Platform & infrastructure work

Boring infrastructure
& AI that actually ships.

I'm Mat Strommen, an independent platform and AI engineer. I put AI agents into your dev workflow without the chaos, cut what you're overpaying for cloud, and leave behind infrastructure your team can still read six months from now.

20–30% cloud spend cut 60–70% faster CI +50% team velocity with AI

AI agents · LLMOps · evalsFinOps · AWS · Azurek8s/k3s · Terraform · GitOps

Get in touch AI & software consulting instead?

01 / What this covers
01.1

AI agents in your dev workflow

Claude and GPT agents wired into CI and code review without the YouTube-tutorial energy. Scoped autonomy, regex guardrails before LLM judgment, eval harnesses, and trace coverage so cost and drift don't surprise you. Up to +50% team velocity, no new headcount.

01.2

Cloud cost & AI spend control

FinOps that pays for the rest of the work. Right-sizing, savings plans, ephemeral CI workers, and LLM spend controls baked into the platform so cost discipline is enforced, not hoped for. Typically 20–30% off the monthly cloud bill.

01.3

Platform engineering

k8s/k3s and EKS clusters, Terraform that converges, GitOps delivery, and pipelines that finish in minutes, deterministic guardrails, no allow_failure: true hiding broken tests. The foundation the AI layer runs on. HIPAA/NIST-ready when the vertical needs it.

IaC repo → CI gate → cluster: audited and reversible iac repo terraform · ansible ci gate regex · tests · lint cluster k8s/k3s · flux · agent agent loop audited · reversible me

IaC repo Everything that touches production is committed first. Terraform plans, Ansible roles, Kustomize overlays. If it's not in this repo, it doesn't ship.

CI gate Deterministic checks before anything else. Regex catches DROP TABLE, manifest validation catches typos, tests run on MRs not after merge.

Cluster Manifests applied by a GitOps controller. State is reproducible from this branch, no clickops, no out-of-band changes.

Agent loop LLM agents climb an autonomy ladder: read-only → draft MRs → fix-on-command → auto-merge. Demoted on the first incident. Every step traced.

Me, briefly I set this up so it keeps working without me. Every engagement ends with a runbook, a diagram, and a person on your team who can keep going.

02 / The stack

AI orchestration & agents

  • Claude · GPT · Llama
  • LiteLLM · LangChain
  • Agent SDKs · MCP
  • Eval harnesses
  • Ollama · Bedrock

FinOps & cloud cost

  • AWS · Azure cost modeling
  • Savings plans · right-sizing
  • LLM spend controls
  • Ephemeral CI workers
  • Cost & drift monitors

Platform engineering

  • k8s/k3s · EKS · AKS
  • Terraform · Terragrunt
  • Ansible · GitOps
  • Helm · Docker
  • GitHub Actions · self-hosted CI

Security & compliance

  • HIPAA/HITECH · NIST
  • TLS · secrets management
  • nuclei · trivy
  • Audited agent autonomy
  • Authentik SSO

Observability

  • Prometheus · Grafana · Loki
  • OpenTelemetry
  • GitOps drift detection
  • Langfuse · LLM tracing
  • Alerting that pages on signal

Languages & APIs

  • Python · FastAPI
  • Bash · PowerShell
  • Node.js · React
  • C#/.NET
  • Next.js

Looking for the AI-replaces-SaaS pitch instead? Back to consulting.