waveagency: infrastructure rebuilt for scale
waveagency needed infrastructure that could grow with its clients. Merilsoft's cloud practice delivered scalability, security, and efficiency beyond expectations.
- New client environment setup
- About a week down to same-day, templated
- Security patching
- Reactive bursts replaced with automatic baseline + monitoring
- Cost visibility
- Usage-based tracking instead of end-of-month surprises
waveagency's infrastructure had grown one client engagement at a time — a server spun up here, a firewall rule added there, patched whenever someone remembered. That's normal for an agency scaling on client wins instead of a five-year infrastructure plan, but it meant every new engagement inherited the mess of the last one, onboarding took most of a week of manual provisioning, and cost only showed up after the invoice landed.
Over a ten-week engagement, Merilsoft audited the full estate, designed a templated cloud architecture, and migrated it in staged phases validated against non-critical environments first. New client environments now stand up same-day instead of over a week, security baselines apply automatically on a fixed schedule instead of in reactive bursts, and cost tracking runs usage-based with a per-client breakdown Keith's team can actually price against.
Client overview
waveagency is a digital agency whose infrastructure footprint grows with every new client win — each engagement historically brought its own server, its own configuration, and its own set of credentials that only the ops team could reliably reconstruct. The ops team's job had quietly become split between supporting live client work and firefighting the accumulated mess of every engagement that came before it.
Keith Tucci, waveagency's CEO, had been living with cost overruns that only surfaced when the invoice landed, with no per-client breakdown to explain why a given month ran high — a hard position for an agency trying to price its next engagement with any confidence.
The challenge
Infrastructure that inherited the last client's mess
waveagency's infrastructure had grown one client at a time — a server spun up here, a firewall rule added there, patched whenever someone remembered. That's normal for an agency scaling on client wins instead of a five-year infrastructure plan, but it meant every new engagement inherited the mess of the last one instead of starting clean.
A week of manual provisioning, per client
Onboarding a new client meant the ops team spending the better part of a week provisioning servers by hand, chasing down credentials, and re-deriving whatever configuration had worked for the last similar project. Security updates happened in reactive bursts — pushed after someone noticed an advisory, not on a schedule — which left windows where an unpatched service sat exposed longer than anyone was comfortable with.
Cost that only showed up on the invoice
Cost was the same story after the fact instead of before it. Keith's team found out about overruns when the invoice landed, with no per-client breakdown to explain why one month ran high — which made it hard to price new engagements with any confidence.
Project objectives
- Replace hand-provisioned, one-off server setups with templated environments any engagement can start from.
- Move security patching from reactive bursts to an automatic, scheduled baseline across every environment.
- Give leadership a per-client, usage-based cost breakdown instead of a surprise at month's end.
- Migrate without breaking anything mid-contract for clients already live on the old infrastructure.
Discovery & business analysis
Discovery opened the engagement and ran to completion before any migration design work started. Merilsoft worked through the estate alongside the ops team rather than asking them to produce documentation that didn't exist — going server by server, cataloguing every server, every credential, and every dependency, including the ones nobody had written down. The ordinary parts of the job mattered as much as the exceptions, because that was where the week went: configuration re-derived from the last similar project, credentials chased down by hand, a setup only the ops team could reliably reconstruct. The commercial picture was just as thin — a blended invoice with no per-client breakdown, which left Keith's team pricing the next engagement on guesswork.
The analysis surfaced one finding above the rest: waveagency's real infrastructure documentation lived in the ops team's heads, and parts of it had already left with staff who were no longer there. Several services that client-facing tools quietly depended on had been set up by nobody currently on the team — inherited from people who'd since gone. That finding is what turned the audit from a checklist into a gate: every dependency of unclear origin was flagged for a manual sign-off from Keith's team before anything touched it. It added time to the audit phase. It was also the reason the migration never silently broke something nobody remembered existed.
Discovery set the migration's sequence too. It established which clients were mid-engagement on the old infrastructure with no tolerance for downtime — which is why every phase was later proven on a non-critical environment first, and why live moves were scheduled in each client's own lowest-traffic window instead of a single company-wide maintenance night. The same phase showed that per-client cost attribution couldn't be bolted onto the old estate, because there was nothing consistent underneath to attribute cost against. That's why cost tagging and usage-based reporting were sequenced last, going live in the final two weeks once the templated environments beneath them were stable enough to produce numbers Keith's team could trust.
Solution architecture
An estate-wide audit before a single server moved
Merilsoft audited the existing estate end to end — every server, credential, and undocumented dependency — then designed a target cloud architecture built around templated environments instead of one-off setups. Migration ran in staged phases over about ten weeks, each phase validated in isolation on a non-critical environment before it touched a live client engagement, so nothing broke mid-contract for anyone already on the books.
Same-day environments, scheduled security baselines
The rebuild replaced hand provisioning with templated, same-day environment setup for new clients, and reactive patching with security baselines that apply automatically across every environment on a fixed schedule. Continuous monitoring now flags anomalies — a spike in traffic, an unexpected resource spin-up — while they're happening, not when they show up on a bill.
Cost visibility that prices the next engagement
Cost tracking moved to a usage-based model with a per-client breakdown, so pricing a new engagement is a lookup instead of a guess. The ops team's time shifted from firefighting old setups to supporting new client work, which is what waveagency actually bills for.
Technology stack
| Component | Technology | Why |
|---|---|---|
| Infrastructure as code | Terraform | Templated, repeatable environments instead of hand-built servers per client |
| Compute | AWS EC2 + Auto Scaling | Matches capacity to each client's workload without manual resizing |
| Patch & config baseline | Ansible | Applies the same security baseline automatically across every environment, on schedule |
| Monitoring & alerting | Datadog | Flags traffic spikes and unexpected resource spin-up while they're happening |
| Cost tracking | AWS Cost Explorer + tagging | Usage-based, per-client cost breakdown instead of one blended invoice |
| Secrets management | HashiCorp Vault | Replaces ad hoc credential sharing with a single source of truth |
| CI/CD | GitHub Actions | A new environment stands itself up from a pipeline, not a checklist |
Key features
Templated environment provisioning
Before
Onboarding a new client took most of a week of manual server setup
Now
New environments deploy from a Terraform template in hours
Week-long provisioning cut to same-day
Scheduled security baselines
Before
Patches went out in reactive bursts after someone noticed an advisory
Now
Baselines apply automatically across every environment on a fixed schedule
No more exposure windows waiting on someone to notice
Anomaly monitoring
Before
Cost and traffic spikes only surfaced when the invoice landed
Now
Continuous monitoring flags anomalies as they happen
Issues caught in real time instead of at month's end
Per-client cost tagging
Before
No way to explain why a given month ran high, client by client
Now
Usage-based cost tracking broken down per client
Pricing a new engagement is now a lookup, not a guess
Rollout & delivery
The engagement opened with an estate-wide discovery and audit phase — every server, credential, and undocumented dependency catalogued before any migration design work started, since the ops team's informal knowledge of "what actually runs where" turned out to be the single biggest migration risk.
Migration itself ran in staged phases over roughly ten weeks. Each phase was validated in isolation on a non-critical environment before it touched a live client engagement — a deliberately slower path than a single cutover, chosen specifically so nothing broke mid-contract for a client already live on the old infrastructure.
Cost tagging and the usage-based reporting model went live in the final two weeks, once the templated environments underneath it were stable enough to produce trustworthy per-client numbers.
Challenges along the way
Undocumented dependencies the ops team didn't know they had
The estate-wide audit turned up several services quietly depended on by client-facing tools that nobody on the current ops team had originally set up — inherited from staff who'd since left. Rather than migrate blind, Merilsoft flagged every dependency of unclear origin for a manual sign-off from Keith's team before it was touched, adding time to the audit phase but avoiding a migration that silently broke something nobody remembered existed.
Zero-downtime migration for clients already live
Several clients were mid-engagement on the old infrastructure when migration started, with no tolerance for downtime. Each phase was proven on a non-critical environment first, and live migrations were scheduled during each client's own lowest-traffic window rather than a single company-wide maintenance night.
The impact
The most immediate change was speed to onboard: what used to take the better part of a week of manual provisioning now stands up the same day from a template, freeing the ops team to spend that time on client-facing work instead of server setup.
Security posture moved from reactive to scheduled — baselines apply automatically across every environment rather than waiting for someone to notice an advisory, and continuous monitoring catches an anomaly while it's happening instead of after it's already cost something. Cost visibility followed the same pattern: a per-client, usage-based breakdown replaced a single blended invoice, so Keith's team can now price a new engagement from real numbers instead of a guess.
Additional value delivered
The audit was scoped as a means to an end — map the estate, then migrate it — but the catalogue it produced outlived the migration. The agency ended up with a written record of what ran where and what depended on what, rather than a picture that only existed in the ops team's collective memory. Credential handling followed from the same finding: secrets moved into Vault as a single source of truth, replacing the ad hoc credential sharing the audit had just shown the cost of. Neither was a stated objective. Together they mean a person leaving no longer takes part of the estate with them.
The Terraform templates were built to cut onboarding from a week to same-day, and they do — but a template is also a description of the environment it builds. An environment can be stood up again from the pipeline that built it instead of reconstructed from notes, and changing one starts as a change to a template rather than an edit someone made on a server and remembered to mention. None of that was the point of templating; speed was. It's the part that keeps the estate from drifting back toward the one-off servers it came from.
Auto Scaling went in to match capacity to each client's workload, which it does — but the quieter effect is on the ops team's week. A busy month for a client is no longer also a manual job, because nobody resizes a server by hand for it. Capacity never appeared in the objectives, which covered provisioning speed, patching, cost visibility, and a migration that didn't break anyone mid-contract. It points the same direction as the scheduled baselines and the monitoring anyway: work that used to depend on somebody noticing — an advisory, a traffic spike, a server that needed to be bigger — now happens on its own.
“Merilsoft transformed our IT infrastructure with ease. Their cloud solutions enhanced our scalability, security, and overall efficiency beyond expectations.”
Lessons learned
- An estate-wide audit before any migration design work is worth the time it costs — the riskiest dependencies were the ones nobody currently on staff knew existed.
- Validating each migration phase on a non-critical environment first, rather than moving straight to production, was slower but meant zero downtime for clients already live on the old infrastructure.
- Cost visibility and security posture improved together, not separately — both came from the same underlying move to templated, tagged, monitored environments instead of one-off servers.
waveagency's problem was never a lack of technical skill on its own ops team — it was infrastructure that had grown faster than anyone had time to standardize. Templating what used to be bespoke, and monitoring what used to be reactive, turned that team's time back toward the client work the agency actually bills for.
Your operation could be next
Tell us how you run today — we'll show you what changes, with numbers.
Or call us: 1-225-573-9244
