Skip to content
Agencei

Expertise

AWS expertise: design, migrate and operate your cloud infrastructure

Amazon Web Services is the most complete cloud platform on the market: compute (EC2, ECS, EKS, Lambda), managed databases (RDS, Aurora, DynamoDB), storage (S3), networking and delivery (VPC, CloudFront), security (IAM, KMS, WAF) and dozens of specialised services.

Agencei designs AWS architectures to host the applications we build and those of our clients: containers on ECS or EKS, PostgreSQL databases on RDS, Lambda functions, static sites on S3 and CloudFront. Everything is described as infrastructure as code with Terraform or AWS CDK.

This expertise is for companies migrating from a traditional host, looking to stabilise a hand-built AWS infrastructure, or trying to bring down a cloud bill that has become opaque.

Use cases

Migration to AWS

Moving applications and databases from shared hosting, dedicated servers or another cloud, with a planned cutover and a rollback path.

Hosting containerised applications

ECS Fargate or EKS for APIs and web applications, with load balancing, autoscaling and zero-downtime deployments.

Managed databases

RDS or Aurora PostgreSQL and MySQL with automatic backups, read replicas, encryption and controlled maintenance windows.

Serverless architectures

Lambda, API Gateway, SQS, EventBridge and DynamoDB for event-driven processing billed on usage.

Security and compliance

Multi-account organisation, least-privilege IAM, KMS encryption, WAF, CloudTrail logs and GuardDuty alerts.

Cost control

Bill analysis, right-sizing, reserved instances or Savings Plans, shutting down unused environments and resource tagging.

Project types

  • Application migration to AWS
  • Containerised infrastructure on ECS or EKS
  • Managed RDS database
  • Serverless architecture
  • Static site or Next.js hosting
  • AWS security and architecture audit
  • Cloud bill optimisation

Integration with the rest of the stack

  • AWS + Docker + Kubernetes (EKS)

    Images pushed to ECR, managed EKS cluster, ALB load balancing and node autoscaling, with CloudWatch or Prometheus observability.

  • AWS + Spring Boot or Node.js

    Services deployed on ECS Fargate, secrets in Secrets Manager, SQS queues, email through SES and S3 storage.

  • AWS + PostgreSQL (RDS, Aurora)

    Managed database with backups, encryption, read replicas and secure connectivity from the application's private subnets.

  • AWS + Next.js or React

    Static delivery through S3 and CloudFront, or server rendering in a container or with Amplify Hosting, certificates managed by ACM.

  • AWS + CI/CD (GitHub Actions, GitLab CI)

    Pipelines that build images, apply Terraform and deploy through OIDC, with no access keys stored in the repository.

Examples of problems solved

AWS bill rising with no explanation

Per-service and per-tag analysis with Cost Explorer, identifying oversized instances, orphaned volumes and expensive data transfers.

Hand-built infrastructure that cannot be reproduced

Importing existing resources into Terraform, setting up identical environments and change reviews before applying.

Overly permissive IAM roles

Policy audit, move to least privilege, removal of long-lived access keys in favour of roles and OIDC.

Outage during a traffic spike

Setting up autoscaling, a load balancer, CloudFront caching and health checks to remove failing instances.

Slow or saturated RDS database

Analysis with Performance Insights, adding indexes, parameter tuning, read replicas or a change of instance class.

Frequently asked questions

Is AWS suitable for an SME?

Yes, provided the architecture is properly scoped. An SME benefits from managed services (RDS, ECS Fargate, S3) that remove server administration, while keeping a readable bill if resources are right-sized and tagged.

How does a migration to AWS work?

Inventory of the existing setup, choice of target services, infrastructure as code, data migration with replication, testing, then DNS cutover with a rollback option.

Terraform or AWS CDK?

Both are solid. Terraform is provider-agnostic and widespread among operations teams; CDK suits teams that prefer describing infrastructure in TypeScript or Python.

How do you secure an AWS account?

Multi-account organisation, multi-factor authentication, least-privilege IAM, encryption by default, CloudTrail logging, GuardDuty detection and regular access reviews.

Can you take over an existing AWS infrastructure?

Yes. We start with an audit of the architecture, security and costs, then propose a recovery plan: codifying the infrastructure, priority fixes and monitoring.

Tell us about your project

Describe your need in a few lines: we come back to you with a first analysis and the next steps.