Client Success Story

Salfati Group: An Azure Estate, Rebuilt as Code

Bringing a live, customer-facing Azure environment under full Terraform management, GitOps change control, and modern identity governance, with zero downtime.

Zero

Downtime during migration

100%

Estate under Terraform management

2

Regions in the DR topology

GitOps

Every change via pull request

Client Overview

Salfati Group is a Zug, Switzerland-headquartered software delivery firm, founded by Elon Salfati, that rebuilds client companies' operations to run on AI agents and ships the result as a fixed-price, client-owned outcome.

The firm positions itself against traditional SaaS and hourly consultancy models: a single scoped outcome at a fixed price, with a senior architect accountable for delivery while AI agents, powered by its internal engine Cambrian, do the underlying build work. It maintains a US presence in Delaware alongside its Swiss headquarters.

Shipping software outcomes directly to clients means Salfati Group's own Azure-hosted infrastructure, supporting both an internal tool and an external customer portal, has to meet a bar for reliability, security, and governance that matches the trust commitments embedded in its business proposition.

Delivery Track Record

68 mandates delivered

As reported by the firm.

98% on-time acceptance

Against a fixed-price, fixed-scope model.

14-day median first delivery

Time from engagement start to first shipped increment.

The Challenge

Salfati Group's Azure environment had grown without consistent infrastructure-as-code discipline. Resources across networking, compute, serverless, and data tiers were only partially documented and inconsistently tagged across production, staging, and dev/test.

No single source of truth for what was running where

Unclear separation of production and non-production workloads

Gaps in FCC-aligned logging and monitoring

No codified disaster recovery path

Because the environment served a live, external customer portal alongside an internal tool, remediation had to happen without downtime or customer-facing disruption. That ruled out rip-and-replace in favor of an incremental, validated migration to infrastructure as code.

Solution Delivered

Rivia was engaged as the delivery agency, executing the work as a coordinated program rather than a single migration event.

1

Discovery & Inventory

Enumerated every Azure resource, including VNets, NSGs, firewalls, storage accounts, compute, serverless, and databases, then classified each as production, staging, dev/test, or unknown. Produced a CMDB-style inventory plus current-state architecture and data-flow diagrams capturing customer-facing and regulatory touchpoints.

2

Zero-Downtime Terraform Codification

Rather than recreating infrastructure, an import-first approach mapped live resources into Terraform state with a remote backend and state locking, validating each import through drift detection before applying changes. Create-before-destroy, blue/green rollouts at the application gateway layer, and rolling scale-set upgrades kept the portal and internal tool running throughout. Reusable modules were built for networking, compute, serverless, data, and monitoring, parameterized across environments.

3

GitOps & Pipeline Governance

A Terraform CI/CD pipeline with plan-on-pull-request and apply-on-approved-merge, environment-scoped approvals requiring elevated sign-off for production, and automated guardrails including tflint validation and Azure Policy enforcement of tags, SKUs, and security baselines.

4

Disaster Recovery

A secondary-region DR topology with pre-provisioned staff VM images and Terraform-driven, on-demand deployment of DR stacks, a tested path to keep employees working through a regional outage, backed by documented RPO/RTO targets and activation runbooks.

5

Data Layer Hardening

SQL Server and database configurations were audited and remediated for encryption at rest and in transit, private endpoint exposure, Entra ID-based authentication, backup and point-in-time recovery, and audit logging routed to Log Analytics.

6

Identity Modernization

Migrated on-premises Active Directory to Microsoft Entra ID via staged Entra Connect/Cloud Sync, remapped legacy groups to Entra roles, enforced MFA and device compliance through Conditional Access, implemented Privileged Identity Management for admin roles, and applied least-privilege RBAC scoped to Azure resources.

7

Governance & Observability

A management group hierarchy and baseline Azure Policy set enforcing allowed regions, mandatory tagging, and diagnostic settings, paired with a standardized tag taxonomy covering environment, application, owner, and data classification. The existing Grafana deployment was assessed against Azure native alternatives, with logging and alerting consolidated across platform, metric, and security signals into Log Analytics.

8

Patching & Handover

A ring-based patch rollout across dev, test, and prod through Azure Update Manager, codified in Terraform where possible. The engagement closed with full runbook documentation, architecture and governance references, and knowledge transfer sessions handing operational ownership back to Salfati Group's internal teams.

The Outcome

Fully codified, Git-governed Azure estate, delivered without downtime

The engagement moved Salfati Group from an ad hoc, partially documented Azure estate to a fully codified, Git-governed infrastructure with clear production and non-production separation, FCC-aligned security and logging controls, and a tested disaster recovery capability, all without disruption to the live customer portal.

The internal team was left with a self-service, auditable change model. Any future infrastructure change now flows through a pull request, automated policy checks, and an approval gate rather than manual console changes, closing the governance and drift risks that existed at the start of the engagement.

Key Takeaways

Engagement Dimension Detail
Client Salfati Group, an AI-agent software delivery firm based in Zug, Switzerland
Cloud platform Microsoft Azure, hosting an internal tool and an external customer portal
Engagement type Delivery agency: infrastructure as code, GitOps, identity & governance
Core technologies Terraform, Azure Policy, Microsoft Entra ID, Log Analytics, Azure Update Manager
Constraint Zero downtime, live customer portal throughout
Outcome Fully Terraform-managed estate, GitOps change control, tested multi-region DR, operational handover

Cloud estate grown past its documentation?

Rivia brings live environments under infrastructure as code without taking them down, covering inventory, codification, GitOps guardrails, and a tested disaster recovery path.