I will write, refactor or optimise your terraform, pulumi iac
About this Gig
Bad IaC is one of the most expensive technical debts a team can carry. I've seen it all hardcoded values, copy-pasted modules, no state management, resources drifting from code, stacks that no one dares touch.
At Transform DevOps, we fix that.
Whether you're starting fresh or need your existing code cleaned up and made production-ready, I'll write IaC you can actually maintain.
What's included:
- Terraform module design and refactoring (remote state, workspaces, DRY structure, Terragrunt consideration)
- Pulumi stack setup in Python, TypeScript
- CloudFormation template rewrites with nested stacks and parameter best practices
- State migration and import of existing resources
- Tagging strategies, naming conventions, environment separation
- Full inline documentation so your team can take it forward
- Cost Optimisaton measures factored into delivery
All code delivered with a README and deployment instructions.
Frameworks:
Npm
•
Terraform
•
Pulumi
•
Ansible
•
Puppet
Cloud Provider:
Amazon Web Services
•
Google Cloud Platform
Programming language:
Bash
•
JavaScript
•
PHP
•
Python
•
Ruby
Expertise:
Installation
•
Migration
•
Configuration
FAQ
Which IaC tools do you work with?
Terraform, Pulumi (Python, TypeScript), and AWS CloudFormation. If you're unsure which is right for your use case, mention it and I'll advise.
Can you import existing AWS resources into Terraform or Pulumi state?
Yes, state import and resource adoption is included where applicable.
Will you follow our existing naming conventions and structure?
Absolutely. Share your conventions upfront and I'll work within them.
Do you write tests for IaC?
Yes, I can include Terratest or Checkov static analysis as part of the delivery if required — mention this when ordering. If Pulumi is the target IaC, I can write some base level tests in the target programming language)
What if we need ongoing support after delivery?
I offer follow-up packages. Message me and we can discuss a support arrangement.
Do you follow security best practices when writing infrastructure as code?
Yes, security is built in by default — not an afterthought. All IaC I deliver follows least privilege & RBAC IAM, encryption at rest & in transit, private networking where appropriate, no hardcoded secrets or credentials. I also run static security analysis tools as part of delivery
Can you help align our IaC with compliance frameworks like SOC 2, ISO 27001, or CIS Benchmarks?
Yes. If you have a specific compliance requirement, flag it when ordering and I'll ensure the infrastructure is structured & documented accordingly. This includes things like audit logging, access controls, encryption standards for compliance traceability. This can be done also in my devsecops gig.
