Track 1 · Azure-first delivery platform

A paved road from repository to reliable Azure production.

Peak Consulting is testing a productized platform-engineering service for lean teams that need repeatable CI/CD, infrastructure, security, observability, and recovery—but cannot yet staff a mature internal platform function.

10 days baseline 1–2 application archetypes 6–8 weeks implementation 90 days optional stabilization

Scope and prices are working hypotheses under customer discovery.

Standardize the journey, not every engineering decision

The outcome is not “install Kubernetes.” It is that a product team can provision, deploy, observe, and recover an approved service without waiting for the one infrastructure expert.

Developer flow

Reduce manual waits

Turn repeated environment, pipeline, access, and deployment handoffs into a documented, supported path.

Production control

Make releases observable

Connect each release to quality gates, artifacts, approvals, workload health, rollback, and a named owner.

Transferable system

Remove key-person risk

Keep templates, IaC, pipelines, diagrams, and runbooks in client-controlled systems so another engineer can repeat the journey.

Manual releases Open platform role Duplicated IaC AKS without ownership Migration friction Audit evidence gaps

Diagnose one journey. Build one path. Prove adoption.

Each stage is bounded and independently useful. The first implementation centers on one representative application archetype rather than an open-ended platform transformation.

Step 1 · 10 business days

Azure Delivery Platform Baseline

$12k–$18k working range

Map one repository-to-production journey, assess the Azure foundation, CI/CD, IaC, service destination, controls, rollback, and developer friction.

Output: target paved road, ranked backlog, acceptance measures, and “do not build” list.

Step 2 · 6–8 weeks

Azure Golden Path Project

$25k–$45k one archetype

Implement reusable CI/CD, approved IaC, environments, identity, secrets, supply-chain controls, release telemetry, rollback, and operating handoff.

Acceptance: a product team deploys a representative service through the path.

Step 3 · Fixed bridge

90-day Platform Stabilization

$6k–$12k/mo working range

Operate the path with the client, remove adoption friction, onboard bounded additional services, measure outcomes, and transfer ownership.

Not unlimited migrations, ticket capacity, or a named full-time engineer.

One Azure foundation, several approved workload destinations

The paved road connects developer experience to delivery automation, controlled environments, the right Azure runtime, and shared operating controls.

Developer experience
Service templates Documentation Ownership metadata Self-service requests
Software delivery
Source CI and tests Security scans Artifacts Approvals and CD
Environment platform
Catalog Bicep / Terraform Configuration Workload identity Secrets
Workload destination
App Service Container Apps AKS when justified
Shared Azure controls
Landing zones RBAC and policy Network Observability Cost Recovery

Kubernetes is a decision, not the product

DestinationUse it whenPause when
App Service Conventional web/API applications benefit from a managed runtime and simple operations. The workload requires complex sidecars, custom scheduling, or direct orchestration APIs.
Container Apps Containerized APIs, jobs, and event-driven services need managed scaling without cluster ownership. Teams require deep Kubernetes customization or direct control of the Kubernetes API.
AKS Multiple workloads need Kubernetes ecosystem capabilities, scheduling, isolation, or portability. There is one small app, no cluster owner, weak recovery practice, or Kubernetes is chosen mainly for prestige.

Six weeks from target decision to production evidence

Week 0–1

Choose the path

Confirm archetype, owner, current journey, target architecture, access, exclusions, and measures.

Week 2

Provision safely

Deliver versioned IaC, identity, configuration, and a repeatable non-production environment.

Week 3

Build and verify

Implement tests, scans, traceable artifacts, and gates that stop a failed change.

Week 4

Release and recover

Implement CD, secrets, approvals, deployment telemetry, and tested rollback.

Week 5–6

Adopt and hand off

Onboard the representative service, exercise the path, document ownership, and capture outcomes.

Acceptance is behavioral

  • A second engineer can provision the approved non-production environment.
  • A failed quality or security gate prevents promotion.
  • An artifact and release can be traced to source and approval.
  • Rollback or redeployment has been exercised.
  • The product team can find release and workload health.
  • The service has an owner, runbook, telemetry, and cost attribution.
  • The first product team uses the path in production.
  • Open exceptions and next work are visible and bounded.

AI accelerates the build. Humans approve the operating system.

AI can accelerate
  • IaC and pipeline scaffolding
  • Configuration and documentation analysis
  • Test and policy-case generation
  • Runbook and telemetry-query drafts
  • Code-review assistance and pattern detection
Humans must own
  • Architecture and workload-service selection
  • Production access and separation of duties
  • Acceptance criteria and exceptions
  • Incident, recovery, and change decisions
  • Final review of production-impacting changes

AI-generated infrastructure is untrusted until it passes peer review, static checks, non-production execution, security gates, and acceptance evidence.

— Delivery control

What this track includes—and what it deliberately excludes

Included

  • One or two named developer journeys
  • Bounded application archetypes
  • Azure architecture, CI/CD, and IaC
  • Identity, secrets, policy, and observability integration
  • Deployment recovery, documentation, and handoff

Separately scoped or excluded

  • Unlimited application migrations
  • Primary 24/7 cluster and incident ownership
  • A custom portal before the paths work
  • Blanket replacement of existing tools
  • Body-only staff augmentation

Architecture references: Microsoft platform engineering, Azure Deployment Environments, and AKS platform engineering.

Platform engineering is the foundation. AI production is the adjacent track.

Both tracks share Azure identity, networking, IaC, CI/CD, observability, cost, recovery, and client-owned operating evidence.