Bringing a live, customer-facing Azure environment under full Terraform management, GitOps change control, and modern identity governance, with zero downtime.
Zero
Downtime during migration
100%
Estate under Terraform management
2
Regions in the DR topology
GitOps
Every change via pull request
Salfati Group is a Zug, Switzerland-headquartered software delivery firm, founded by Elon Salfati, that rebuilds client companies' operations to run on AI agents and ships the result as a fixed-price, client-owned outcome.
The firm positions itself against traditional SaaS and hourly consultancy models: a single scoped outcome at a fixed price, with a senior architect accountable for delivery while AI agents, powered by its internal engine Cambrian, do the underlying build work. It maintains a US presence in Delaware alongside its Swiss headquarters.
Shipping software outcomes directly to clients means Salfati Group's own Azure-hosted infrastructure, supporting both an internal tool and an external customer portal, has to meet a bar for reliability, security, and governance that matches the trust commitments embedded in its business proposition.
As reported by the firm.
Against a fixed-price, fixed-scope model.
Time from engagement start to first shipped increment.
Salfati Group's Azure environment had grown without consistent infrastructure-as-code discipline. Resources across networking, compute, serverless, and data tiers were only partially documented and inconsistently tagged across production, staging, and dev/test.
No single source of truth for what was running where
Unclear separation of production and non-production workloads
Gaps in FCC-aligned logging and monitoring
No codified disaster recovery path
Because the environment served a live, external customer portal alongside an internal tool, remediation had to happen without downtime or customer-facing disruption. That ruled out rip-and-replace in favor of an incremental, validated migration to infrastructure as code.
Rivia was engaged as the delivery agency, executing the work as a coordinated program rather than a single migration event.
Enumerated every Azure resource, including VNets, NSGs, firewalls, storage accounts, compute, serverless, and databases, then classified each as production, staging, dev/test, or unknown. Produced a CMDB-style inventory plus current-state architecture and data-flow diagrams capturing customer-facing and regulatory touchpoints.
Rather than recreating infrastructure, an import-first approach mapped live resources into Terraform state with a remote backend and state locking, validating each import through drift detection before applying changes. Create-before-destroy, blue/green rollouts at the application gateway layer, and rolling scale-set upgrades kept the portal and internal tool running throughout. Reusable modules were built for networking, compute, serverless, data, and monitoring, parameterized across environments.
A Terraform CI/CD pipeline with plan-on-pull-request and apply-on-approved-merge, environment-scoped approvals requiring elevated sign-off for production, and automated guardrails including tflint validation and Azure Policy enforcement of tags, SKUs, and security baselines.
A secondary-region DR topology with pre-provisioned staff VM images and Terraform-driven, on-demand deployment of DR stacks, a tested path to keep employees working through a regional outage, backed by documented RPO/RTO targets and activation runbooks.
SQL Server and database configurations were audited and remediated for encryption at rest and in transit, private endpoint exposure, Entra ID-based authentication, backup and point-in-time recovery, and audit logging routed to Log Analytics.
Migrated on-premises Active Directory to Microsoft Entra ID via staged Entra Connect/Cloud Sync, remapped legacy groups to Entra roles, enforced MFA and device compliance through Conditional Access, implemented Privileged Identity Management for admin roles, and applied least-privilege RBAC scoped to Azure resources.
A management group hierarchy and baseline Azure Policy set enforcing allowed regions, mandatory tagging, and diagnostic settings, paired with a standardized tag taxonomy covering environment, application, owner, and data classification. The existing Grafana deployment was assessed against Azure native alternatives, with logging and alerting consolidated across platform, metric, and security signals into Log Analytics.
A ring-based patch rollout across dev, test, and prod through Azure Update Manager, codified in Terraform where possible. The engagement closed with full runbook documentation, architecture and governance references, and knowledge transfer sessions handing operational ownership back to Salfati Group's internal teams.
The engagement moved Salfati Group from an ad hoc, partially documented Azure estate to a fully codified, Git-governed infrastructure with clear production and non-production separation, FCC-aligned security and logging controls, and a tested disaster recovery capability, all without disruption to the live customer portal.
The internal team was left with a self-service, auditable change model. Any future infrastructure change now flows through a pull request, automated policy checks, and an approval gate rather than manual console changes, closing the governance and drift risks that existed at the start of the engagement.
| Engagement Dimension | Detail |
|---|---|
| Client | Salfati Group, an AI-agent software delivery firm based in Zug, Switzerland |
| Cloud platform | Microsoft Azure, hosting an internal tool and an external customer portal |
| Engagement type | Delivery agency: infrastructure as code, GitOps, identity & governance |
| Core technologies | Terraform, Azure Policy, Microsoft Entra ID, Log Analytics, Azure Update Manager |
| Constraint | Zero downtime, live customer portal throughout |
| Outcome | Fully Terraform-managed estate, GitOps change control, tested multi-region DR, operational handover |
Rivia brings live environments under infrastructure as code without taking them down, covering inventory, codification, GitOps guardrails, and a tested disaster recovery path.