Skip to main content
Independent DevOps & Platform Engineering Consultant

Cloud bills, cut. Kubernetes, shipped.

I help SaaS teams cut 30%+ of their AWS or Azure bill, ship production-grade GitOps platforms in weeks, and embed as fractional DevOps when a full-time platform hire isn't justified yet.

Book a free 30-min call How I workNo pitch deck. No sales call. Just diagnostic.
Cost
~40%
Cloud spend cut for an enterprise SaaS client, capacity unchanged — still ~33% below baseline as workload grew.
Scale
1,000+
Apps managed via the GitOps platform I architected, across 10 production K8s clusters.
Reliability
99.9%
Availability against contracted SLAs, on infrastructure serving 2M+ daily requests.
Teaching
800+
Engineers trained across 12 cohorts as Lead DevOps Instructor at Ostad.
Services

Five ways teams actually hire me.

Starting points below — the exact number comes out of a call once we've scoped the problem. Two to six weeks for fixed projects; weekly billing for retainers.

K8s01 · Platform

Kubernetes & GitOps platform setup

Production-ready Kubernetes + GitOps from scratch — multi-cluster, secure, observable, deployable in weeks not quarters.

  • Cluster architecture & tenancy model
  • ArgoCD, app-of-apps, secrets management
  • CI/CD pipelines & deploy automation
  • SLI/SLO + error budget definition
  • Fault injection before release — pod kill, node loss, net partition
  • Runbooks, ADRs, team handoff
from $6,500 · 2–6 weeks, scales with scope
Ideal for: Series A–C SaaS scaling past 5 engineers, or teams stuck on legacy infra they're afraid to touch.
40% cloud spend cut →
$02 · Audit

Cloud cost optimization audit

I'll find 30%+ of your AWS or Azure bill that you don't need to be spending — plus a governance playbook so it doesn't drift back.

  • Full account audit — waste, tagging, RIs
  • Rightsizing & spot strategy
  • Reserved / savings plan modeling
  • FinOps governance playbook
  • Implementation support
from $2,500 · fixed scope
Ideal for: Companies spending $20K+/month on cloud with no dedicated FinOps owner.
CI03 · Pipelines

CI/CD pipeline engineering

One-click repo-to-production pipelines with security scanning baked in. .NET, Java, Python, JS, Go — all covered.

  • GitHub Actions or GitLab CI design
  • Reusable workflows & templates
  • SonarQube + OWASP Dependency-Track
  • Workload identity & OIDC federation — kill client-ID/secret auth
  • Promote-via-PR release flow
  • Developer-facing docs
from $4,000 · 2–4 weeks, scales with scope
Ideal for: Engineering teams shipping slowly or fighting with brittle legacy Jenkins.
04 · Embed

Fractional DevOps & advisory

Embedded senior DevOps expertise without a full-time hire. Architecture reviews, mentoring, hiring help, on-call backup.

  • 10–20 hrs / week, ongoing
  • Architecture & cost reviews
  • PR review & mentoring
  • On-demand crisis response
  • Help hiring your first platform engineer
from $3,500 / month · 10–20 hrs / week
Ideal for: Early-stage startups (pre-DevOps hire) or scaleups bridging to their first dedicated platform engineer.
AI05 · AI infra

AI/ML platform & GPU workload infrastructure

The infrastructure layer under your models — GPU scheduling, training and inference pipelines, and the compliance controls that come with regulated data.

  • GPU/ML workload orchestration on Kubernetes
  • Training & inference pipeline automation
  • Mixed spot/on-demand capacity for cost control
  • HIPAA / regulated-data ML platforms
  • Model deployment lead time: weeks → hours
from $6,500 · scoped like a platform build
Ideal for: ML teams whose data scientists are blocked on infrastructure, or AI products moving from notebook to production.
Book a 30-min intro call Not sure which? We'll figure it out on the call.
Case studies

Four engagements. Four specific outcomes.

Problem → approach → result. Real engagements; happy to walk through any of them on a call.

Enterprise SaaS · SwitzerlandEnterprise SaaSCloud cost

Cut a SaaS company's cloud bill ~40% — no capacity lost.

Problem
The Azure bill had climbed steadily with no FinOps owner. Engineering was being asked to cut spend without slowing delivery.
Approach
Full account audit. Surfaced untagged waste, oversized VMs, idle services, missing reserved coverage. Modeled the right RI + spot mix. Wrote a governance playbook so savings wouldn't drift back.
Outcome
A ~40% reduction at the time, and still ~33% below baseline today as platform workload keeps growing. No capacity cut, no velocity hit. The playbook is still the FinOps reference.
Read the full case study
Multi-tenant PaaSMulti-tenantGitOps platform

Built a GitOps platform managing 1,000+ apps from a blank repo.

Problem
Tenant onboarding was manual and slow. Deployments drifted between clusters. Platform team on-call for routine changes that should have been self-service.
Approach
Designed a multi-cluster ArgoCD control plane on the app-of-appsets pattern — one root Application fanning out into per-service, per-cluster Applications. Codified tenant provisioning, split control plane from Helm values across two repos, wrote the handoff docs the platform team operates from.
Outcome
1,000+ apps via GitOps across 10 production clusters. New tenants live in under an hour, fully self-served. Platform team reclaimed on-call hours.
Read the full case study
Health-techML on patient dataHIPAA compliance

HIPAA-compliant ML infrastructure — zero incidents to date.

Problem
ML team needed to deploy patient-data workloads under strict HIPAA controls — without slowing data scientists down or turning platform into a ticket queue.
Approach
Isolated network architecture, encryption-at-rest by default, automated audit logging, developer experience that hid the compliance machinery behind a clean abstraction.
Outcome
Production HIPAA-aligned infra delivered on schedule. Zero security incidents since launch. ML team self-services deployments without platform intervention.
Read the full case study
Enterprise SaaS · PlatformSelf-managed K8sCloud-agnostic

Built a self-managed RKE2 platform as a cloud-agnostic alternative to AKS.

Problem
The platform was locked to one managed Kubernetes provider. Enterprise clients with data-residency and sovereignty requirements needed the same product running outside a hyperscaler — without a second operating model.
Approach
Security-hardened RKE2 provisioned end-to-end with Ansible. Defense in depth: admin plane behind a VPN and cloud security group, host firewall scoped to peer nodes, WireGuard-encrypted node-to-node traffic because the overlay crosses a public segment. A self-hosted OIDC issuer lets out-of-cloud workloads federate to the managed secret store without static credentials.
Outcome
Deployed across development, staging and production, running bare-metal alongside the managed AKS and EKS estate on the same GitOps control plane and delivery pipeline. Provider lock-in stopped being a commercial blocker.
Read the full case study
Approach

Three engagement shapes. One set of principles.

Outcome-led scopes. Written before built. Async-friendly across time zones. Your team owns it after.

Fixed-scope project

Defined deliverable, timeline, and price. Best when the problem is known and you want a clean line-item on the books.

2 – 6 weeks

Fractional retainer

Embedded with your team. Architecture, mentoring, on-call backup, hiring support. Best when a full-time platform engineer isn't justified yet.

10 – 20 hrs / week

Audit or advisory

A focused audit, a paid strategy call, or a single discrete deliverable. For second opinions, due diligence, or unblocking a decision.

Discrete
Written before built.

Every engagement starts with a written scope and success criteria. No goalpost drift mid-project.

Async-first across time zones.

I overlap with US, EU and APAC business hours. Loom + written updates beat status meetings.

Outcomes over hours.

Fixed-scope wherever the work allows. Retainers measured in shipped wins, not seat time.

Your team owns it after.

Runbooks, ADRs, walkthroughs, pairing. Nothing I build is a black box you can't operate.

About

Quietly working with serious teams, globally.

Ashik Mostofa Tonmoy

Independent DevOps & Platform Engineering consultant based in Bangladesh, working remote-first with clients across the US, EU and APAC. I architect platforms production teams actually want to operate — Kubernetes done right, GitOps that survives the second year, and cloud bills that match the value being shipped. Full resume (PDF) ↓

Accountable for production infrastructure, not advising on it. Infrastructure I've built serves 2M+ daily requests at 99.9% availability against contracted SLAs. GitOps platforms I've architected manage 1,000+ apps across 10 clusters. HIPAA-compliant systems delivered with zero security incidents, and I've worked under client NDAs across ISO 27001, GDPR, FADP and SOC 2 environments. Outside client work I'm Lead DevOps Instructor at Ostad, where I've trained 800+ engineers across 12 cohorts. B.Sc. Electronics & Communication Engineering, KUET.

KubernetesRKE2ArgoCDTektonHelmTerraformAnsibleAWSAzureGitHub ActionsGitLab CI/CDPrometheusGrafanaDatadogOpenTelemetrySonarQubeTrivyWireGuardPythonGo
Experience

Six roles, three of them owning production infrastructure.

Where the case studies came from. Consulting is what I do now; operating other people's production estates is how I learned what actually survives the second year.

  1. Aug 2024 — Present

    Senior DevOps Engineer · Selise Digital Platforms

    Infrastructure owner for the company's commercial multi-tenant PaaS, serving enterprise clients across Europe and North America — 10 clusters, 8 environments, 2M+ daily requests at 99.9% availability against contracted SLAs.

  2. May 2025 — Present

    Lead DevOps Instructor · Ostad

    Designed and deliver “Mastering DevOps” — 17 weeks, 18 modules, 36 live sessions. 800+ engineers trained across 12 cohorts, from university students to senior professionals.

  3. Apr 2024 — Jul 2024

    DevOps Engineer · W3 Engineers Ltd.

    Replaced manual AWS provisioning with Terraform IaC — 75% faster deployments, configuration drift eliminated. Passed an external security audit and migrated 15+ legacy applications with zero-downtime blue-green deploys.

  4. Nov 2023 — Mar 2024

    DevOps Engineer · Zaynax Group

    Built and operated a highly available on-premises Kubernetes platform on air-gapped infrastructure meeting government compliance requirements. Cut development-to-production cycle time 60% for a team new to DevOps.

  5. Jan 2023 — Oct 2023

    MLOps Engineer · InNeed Intelligent Cloud

    Ran AWS EKS with mixed fixed and spot capacity for a HIPAA-compliant ML platform — 70% infrastructure cost reduction, zero security incidents. Model deployment lead time went from weeks to hours.

  6. Dec 2021 — Dec 2022

    Machine Learning Engineer · ACME AI

    Led the Bill & Melinda Gates Foundation-funded livestock detection project using computer vision, reaching 92% production accuracy, and led an 8-person cross-functional team across data acquisition, training and deployment.

FAQ

What clients actually ask first.

The 7 questions that come up on every intro call, cleared up in advance.

Do you take freelance and contract work?

Yes — freelance and contract engagements are most of what I do, fully remote for clients in the US, EU and APAC. That covers fixed-scope projects (a cloud cost audit, a Kubernetes or GitOps platform build, a CI/CD pipeline rebuild) and ongoing fractional DevOps retainers. I contract directly and through the usual freelance platforms.

What time zones do you work in?

Based GMT+6 (Bangladesh) but built for async. Overlap with EU mornings, US Pacific evenings, and the full APAC business day. Most clients see me responsive 12+ hours a day on Slack / Linear / email.

Do you work fixed-fee or hourly?

Fixed-scope whenever the work allows it — that protects both of us. Retainers are quoted weekly. I don't publish hourly rates because the deliverable is what matters. Pricing is discussed on the intro call once we've scoped the problem.

How fast can you start?

Audits and advisory sessions usually within 1–2 weeks. Larger projects (cluster builds, platform work) typically kick off 2–4 weeks out. If something's on fire, say so on the intro call — I keep a small amount of capacity for urgent work.

Do you work with my existing team or solo?

Both. Most engagements run alongside an internal team — I embed, pair with your engineers, and leave them able to operate what I've built. Where there isn't yet a platform team to pair with, I deliver directly, and for larger builds I bring in engineers from the delivery company I co-founded. Scope isn't capped by one person's calendar, and I stay accountable for the work either way.

What does the first 30 days look like?

Week 1: scoping interviews, access, written engagement doc. Week 2: discovery / audit, surfaced findings, prioritised plan. Weeks 3–4: implementation on the agreed scope, weekly written check-ins, live demo at end of week 4.

Do you sign NDAs?

Yes — happy to sign before the first call. I've worked under client NDAs across ISO 27001, GDPR, FADP and SOC 2 environments.

— Let's talk

Let's see if I'm a fit for what you're actually trying to ship.

A 30-minute call. Tell me the shape of the problem. If I'm the right fit we'll scope an engagement; if I'm not, I'll point you at someone who is.

Currently booking Q4 2026
tonmoy.ashik@gmail.com

Or send a brief

No spam · reply within 24h on business days
Mailto fallback: tonmoy.ashik@gmail.com