Advisory

Architecture review

We walk through your cloud layout, secrets, integrations, and data storage against our Terraform and Ansible reference — and send you a readiness checklist.

Scope

What we look at

Focused on getting your first customer instance production-ready.

cloud

Cloud & network

Cloud Run service accounts, Cloud SQL connectivity, GCS documents bucket, and project IAM for GitHub Actions actAs.

key

Secrets & config layers

Secret Manager ↔ Ansible vault mapping, domain_config vs config.json vs brand, and no secrets in the container image.

hub

Tools & MCP

ENABLED_TOOLS, custom_tools MCP allowlists, S2S auth, tenant header (X-Tenant-ID), and HTTPS Host allowlists on customer MCP hosts.

database

Data plane

Postgres schemas and search_path, Qdrant collections, Langfuse project isolation, and conversation persistence for API tier.

You receive

Written output after the call

  • task_altWritten topology diagram for your tier (enterprise vs api)
  • task_altGap list against whitelabel Terraform modules and Ansible bootstrap
  • task_altRecommended smoke checks and CI permissions (including iam.serviceAccountUser)
  • task_altOptional follow-up workshop with Bold Innovation