Skip to content

Changing your infrastructure should be boring. Not an event.

For most teams it's still an event: fifteen clicks for one virtual machine, six logins for one network change, and one person who knows how it really works. We move infrastructure into code — the desired state lives in Git, every change passes a dry run and an approval, and the environment can be rebuilt.

Two questions run through everything here.

Reproduce
Can you build it again?

How much of your estate comes from code and a template rather than from clicking — virtual machines, network devices, services, anything you provision. The working target is 95 % from a template and 5 % deliberate exceptions. And how long it would take to stand an environment up again.

Review
Can you prove the change?

What share of changes went through Git, a dry run and an approval — rather than being made by hand — plus the lead time from request to deployment and honest automation coverage per class of device. What comes out is an auditable trail: who changed what, when and why, and it can be rolled back.

Every engagement starts by measuring both gaps and ends by closing them — an environment you can build from code, and an approval flow your team actually uses.

Automation done right is three moves: describe it, review it, rebuild it.

Describe it

A single source of truth over your infrastructure — Netbox, integrated with vCenter and iLO, with a dynamic inventory — and the desired state of the environment held in Git. What you have, written down in a form machines can act on.

Review it

A dry run that shows exactly what would change and refuses to deploy on error, a pull request with a named approver, a versioned change and a rollback through code. Nothing reaches production without a trace.

Rebuild it

Packer templates, Terraform or OpenTofu provisioning and deprovisioning, Ansible configuration for servers and network devices. A repeatable environment — not a script that worked once, on someone's laptop.

What we deliver

Four ways to engage

The same lifecycle as everywhere at G2F — assessment, build, operations, enablement — focused on one question: how much of your infrastructure could you rebuild without the person who built it?

01

Assess

Automation & IaC Assessment

How much of your infrastructure could you rebuild without the person who built it? That's the first thing we measure.

  • An as-is map of manual work — who changes what, and where — and an inventory of your source of truth: does one exist, or does the state of the estate live in people's heads and in text config files?
  • Automation coverage per class of device and per environment — honest percentages, not yes or no — plus the drift gap: how many changes happen outside Git, and whether anyone notices.
  • A toolset assessment (Terraform, OpenTofu, Ansible, Packer and your existing Git and CI base) — what to keep, what to consolidate, and what your licence exposure is — and a target GitOps model: desired state, dry run, and who approves what.
  • A roadmap in three phases (quick wins, systematic approach, long-term projects) and a named key-person risk: what specifically stops when the person who builds the environment is away. Optionally, an independent read of an infrastructure audit you already paid someone else for.

02

Build

From manual infrastructure into code

A script that ran once isn't automation. What we hand over is an environment you can build again.

  • An automation platform — Git holding the desired state of the environment, plus a pipeline in your own environment (GitLab CI, Gitea Actions, GitHub Actions): a dry run that blocks on error, a real deployment after an approved merge. Self-hosted where the code must not leave your perimeter.
  • Provisioning across the estate — Packer templates, Terraform or OpenTofu provisioning and deprovisioning, Ansible for Nexus, ASA, F5 and vSphere; Terraform for AWS and Azure, and a MaaS pipeline for bare metal. A network change is entered in Git instead of logged into six devices.
  • Netbox as the single source of truth about the infrastructure itself — what exists, where, and how it's connected — integrated with vCenter and iLO, with an Ansible dynamic inventory wired to Git. An inventory that gets used when a machine is built, not a dead CMDB.
  • Secrets out of the code — IaC without secrets management means credentials in a repository, and it is the most common real finding. A central store, Vault or the tool you already run, wired into the pipeline.
  • Handover is the environment, the templates, a documented approval flow and a team that can work in the code.

03

Operate

Automation Maintenance & On-Demand

Automation isn't a project that finishes. It dies when nobody maintains it and the team quietly goes back to clicking.

  • Drift tracked and returned to the code — what has diverged from Git, and why — plus maintenance of playbooks and templates as the estate moves under them: new vSphere, switch, operating system and image versions.
  • Coverage extended class of device by class of device, starting where the volume of change is highest, and day-one and day-two configuration (hostname, NTP, user management, RADIUS).
  • Troubleshooting for the pipeline and provisioning, and on-demand consulting blocks. Typically part of a wider support arrangement rather than a standalone line item.

04

Train

Enablement inside the build

The goal is that your team owns the code after we leave — not that they sit through a course.

  • Your admins work on the code alongside us and take it over during delivery.
  • Deep dives on Git and Ansible and a lab environment on request, run inside the engagement.
  • We don't sell this as a standalone automation course. Enablement lives inside the build, where the code is real.

Vendor-neutral by design

We don't sell an automation platform and we don't resell anyone else's. The open-source-first layer we build on is Ansible, Netbox, OpenTofu and Git. Terraform and Packer are the de facto market standard, but since August 2023 they are no longer open source — HashiCorp relicensed them from MPL 2.0 to BUSL 1.1, and HashiCorp is now part of IBM. Where a commercially backed, supported stack is what your organisation requires, we work in the tools you already run. Where the licence is a constraint, we use OpenTofu, the open-source fork under the Linux Foundation and a drop-in replacement.

Delivered in production

Where we've done this

Infrastructure we've assessed, automated and handed over as code — for a critical transport infrastructure operator, a regulated fintech and an enterprise integrator.

See where we've delivered

How much of your infrastructure could you build again tomorrow?

An Automation & IaC Assessment maps what still changes by hand, measures your coverage per class of device, names the key-person risk, and gives you a roadmap in three phases. Vendor-neutral, fixed scope. Most first conversations take 30 minutes. No pitch, no deck.