Segfault Labs

We build, automate and watch over the infrastructure your product runs on.

We are brave.

Someone has to go first. Into the pipeline nobody has dared to touch since the person who wrote it left. Into the cloud account with no owner and a bill nobody can explain. Into the Terraform state that drifted away from reality two years ago.

That is the part we take. We do not rewrite everything - we find out what is actually running, put it under version control, and hand it back in a shape the next person can read.

What we run

Platform & delivery

GitLab CI as the backbone, AWS as the target, Terraform and OpenTofu as the only way anything gets created.

Zero trust access

HashiCorp Vault for secrets and short-lived credentials, NetBird for private network access without a VPN concentrator to babysit.

Observability

The Grafana stack - dashboards, logs, metrics and alerts that page a human only when a human is needed.

Google Cloud, Azure, GitHub Actions and Ansible show up in our work too - see services for the full picture.

Open source

Things we needed, could not find, and gave away afterwards.

renovate-gitlab-exporter

Prometheus exporter that turns Renovate dependency updates across GitLab into metrics you can alert on. Go.

terraform-helm-grafana-agent

Grafana Agent rolled out through Helm, wrapped as a Terraform module so it lands in the same plan as everything else.

terraform-aws-serverless-image-handler

The AWS serverless image handler as a plain Terraform module, without the CloudFormation detour.

ansible-role-openvpn

Ansible role for OpenVPN servers, for the places that are not on NetBird yet.

terraform-google-machine

Terraform module for a simple virtual machine on Google Cloud Platform.

terraform-google-dns-zone

Terraform module to manage a DNS zone on Google Cloud Platform.

More on GitHub and GitLab.

Let's talk

Tell us what is on fire, or what you would rather never catch fire in the first place.

info@segfault-labs.dev
+420 602 807 773

Company details on the contact page.