About
I'm Erik. I build platforms that have to be explained to a regulator.
Twenty years in cloud infrastructure, the last several of them as an independent architect working almost entirely inside financial services and other regulated enterprises. Ascode is the practice I work through; the person you hire is me.
What I actually do
I sit in two places most people only sit in one of.
At the architecture review board, I write key design decisions, solution architecture designs, argue them, and produce the control mappings like PCI DSS, SOX, DORA and NIS2, that let a platform be approved rather than tolerated. ISO/IEC 42001 is the newest addition to that list and the one the AI work is heading towards. Then I go and build the thing: Terraform, Entra ID, AKS, GitLab pipelines, the actual implementation of the design, exactly as intended.
That combination is the whole point. Governance work done by someone who has never deployed the control produces documents that describe an architecture nobody built. Implementation done without the governance conversation produces platforms that get blocked six months in. Keeping both in one head is slower to hire for and much faster to finish.
Where I'm strongest
- Azure, deeply Entra ID and identity architecture above all, plus AKS, networking and the governance layer around them. AWS and GCP when a client's estate needs it.
- AI platform work API gateways in front of model endpoints, quotas and chargeback, the isolation and logging that make a generative feature defensible.
- Zero Trust and access control Conditional Access at scale, Global Secure Access, PKI, workload identity, removing standing secrets.
- Infrastructure and compliance as code Terraform and OpenTofu, GitOps with ArgoCD and Helm, policy-as-code, CI/CD that fails a merge request rather than a quarterly audit.
How I work
One client at a time, mostly. I take a small number of engagements so that I am actually available when something breaks at 16:00 on a Friday.
Opinions, with the alternatives. There is no single right way to build a cloud platform. I will bring you the options, and then tell you which one I would pick and why. You are paying for the second half.
Nothing I build is a black box. The code lives in your repositories, in your pipeline, documented in language your own team can maintain. If the engagement ends and you cannot carry on without me, I did it wrong.
Dutch and English, and comfortable in both a board room and a terminal often in the same afternoon.
Outside the day job
A four-node Raspberry Pi 5 Kubernetes cluster in the home lab that I keep migrating between distributions for no defensible reason, a long-running interest in running LLMs locally, and rather more time than is reasonable spent on infrastructure automation for things that did not need automating. BBQ for fun and flavour, and the occasional video game.
Most of what I learn from that ends up in the writing.
Let's talk
Thirty minutes, no deck. Tell me what you're building and where the pressure is coming from.