omaro::solutions v.26.05
since 2005 region eu-north-1[book ↗]
omaro@infra:~$ cat ./manifesto.md
omaro::solutions

AWS, Azure, GCP —
all infrastructure in Terraform.
ClickOps Reproducible.
No surprises.

Omaro Solutions is a senior cloud-architecture and DevOps practice in Stockholm. One engineer at the core, named subcontractors when scope grows — never headcount theatre. Two decades in production, fifteen years in cloud, a decade running DevOps for everything from million-user platforms to Series-B scale-ups. PRs over tickets. Modules over snowflakes. Agents pair on PRs and ops; the merge button still belongs to a human. Pipelines you can read on a Sunday and still understand on Monday.

// sectors served
two decades · six sectors
20yrs
In production. 15 in cloud, a decade in DevOps, every year shipping.
/01
3clouds
AWS, Azure, GCP. Same Terraform underneath, same boring reliability on top.
/02
100%
Infrastructure as code. No clicks. No drift. No exceptions.
/03
0
ClickOps changes in production. Period.
/04
// 01 — services

Four modules. One senior engineer who slots into your team.

Hire by module or as a fractional platform engineer. The work happens inside your team — Slack, on-call, PRs — never as a black-box agency. Senior subcontractors brought in by name when scope grows.

// best fit · Best fit for SaaS scale-ups, post-Series-A engineering teams, and regulated mid-market clients migrating to or modernising on the cloud.

module.cloud_architecture

Cloud architecture

// one org chart, one Terraform tree

Multi-region, multi-account, multi-cloud topologies that actually map to your org. Landing zones, Transit Gateways, DirectConnect, IAM, FinOps guardrails — all in Terraform, all reviewed in PRs. Built and run organisations with dozens of accounts under a single, audited Org.

aws-organizationsgcpazuretransit-gatewaydirectconnectscp
module.devops_platform

DevOps & platform

// the Jenkins server, retired

CI/CD your team won’t fight. Reusable Terraform modules with verify · test · plan · apply on every PR. AI code review and change-aware test selection on every diff — fast feedback, fewer false positives. GitHub Actions, GitLab CI, Kubernetes (EKS), ECS, Helm. We leave a platform that compounds — not a Jenkins server that haunts you.

terraformgithub-actionsgitlab-cieksecshelmai-code-review
module.ai_ops

AI-augmented ops, SRE & security

// agents do the legwork, you keep the merge button

Agentic ops in production, safely. MCP-controlled access to your infra, observability and ticketing. Agents triage alerts, cross-reference dashboards, and draft remediations. Everything goes through an audit log, and they escalate to a human the moment their confidence drops. Observability stays human-readable at 3 a.m.: Grafana & Prometheus on Kubernetes via Helm + Grafonnet, OpenTelemetry across clouds, OPA for IaC, OIDC-federated everything, no static credentials.

mcpclaude-codeagentic-opsllm-evalgrafanaprometheusopentelemetryopaoidc
module.consultancy

Consultancy, FinOps & compliance

// scoped in days, not retainer-months

Architecture reviews. FinOps deep-dives with Cost Intelligence dashboards your finance team can read. SOC 2 & ISO 27001 readiness — hands-on, end-to-end, with audit-ready evidence in the same repo as the platform. Migrations, audits, second opinions.

finopssoc2iso27001migrationarch-review
// 02 — principles

How we work — and why it sticks.

Engineering opinions worth printing on a t-shirt. Or at least pinning in #platform.

If it isn't in git,
it doesn't exist.

  1. No ClickOps.

    Console access is read-only. Every change goes through a PR, a plan and a paper trail. Even ours.

  2. We hand it back.

    Not a moat. Every engagement ends with you owning the modules, the dashboards and the runbooks — documented, in your repo.

  3. Senior, single point of contact.

    The engineer who scopes the work writes the work. No account managers, no junior hand-offs, no body-shopping.

  4. Boring tech, on purpose.

    Postgres, Terraform, Kubernetes, S3. Novelty earns its place when it pays for itself — not because it’d look good on a blog post.

  5. Agents pair. Humans review.

    Agents review PRs, generate tests, page themselves before they page you, and propose remediations end-to-end. The merge button, the prod migration, the IAM change — those still go through a human and an audit log. Velocity without a paper trail is just debt with better PR.

// 03 — typical engagements

What we actually do, week by week.

These are the patterns we keep getting hired for. Specifics, references and case-notes shared 1:1 under NDA.

~ 1 wk
@discovery · fixed-price written assessment
Two days reading your repo, your dashboards, your on-call, your cloud bill. Two days writing it up. You leave with a prioritised roadmap, named risks, and the cheapest wins to ship first — → keep it whether we work together or not.
~ 4–12 wk
@cloud-architecture · landing zones & multi-account org
AWS / Azure / GCP organisations done properly: identity, networking, logging, billing, FinOps guardrails — all in Terraform, all reviewed in PRs. Pre-baked golden paths your engineers use on day one. → a platform your auditors can read.
~ 6–12 wk
@devops-platform · ci/cd & gitops modernisation
Replace the Jenkins server everyone's afraid of. Reusable Terraform modules with verify · test · plan · apply on every PR. OIDC-federated cloud access — no static credentials anywhere. → commits to production without paging anyone.
~ 6–12 wk
@observability · metrics, logs, traces — across clouds
Grafana & Prometheus on Kubernetes via Helm + Grafonnet. OpenTelemetry across AWS / Azure / GCP. Custom exporters where the vendors gave up. Alerts that wake a human only after the obvious checks have already run. → a 3 a.m. dashboard you can read with one eye open.
~ 6–12 wk
@ai-platform · agentic ops & AI-driven CI/CD
MCP servers wired to your cloud, observability and ticketing. Agents that triage alerts, cross-reference dashboards, draft remediations and PR comments — gated behind audit logs, confidence thresholds and human review for prod-state changes. AI code review and change-aware test selection on every PR. Eval pipelines for any LLM-touched code path, treated like broken tests when they fail. → ops the team trusts to run on its own — and a clear escalation path when it shouldn’t.
~ 3–6 mo
@compliance · soc 2 & iso 27001 readiness
Compliance-as-code in the same repo as the platform. Vulnerability remediation, documented controls, audit-ready evidence pipelines. We've taken regulated teams through both standards end-to-end. → audit-ready without a six-month consulting bill.
~ 2–4 wk
@finops · cost & performance deep-dive
Right-sizing, Spot, savings plans, transit-cost audits, network topology rework. Cost Intelligence dashboards your finance team can actually read. Honest answers about what's worth optimising and what isn't. → measurable cloud-bill cuts, no rugpulls.
ongoing
@fractional-platform · interim senior devops · retainer
Fractional senior platform engineering for teams that need the seniority but not the headcount. Shared on-call. Architecture review board of one. PRs and pairing instead of slide decks. → a senior engineer who slots into your team.
// 04 — about

About omaro::solutions.

Senior cloud architecture & DevOps practice based in Stockholm. Sweden · EU calendar · remote-default, on-site for kickoffs.

Reproducible.
Observable.
Boring in production.

  1. How we’re set up.

    One senior engineer at the core, working directly with your team. Named subcontractors brought in by name when scope grows — never a body-shop, never a junior hand-off. The engineer who scopes the work writes the work.

  2. Where we work.

    Stockholm office, EU-wide remote. Most clients in the Nordics and the DACH region; happy to travel for kickoffs and quarterly checkpoints.

  3. Hours & reach.

    CET working hours. Enquiries answered within one business day — and yes, every message is read. $ start a conversation ↗

// ready when you are

Stop firefighting. Start shipping.

Drop a few lines about your stack and what hurts. No salespeople, no slides. You’ll get a real reply within a business day, and a 30-minute discovery call if we’re a fit.

No spam. No retainer pressure. We answer every message.