Expertise
AWS expertise: design, migrate and operate your cloud infrastructure
Amazon Web Services is the most complete cloud platform on the market: compute (EC2, ECS, EKS, Lambda), managed databases (RDS, Aurora, DynamoDB), storage (S3), networking and delivery (VPC, CloudFront), security (IAM, KMS, WAF) and dozens of specialised services.
Agencei designs AWS architectures to host the applications we build and those of our clients: containers on ECS or EKS, PostgreSQL databases on RDS, Lambda functions, static sites on S3 and CloudFront. Everything is described as infrastructure as code with Terraform or AWS CDK.
This expertise is for companies migrating from a traditional host, looking to stabilise a hand-built AWS infrastructure, or trying to bring down a cloud bill that has become opaque.
Use cases
Migration to AWS
Moving applications and databases from shared hosting, dedicated servers or another cloud, with a planned cutover and a rollback path.
Hosting containerised applications
ECS Fargate or EKS for APIs and web applications, with load balancing, autoscaling and zero-downtime deployments.
Managed databases
RDS or Aurora PostgreSQL and MySQL with automatic backups, read replicas, encryption and controlled maintenance windows.
Serverless architectures
Lambda, API Gateway, SQS, EventBridge and DynamoDB for event-driven processing billed on usage.
Security and compliance
Multi-account organisation, least-privilege IAM, KMS encryption, WAF, CloudTrail logs and GuardDuty alerts.
Cost control
Bill analysis, right-sizing, reserved instances or Savings Plans, shutting down unused environments and resource tagging.
Project types
- Application migration to AWS
- Containerised infrastructure on ECS or EKS
- Managed RDS database
- Serverless architecture
- Static site or Next.js hosting
- AWS security and architecture audit
- Cloud bill optimisation
Integration with the rest of the stack
AWS + Docker + Kubernetes (EKS)
Images pushed to ECR, managed EKS cluster, ALB load balancing and node autoscaling, with CloudWatch or Prometheus observability.
AWS + Spring Boot or Node.js
Services deployed on ECS Fargate, secrets in Secrets Manager, SQS queues, email through SES and S3 storage.
AWS + PostgreSQL (RDS, Aurora)
Managed database with backups, encryption, read replicas and secure connectivity from the application's private subnets.
AWS + Next.js or React
Static delivery through S3 and CloudFront, or server rendering in a container or with Amplify Hosting, certificates managed by ACM.
AWS + CI/CD (GitHub Actions, GitLab CI)
Pipelines that build images, apply Terraform and deploy through OIDC, with no access keys stored in the repository.
Examples of problems solved
AWS bill rising with no explanation
Per-service and per-tag analysis with Cost Explorer, identifying oversized instances, orphaned volumes and expensive data transfers.
Hand-built infrastructure that cannot be reproduced
Importing existing resources into Terraform, setting up identical environments and change reviews before applying.
Overly permissive IAM roles
Policy audit, move to least privilege, removal of long-lived access keys in favour of roles and OIDC.
Outage during a traffic spike
Setting up autoscaling, a load balancer, CloudFront caching and health checks to remove failing instances.
Slow or saturated RDS database
Analysis with Performance Insights, adding indexes, parameter tuning, read replicas or a change of instance class.
Frequently asked questions
Is AWS suitable for an SME?
Yes, provided the architecture is properly scoped. An SME benefits from managed services (RDS, ECS Fargate, S3) that remove server administration, while keeping a readable bill if resources are right-sized and tagged.
How does a migration to AWS work?
Inventory of the existing setup, choice of target services, infrastructure as code, data migration with replication, testing, then DNS cutover with a rollback option.
Terraform or AWS CDK?
Both are solid. Terraform is provider-agnostic and widespread among operations teams; CDK suits teams that prefer describing infrastructure in TypeScript or Python.
How do you secure an AWS account?
Multi-account organisation, multi-factor authentication, least-privilege IAM, encryption by default, CloudTrail logging, GuardDuty detection and regular access reviews.
Can you take over an existing AWS infrastructure?
Yes. We start with an audit of the architecture, security and costs, then propose a recovery plan: codifying the infrastructure, priority fixes and monitoring.
Related services
AWS Services
Design, deployment and optimisation of AWS infrastructure: compute, databases, storage, IAM, costs.
See this serviceCloud Migration
Migration of applications and infrastructure to the public cloud, from lift-and-shift to re-architecture.
See this serviceDevOps Consulting
Setting up CI/CD, infrastructure as code, monitoring and GitOps practices.
See this serviceKubernetes Consulting
Kubernetes clusters (EKS, k3s), Helm charts, ingress, autoscaling and observability for your applications.
See this serviceSecurity
Hacked site cleanup, hardening, vulnerability assessment, WAF, backups and access management.
See this serviceMobile app
Native or React Native apps for iOS and Android, from scoping to app store publication.
See this serviceRelated expertise
Tell us about your project
Describe your need in a few lines: we come back to you with a first analysis and the next steps.