Fixed scope, published floor, named exclusions
Two ways in. An assessment or a workshop is how most people start, because it is
cheap enough to decide on quickly and produces something useful on its own. Builds
are what people buy once they have seen the work.
Entry — assessment and enablement
package/gcp-architecture-security-review
Your existing estate assessed against the Google Cloud architecture framework. Findings ranked by severity, with Terraform for the fixes that matter most.
- +IAM and organization policy audit
- +Network topology and VPC Service Controls
- +KMS and secrets handling
- +Security Command Center findings triage
- + 3 more in scope
- −remediation implementation
- −application-layer security
- −compliance certification
package/gcp-onboarding-workshops
Two days, instructor-led, built around your architecture rather than a generic curriculum. Hands-on labs in a sandbox project provisioned for the cohort.
- +Track of your choice: foundations, GKE, networking, or security
- +Material written against your own architecture and naming
- +Hands-on labs in a sandbox project provisioned for the cohort
- +Sumech’s own slides, walkthroughs, and lab exercises
- −Skills Boost licensing
- −official Google certification training
- −ongoing enablement
Build — delivery engagements
package/automation-iac-devsecops
A versioned Terraform module library, pipelines with real gates, and security scanning that runs on every commit instead of before an audit.
- +Terraform module library: versioned, tested, published to a private registry
- +Remote state, workspace, and environment promotion model
- +CI/CD delivery pipelines with environment gates
- +Policy as code: Terraform plan validation, Policy Controller on GKE
- + 4 more in scope
- −application code changes and test authoring
- −remediation of findings the scanners raise
- −third-party scanner licensing
- −non-GCP CI/CD platforms beyond the agreed runner
package/gcp-landing-zone
Organization hierarchy, identity model, Shared VPC, and hybrid connectivity, delivered as reusable Terraform modules with a handover runbook. Interconnect is priced inside, not renegotiated later.
- +Organization hierarchy and folder structure
- +IAM and least-privilege model
- +Shared VPC design
- +Hybrid connectivity: Cloud Interconnect or HA VPN, on-prem routing and DNS
- + 4 more in scope
- −workload migration
- −application refactoring
- −physical Interconnect procurement
package/vm-migration-to-gcp
VMware vSphere estates moved to Google Cloud with M2VM, snapshot-based cutover, and wave planning that survives contact with dependencies. 2,000+ VMs delivered.
- +Discovery and dependency mapping
- +Wave planning against real application dependencies
- +Migration factory setup
- +M2VM configuration and snapshot-based cutover design
- + 4 more in scope
- −application remediation
- −database platform changes
- −non-GCP target environments
package/gke-platform-engineering
Cluster architecture, autoscaling, and load testing against a defined latency SLO. Proving the platform holds at peak is the part most GKE work skips.
- +Cluster and node pool architecture
- +Horizontal and cluster autoscaling
- +Quota and limit design
- +Load and performance testing against defined latency SLOs
- + 2 more in scope
- −application containerization
- −service mesh
- −CI/CD pipeline authoring
package/governed-data-platform
Self-serve ingestion with Dataplex governance and Sensitive Data Protection underneath it: classification, column-level security, and access that holds when the data multiplies.
- +Self-serve ingestion framework
- +Dataplex governance, cataloguing, and policy tag taxonomy
- +Sensitive Data Protection (Cloud DLP): classification, de-identification, redaction
- +Scheduled DLP inspection jobs with findings routed to Security Command Center
- + 4 more in scope
- −source system integration beyond agreed connectors
- −BI and dashboard development
- −data migration from legacy warehouses
package/gcp-cost-optimization
A savings model with a prioritized implementation plan: commitment modelling, sole-tenant BYOL analysis, bin-packing, and the egress patterns nobody has looked at.
- +Committed and sustained use discount modelling
- +Sole-tenant BYOL licensing analysis
- +Idle and overprovisioned capacity
- +GKE bin-packing
- + 2 more in scope
- −implementation of recommendations
- −contract negotiation with Google
- −non-GCP spend
Floors reflect typical engagements. Larger, regulated, or multi-region estates are scoped and quoted after Discovery.
Full detail on every engagement — what gets built, how
the weeks run, and where each one stops.