Cloud infrastructure and platform engineering

Infrastructure for products that cannot afford to be fragile.

Yeti designs and builds the cloud foundations behind SaaS platforms, customer journeys and integrated digital services.

We design cloud foundations to support resilience, security, scaling, monitoring and recovery, with the operational documentation and continued support required by the agreed operating model.

What better infrastructure gives you

A stronger product, not just a different cloud setup.

The infrastructure underneath a product determines how confidently it can launch, grow and recover.

Design for resilience under pressure.

Routing, redundancy and service boundaries can be designed to isolate failures and redirect traffic where the product requires it.

Healthy route in use

Scale without rebuilding everything.

Capacity and service boundaries are designed to support growth without forcing an avoidable full-platform rebuild.

Capacity expanding

Keep sensitive systems behind controlled boundaries.

Public traffic, application services and data can be separated using appropriate network, identity and access controls.

Boundary enforced

Make production behaviour visible.

Monitoring, logs and alerts are designed to surface problems and support an informed response.

Signal detected early

The system underneath

The product stays simple. The complexity is handled underneath it.

Every product is different, but production platforms usually need coordinated layers for traffic, applications, data, access, recovery and operations.

Normal operation. Traffic is routed to the active primary environment while the recovery environment remains on standby.

Traffic is routed to the active primary environment while the recovery environment remains on standby. Monitoring observes both environments and data and assets are replicated according to the illustrative design.

What Yeti delivers

Architecture, implementation and an operating model your team can understand.

  • Product requirements
  • Operational needs
  • Security and access
  • Data and integrations
  • Resilience requirements

Target architecture

  • Environment model
  • Security controls
  • Data and integrations
  • Resilience approach

Implementation plan

Architecture and planning

Design the foundation.

We turn product, operational, security and data requirements into one agreed technical architecture and delivery plan.

Environments and release

Build once. Promote safely.

We create the environments, networking and deployment automation in code, then move tested changes through development, testing and production using a controlled release process.

Availability

Service health

Performance

Response time

Errors

Error rate

Cost

Usage and spend

Monitoring and alerting

  • Health visibility
  • Thresholds
  • Alerts
  • Diagnostic context

Operational response

  • Incident ownership
  • Escalation
  • Runbooks

Recover and improve

  • Restore service
  • Confirm stability
  • Review the incident
  • Improve the controls
Monitoring and operations

Make it visible and operable.

We establish the monitoring, alerts, operational ownership and recovery procedures needed to run the product confidently in production.

  • Service health
  • Alerting
  • Incident response
  • Runbooks
  • Recovery

Designed for real conditions

A fault should not become a full outage.

Yeti designs platforms to detect unhealthy components, stop sending traffic to them, keep customers on working capacity and alert the operating team to recover the service and address the cause.

How we work

A clear path from uncertainty to production.

UncertaintyWorking production platform
  1. STEP 1

    Define

    We establish what the product must support, where the risks sit, then agree the architecture, environments, access model, data services and recovery requirements.

  2. STEP 2

    Build

    We implement and automate the agreed infrastructure in code, connect it to the product and test the critical operational paths.

  3. STEP 3

    Monitor

    We launch, then watch how the platform behaves in production: service health, performance, errors, capacity and cost.

  4. STEP 4

    Iterate

    We use that evidence to tune capacity, releases, monitoring and recovery procedures, so the platform keeps improving after launch.

The technology we work with

Depending on the product and its existing technology, our work may include Microsoft Azure, AWS, .NET, Node.js, TypeScript, managed SQL and PostgreSQL services, Terraform, Terragrunt and automated delivery pipelines.

We choose the technology around the product, the existing estate, the team responsible for it and how it needs to be operated.

Worked example

A full platform, drawn end to end.

The same system in full detail: one cloud platform, a production environment and a matching testing environment, each running across two regions, with a shared management environment for identity, name resolution and private access.

Regions are numbered and every service is named by what it does, so the drawing stays accurate when a provider renames a product or retires a region. Data is only ever reached through private endpoints inside the network. Copies between regions are continuous. Failover paths carry work only when a region is lost.

Detailed two-environment platform architecture

One cloud platform holding a production environment, a matching testing environment and a shared management environment. Each application environment runs in two numbered regions with private-only paths to data, cross-region copies and a region-loss failover path. Regions are numbered rather than named, and services are named by function.

  1. Cloud platform
    1. Production environment
      1. Global entry
        1. Traffic entry
          1. Edge filtering
          2. Global traffic routing
        2. Provider-managed boundary
          1. Private endpoint
        3. Provider-managed boundary
          1. Private endpoint
        4. Platform monitoring
        5. Threat detection
      2. Region 1
        1. Applications
          1. Managed services
            1. Secret store zone
            2. Object storage zone
            3. Application host zone
            4. Relational data zone
            5. Application telemetry
          2. Highly available managed services
            1. Availability zone
              1. Application host capacity
              2. Application services
            2. Secret stores
            3. Object storage
            4. Relational data
          3. Private network
            1. Application integration subnet
              1. Application network interface
            2. Private endpoint subnet
              1. Secret store endpoint
              2. Object storage endpoint
              3. Relational data endpoint
      3. Region 2
        1. Applications
          1. Managed services
            1. Secret store zone
            2. Object storage zone
            3. Application host zone
            4. Relational data zone
            5. Application telemetry
          2. Highly available managed services
            1. Availability zone
              1. Application host capacity
              2. Application services
            2. Object storage
            3. Relational data
          3. Private network
            1. Application integration subnet
              1. Application network interface
            2. Private endpoint subnet
              1. Secret store endpoint
              2. Object storage endpoint
              3. Relational data endpoint
    2. Testing environment
      1. Global entry
        1. Traffic entry
          1. Edge filtering
          2. Global traffic routing
        2. Provider-managed boundary
          1. Private endpoint
        3. Provider-managed boundary
          1. Private endpoint
        4. Platform monitoring
        5. Threat detection
      2. Region 1
        1. Applications
          1. Managed services
            1. Secret store zone
            2. Object storage zone
            3. Application host zone
            4. Relational data zone
            5. Application telemetry
          2. Highly available managed services
            1. Availability zone
              1. Application host capacity
              2. Application services
            2. Secret stores
            3. Object storage
            4. Relational data
          3. Private network
            1. Application integration subnet
              1. Application network interface
            2. Private endpoint subnet
              1. Secret store endpoint
              2. Object storage endpoint
              3. Relational data endpoint
      3. Region 2
        1. Applications
          1. Managed services
            1. Secret store zone
            2. Object storage zone
            3. Application host zone
            4. Relational data zone
            5. Application telemetry
          2. Highly available managed services
            1. Availability zone
              1. Application host capacity
              2. Application services
            2. Object storage
            3. Relational data
          3. Private network
            1. Application integration subnet
              1. Application network interface
            2. Private endpoint subnet
              1. Secret store endpoint
              2. Object storage endpoint
              3. Relational data endpoint
    3. Management environment
      1. Region 1
        1. Private connectivity
          1. Private access
            1. Network access rules
            2. Private gateway
      2. Identity directory
      3. Threat protection
      4. Relational data zone
      5. Application host zone
      6. Secret store zone
      7. Object storage zone
  2. Public users
  3. Internal testers
  4. Employees

Routes between parts of the structure:

  • Production environment: Public users connects to Edge filtering: public traffic.
  • Production environment: Global traffic routing connects to Private endpoint.
  • Production environment: Global traffic routing connects to Private endpoint.
  • Production environment: Private endpoint connects to Application network interface in region 1.
  • Production environment: Private endpoint connects to Application network interface in region 2.
  • Production environment: Managed services in region 1 connects to Private network in region 1: private name-resolution link.
  • Production environment: Managed services in region 2 connects to Private network in region 2: private name-resolution link.
  • Production environment: Secret store endpoint in region 1 connects to Secret stores in region 1.
  • Production environment: Object storage endpoint in region 1 connects to Object storage in region 1.
  • Production environment: Relational data endpoint in region 1 connects to Relational data in region 1.
  • Production environment: Application services in region 1 connects to Application network interface in region 1.
  • Production environment: Secret store endpoint in region 2 connects to Secret stores in region 1.
  • Production environment: Object storage endpoint in region 2 connects to Object storage in region 2.
  • Production environment: Relational data endpoint in region 2 connects to Relational data in region 2.
  • Production environment: Application services in region 2 connects to Application network interface in region 2.
  • Production environment: Secret stores in region 1 only carries work on loss, from Highly available managed services in region 2: failover to paired region on loss.
  • Production environment: Object storage in region 1 is copied between the two regions, reaching Object storage in region 2.
  • Production environment: Relational data in region 1 is copied between the two regions, reaching Relational data in region 2.
  • Production environment: Private gateway in region 1 connects to Private network in region 1: private network peering.
  • Production environment: Private gateway in region 1 connects to Private network in region 2: private network peering.
  • Testing environment: Internal testers connects to Edge filtering: tester traffic.
  • Testing environment: Global traffic routing connects to Private endpoint.
  • Testing environment: Global traffic routing connects to Private endpoint.
  • Testing environment: Private endpoint connects to Application network interface in region 1.
  • Testing environment: Private endpoint connects to Application network interface in region 2.
  • Testing environment: Managed services in region 1 connects to Private network in region 1: private name-resolution link.
  • Testing environment: Managed services in region 2 connects to Private network in region 2: private name-resolution link.
  • Testing environment: Secret store endpoint in region 1 connects to Secret stores in region 1.
  • Testing environment: Object storage endpoint in region 1 connects to Object storage in region 1.
  • Testing environment: Relational data endpoint in region 1 connects to Relational data in region 1.
  • Testing environment: Application services in region 1 connects to Application network interface in region 1.
  • Testing environment: Secret store endpoint in region 2 connects to Secret stores in region 1.
  • Testing environment: Object storage endpoint in region 2 connects to Object storage in region 2.
  • Testing environment: Relational data endpoint in region 2 connects to Relational data in region 2.
  • Testing environment: Application services in region 2 connects to Application network interface in region 2.
  • Testing environment: Secret stores in region 1 only carries work on loss, from Highly available managed services in region 2: failover to paired region on loss.
  • Testing environment: Object storage in region 1 is copied between the two regions, reaching Object storage in region 2.
  • Testing environment: Relational data in region 1 is copied between the two regions, reaching Relational data in region 2.
  • Testing environment: Private gateway in region 1 connects to Private network in region 1: private network peering.
  • Testing environment: Private gateway in region 1 connects to Private network in region 2: private network peering.
  • Employees connects to Private gateway in region 1: employee access.

Public users

Internal testers

00Cloud platform
01Production environment
Global entry
Provider-managed boundary

Private endpoint

Traffic entry
E1

Edge filtering

E2

Global traffic routing

Provider-managed boundary

Private endpoint

Platform monitoring

Threat detection

R1Region 1
Applications
Managed services

Secret store zone

Object storage zone

Application host zone

Relational data zone

Application telemetry

Private network
Application integration subnet

Application network interface

Private endpoint subnet

Secret store endpoint

Object storage endpoint

Relational data endpoint

Highly available managed services
Availability zone
A1

Application services

Application host capacity

K1

Secret stores

Object storage

Relational data

R2Region 2
Applications
Highly available managed services
Availability zone
A2

Application services

Application host capacity

Object storage

Relational data

Private network
Application integration subnet

Application network interface

Private endpoint subnet

Secret store endpoint

Object storage endpoint

Relational data endpoint

Managed services

Secret store zone

Object storage zone

Application host zone

Relational data zone

Application telemetry

02Testing environment
Global entry
Provider-managed boundary

Private endpoint

Traffic entry
E1

Edge filtering

E2

Global traffic routing

Provider-managed boundary

Private endpoint

Platform monitoring

Threat detection

R1Region 1
Applications
Managed services

Secret store zone

Object storage zone

Application host zone

Relational data zone

Application telemetry

Private network
Application integration subnet

Application network interface

Private endpoint subnet

Secret store endpoint

Object storage endpoint

Relational data endpoint

Highly available managed services
Availability zone
A1

Application services

Application host capacity

K1

Secret stores

Object storage

Relational data

R2Region 2
Applications
Highly available managed services
Availability zone
A2

Application services

Application host capacity

Object storage

Relational data

Private network
Application integration subnet

Application network interface

Private endpoint subnet

Secret store endpoint

Object storage endpoint

Relational data endpoint

Managed services

Secret store zone

Object storage zone

Application host zone

Relational data zone

Application telemetry

03Management environment

Secret store zone

Object storage zone

Application host zone

Relational data zone

Identity directory

Threat protection

R1Region 1
04Private connectivity
Private access
G1

Private gateway

Network access rules

Employees

Lines

Structural route
Supporting relationship
Continuous two-way copy
Path used on loss only

Elements

Primary system block
Supporting service
Privately reached service
Data store

Boundaries

Defined system
Logical grouping
Protected area
01

The source topology and containment relationships are preserved using provider-neutral labels.

02

Region 2 is drawn mirrored so the two regions meet along their data services. The cross-region copy and failover paths are the shortest runs on the page.

03

The supporting line between managed services and the private network is the private name-resolution link, drawn once for each region.

04

Continuous copies are drawn as solid two-way runs. Paths that only carry work when a region is lost are drawn dashed and one-way.

Two mirrored application environments and a shared management environment inside one cloud platform. Each environment filters traffic at the edge, routes it privately into two regions, reaches data only through private endpoints, copies data continuously between regions and keeps a failover path for the loss of a region. Platform service names are used factually to describe a technical structure. No vendor marks are reproduced and no affiliation or endorsement is implied.

About these diagrams

These diagrams illustrate Yeti’s approach to infrastructure design and operation. The architecture, technologies, controls, resilience measures, availability targets, recovery objectives, responsibilities, support arrangements and service levels for each engagement are designed around the product, its existing technology, data sensitivity, operating model and agreed scope, and are defined in the applicable proposal and client agreement.

Building something that needs stronger foundations?

Tell us what the product does, where the risk sits and what has to be true when it reaches production.

New platform, a system that has outgrown its foundations, a migration or a product handling sensitive data.