Closed Circuit Consultants · Las Vegas, NV · remote US
Cloud exit to Hetzner and Cloudflare, without an outage.
For teams paying hyperscaler prices for workloads that run fine on a handful of servers. We move you to Hetzner behind Cloudflare, all of it in Pulumi or Terraform, with a parallel run and a rollback plan. Your customers should not notice the move.
Free 30-minute call. Written findings in 48 hours that you keep. Then a scoped SOW.
How it starts
Call → 48h cost and move map → scoped migration
- 1. Free 30-minute call. Accounts, regions, the bill, and which managed services you lean on.
- 2. 48-hour findings you keep. What runs where, what it costs, and for each piece: move, replace, or keep. With the monthly cost on the other side.
- 3. Scoped migration. Fixed price for the move, or from $2,500/month if you want us operating it after.
What moves where
Compute and networks
Hetzner servers, private networks, firewalls, and load balancing, defined in code.
DNS, CDN, and WAF
Cloudflare in front: DNS, TLS, caching, and bot and abuse protection, with zones managed as code.
Object storage
S3 buckets moved to Cloudflare R2, which speaks the S3 API, so most application code does not change.
Databases
PostgreSQL or MySQL with backups we restore before cutover, not after.
Secrets and CI/CD
Secrets, deploy pipelines, and infrastructure state moved with everything else, so nothing still points at the old account.
Shutdown
The old account emptied and closed after you sign off, so the bill actually stops.
Proof
Who has done this
Full estate to Hetzner, no outage
Moved a full production estate to Hetzner on Pulumi: servers, private networking, firewalls, DNS, secrets, and CI/CD, with no customer-visible outage. Run cost for those workloads came to about $18 a month.
Cloudflare as code
Cloudflare zones for several companies run as Pulumi projects, one per Cloudflare account, with state kept in Cloudflare R2. A DNS change is a reviewed diff, not a dashboard click.
80 servers to 11
As CTO at Parlement, Sean O'Dea rebuilt a 16-million-user platform into a functional API on bare-metal Kubernetes and took production from 80 servers to 11.
$2M to $3M a year
At a multi-million-user social platform, right-sizing environments and a prepaid-spend strategy saved $2M to $3M a year.
Questions
Is Hetzner reliable enough for production?
For many workloads, yes, if you design for a server failing: infrastructure as code that can rebuild a box, backups you have restored, and Cloudflare in front. Hetzner Cloud has US locations in Ashburn, Virginia and Hillsboro, Oregon, plus Europe.
Do we have to leave AWS completely?
No. Some teams move compute and storage and keep one managed service they depend on. The findings price each piece: move, replace, or keep.
Pulumi or Terraform?
Both. We use Pulumi in TypeScript day to day, and OpenTofu or Terraform where your team already has it. Either way, every server, network, firewall, and DNS record is code in your repo.
How do you avoid an outage?
The new stack runs in parallel first. Data is replicated, DNS TTLs are lowered ahead of time, cutover happens in a window you pick, and the old stack stays up as a rollback path until you sign off.
What if moving is not worth it?
Then the findings say so. Deep use of managed services can make an exit cost more than it saves. Sometimes the right answer is cutting the AWS bill in place, which is our AWS cost consulting work.
Pay for the servers you use.
Book the free call. Bring last month's cloud bill.
Closed Circuit Consultants · SOC LLC d/b/a · Las Vegas, NV · remote across the US