Critical infrastructure, handled.
Mesa Ops Partners stabilizes and modernizes network and container infrastructure for regulated businesses: fewer outages, cleaner audits, lower infrastructure spend. Fixed-scope engagements led by a senior principal. You buy outcomes, not hours.
Book a fit call See engagementsThe problem
Aging infrastructure is a business risk, not an IT detail
Unmaintained software is sitting at the edge of most production Kubernetes clusters: ingress-nginx is retired, and no longer receives feature development or guaranteed security fixes. For a regulated business, that isn't a backlog item. It's an outage waiting to happen and an audit finding waiting to be written.
Meanwhile, the bar keeps rising. mTLS requirements, segmentation expectations, and observability gaps are no longer nice-to-haves. They're what examiners, customers, and boards expect your infrastructure to prove.
None of this is unsolvable. It's just rarely anyone's day job. It happens to be ours.
Engagements
Three engagements. Fixed scope. Defined outcomes.
Infrastructure Reliability & Compliance Assessment
We map your network and container infrastructure end to end: controllers, meshes, firewalls, segmentation, traffic patterns. Then we hand you a findings report ranked by risk and cost, with a sequenced remediation roadmap. Written so your engineers, your board, and your examiners can all read it. A lot of what we find is usually fine. The point is knowing exactly what isn't, what it's costing you, and what to fix first.
Modernization Sprint
A defined modernization project with written acceptance criteria: an Ingress-to-Gateway-API migration, a service mesh rollout, a network segmentation buildout. We run the old and new stacks in parallel and cut over in small, reversible steps. No big-bang switchover, no weekend heroics. Done means the acceptance criteria are met, in writing.
Fractional Platform Leadership
Ongoing senior ownership of platform and network reliability, for teams that need the accountability of a head of platform without the executive hire. Defined scope bands and defined response times, not an open-ended block of hours. We review designs, lead incident retrospectives, plan upgrades, and keep your infrastructure exam-ready.
Under the hood: Ingress and Gateway API migrations, Istio/Linkerd/Cilium service mesh design and operations, Kubernetes networking architecture review, firewall and segmentation design.
Full technical detail
Ingress to Gateway API migration
We move you off ingress-nginx, or whatever legacy controller you're running, and onto the Gateway API. First we inventory your Ingress resources and annotations, then we pick a Gateway implementation that fits your platform, then we cut traffic over piece by piece with both stacks running in parallel. No big-bang switchover, no weekend heroics.
Service mesh adoption & operations
Thinking about Istio, Linkerd, or Cilium? We'll help you figure out whether you actually need a mesh before you commit to running one. If the answer is yes, we design the rollout with you: mTLS, traffic policy, upgrade strategy, and the observability you'll need to operate it without guessing.
Kubernetes networking advisory
Sometimes you just want experienced eyes on a design before you commit to it. We review north-south and east-west architecture: load balancing, multi-cluster connectivity, DNS, network policy, and traffic management. You get honest feedback and specific recommendations, in writing.
How we work
Fixed scope. No open-ended hourly work.
Assess
Every engagement starts with the Assessment. We map what you actually have: controllers, meshes, firewalls, annotations, traffic patterns. A lot of it is usually fine. The point is figuring out what really needs to change.
Plan
You get a written plan with clear phases, rollback points, and honest effort estimates. Your team reviews it and pokes holes in it before anything moves.
Migrate & enable
We do the work with your engineers, pairing through the cutover. When we leave, your team knows how to run the new stack because they helped build it.
Why Mesa Ops Partners
Practitioners, not a bench
Independent
We don't resell anything, and nobody pays us a kickback. If Envoy Gateway fits you better than Istio, we'll say so. If the boring option is the right one, we'll say that too.
Production-grounded
We've run Kubernetes networking in production. Our advice comes from upgrades that broke traffic at 2 a.m., not from conference talks.
Enablement-first
The goal is your team running the stack without us. Every engagement ends with runbooks, documented decisions, and engineers who understand why things are set up the way they are.
Narrow on purpose
We do critical infrastructure for regulated environments: the networks, clusters, and firewalls your business runs on and your examiners ask about. That's it. We'd rather be great at one thing than okay at ten.
Who we are
Who you're working with
Kacey Gambill has spent eight years running production Kubernetes in healthcare and fintech, where downtime is expensive and infrastructure gets audited. More than fifty clusters, twenty-plus nodes each. The work centers on Kubernetes networking: ingress and Gateway API, service mesh operations, and the firewall and segmentation design that regulated infrastructure demands. Recent work includes root-causing months of intermittent DNS timeouts across a production EKS fleet from existing telemetry alone, without touching a live node. The cause was a kernel-level packet race every dashboard missed. Mesa Ops Partners is that work, at fixed scope, for businesses that need it done well more often than they need someone full-time.
Every recommendation is tested first in our production-replica lab, before it goes anywhere near your infrastructure. The lab runs enterprise firewalls and a multi-node Kubernetes cluster mirroring the environments our clients run.
Currently engaged: infrastructure consulting for a regulated healthcare platform.
A senior principal leads every engagement. No bench of juniors, no handoffs.
FAQ
Common questions
How do engagements work?
Fixed scope, three steps. Every engagement starts with the Assessment. It scopes and prices everything that follows, so if we recommend a Modernization Sprint, the proposal comes straight from the assessment findings. Ongoing work runs on defined scope bands and response times with quarterly renewal. We don't sell open-ended blocks of hours.
What does it cost?
Assessments start at $20,000, fixed price. Modernization Sprints typically run $50,000–$150,000, priced by the assessment. Fractional Platform Leadership starts at $15,000 per month. We publish these numbers because surprises belong in outages, not invoices.
Are we a fit?
Probably not, if you're looking for staff augmentation, hourly contractors, or a body for a ticket queue. Probably yes, if you're accountable to a regulator, customer, or board for infrastructure that has to hold up, and you want it fixed with a defined scope and a defined outcome.
How long does an Ingress to Gateway API migration take?
Most single-cluster migrations take two to six weeks. The big variables are how many Ingress resources you have and how much controller-specific annotation logic they carry. We run the old and new stacks side by side, so the cutover happens in small, reversible steps rather than one scary weekend.
Why do I need to migrate off ingress-nginx?
The project is retired, so it no longer gets feature development or guaranteed security fixes. An unmaintained proxy at the edge of your cluster is a risk that only grows. The supported path forward in the Kubernetes community is the Gateway API with an actively maintained implementation.
Do I actually need a service mesh?
Honestly, often no, and we'll tell you if that's the case. A mesh earns its complexity when you need mTLS between services, fine-grained traffic policy, or consistent L7 observability across a lot of teams. If your needs are narrower than that, simpler options usually win, and part of our job is helping you make that call.
Which Gateway API implementation should I choose?
It depends on your platform. Teams that lean on cloud load balancers often use their provider's implementation. Teams that want portability tend to look at Envoy Gateway, Cilium, or Istio's gateway. We don't have a horse in that race, so the recommendation comes from your traffic, your tooling, and your team's capacity.
Contact
Tell us where things stand
Bring us the infrastructure you're worried about. We'll show up to the first call with questions, not a pitch deck.
Book a fit call kacey@mesaopspartners.com