WZ-IT audits, stabilizes and operates Kubernetes platforms with a clearly defined scope. Monitoring, updates, CVEs, backup and incident response become one coherent lifecycle.
Kubernetes services
From target architecture through infrastructure and delivery to ongoing operations. Each page explores one part of the same accountable platform.
A running cluster can contain unknown dependencies, outdated components and untested recovery paths. Before assuming operations, we create visibility and prioritize the required stabilization work.
Capture distribution, versions, nodes, add-ons, workloads, access, dependencies and provider responsibility.
Review monitoring, logging, alerting and capacity before defining response commitments.
Assess etcd, persistent data, configuration and application backups, including the restore path.
Control plane, nodes, platform add-ons, workloads, databases and application receive clear owners.
The transition follows a documented process with an accepted state and agreed scope.
Capture access, inventory, architecture, providers and existing processes.
Prioritize critical versions, single points, security and recovery gaps.
Bring monitoring, backups, updates, access and documentation to a minimum standard.
Agree scope, maintenance windows, response, escalation and responsibilities.
Monitor, maintain, respond, report and evolve the platform with control.
The exact scope is agreed for each platform. These capabilities provide the framework for reliable operations.
Monitor control plane, nodes, core components, capacity and agreed workloads with actionable alerts.
Test and update Kubernetes versions, operating systems and platform add-ons in a planned way.
Classify vulnerabilities, assess exposure and coordinate measures based on risk.
Monitor backup jobs, handle failures and test recovery at agreed intervals.
Qualify alerts, isolate causes, apply runbooks and manage escalations transparently.
Review resources, costs, technical debt and recurring problems regularly.
In addition to the cluster, applications need defined processes for delivery, access, observability, recovery and technical ownership.
GitOps, CI/CD, separate environments, approvals and reproducible rollbacks.
CNI, network policies, ingress or gateway, DNS, TLS and private access.
OIDC, RBAC, secrets, image validation, policies and traceable changes.
Metrics, logs, traces, alerting and SLOs for platform and applications.
Cluster state, persistent data, restore tests and a documented recovery path.
Updates, CVE assessment, capacity, costs and an agreed operating model.
The agreed scope can range from cluster support to operating selected applications. Infrastructure, Kubernetes platform, add-ons, data and workloads are listed as separate responsibility layers.
WZ-IT builds or stabilizes the platform, documents it and hands it over to your operations team.
For teams with their own Kubernetes responsibility
Responsibility is divided by layer, for example WZ-IT for cluster and platform while your team owns applications.
For teams building responsibility incrementally
WZ-IT continuously owns the agreed platform scope; applications and business approvals remain clearly separated.
For companies without their own platform team
Knowledge base
Agree operating services separately
Monitoring, alert handling, response times, support windows, on-call service and recovery objectives are separate service components. The agreed scope is recorded in the operating model and service level.
Move to the part of the platform that matters most for your current initiative.
Clear answers on architecture, delivery, responsibilities and ongoing operations.
A takeover always starts with discovery and an audit. Severely outdated, undocumented or unstable environments need a stabilization phase first. We then decide which operating scope can be responsibly assumed.
Typical capabilities include monitoring, updates, CVE assessment, backup control, restore tests, incident response and capacity reviews. The concrete scope and responsibility for workloads and databases are defined contractually.
Continuous monitoring and support or response times are separate services. Available service levels and support windows are agreed according to criticality; 24/7 on-call support is not automatically promised with every operations package.
Yes, existing managed Kubernetes platforms can be taken over. The cloud provider remains responsible for its service components while WZ-IT handles the agreed cluster, add-on and workload scope.
That depends on the agreed model. Platform and application operations are described separately. Because WZ-IT also provides software development, we can assume additional application responsibility if desired, but it is never implied.
That depends on access, documentation, versions, criticality and known problems. Initial scoping is followed by an audit that defines effort, stabilization work and a realistic transition plan.
Tell us the distribution, infrastructure and current problems. We will propose the right entry point for audit and stabilization.
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.
Timo Wevelsiep & Robin Zins
Managing Directors of WZ-IT
