migration path
- ✓Business case and roadmap
- ✓Decision paper for leadership
For: cloud strategy and platform health checks
Build & Migration
The platform gets built, migrated and handed over — with your teams.
- ✓Landing zone and Kubernetes platform
- ✓CI/CD and GitOps delivery paths
- ✓Policy-as-code and audit trail
- ✓Golden paths, handover and enablement
For: a new platform or modernizing what exists
Embedded Architect
Architecture and hands-on work inside the team, typically 2–3 days a week.
- ✓Architecture decisions in day-to-day delivery
- ✓AppOps/SRE build-up and mentoring
- ✓Compliance and cost topics solved along the way
- ✓Knowledge stays in the team
For: teams that need senior reinforcement for a while
All models remote-first with on-site days as needed — easy to reach across DACH from Cologne.
From the field
- Published on
The One Part No AI Lab Will Build for You

- Published on
The Future of Coding - How AI Will Change Everything

- Published on
You Build It, You Run It – Or is there a Smarter Approach?
Next step
Tell me about your platform
30 minutes, your biggest problem: a migration, an audit, cloud costs, or the AI topic your IT security is currently blocking. I'll tell you how I would approach it.
