# SaaS startup — Friday deploys back on the calendar

Quebec SaaS — Pouya K built GitHub Actions → AKS; Amir KH handled Azure networking and Key Vault cutover.

> technology · 2026-07-08T22:55:43.770Z

Project overview

A Quebec SaaS team shipping React/Next.js frontends and NestJS APIs was spending half a day per release — manual deploys, secrets in config files, no staging gate. Pouya K designed the GitHub Actions → AKS pipeline, containerized the services, and added automated smoke tests; Amir KH handled Azure networking, Key Vault integration, and the DigitalOcean-to-AKS cutover plan.

Client context

  - Industry: Technology / SaaS

  - Client size / environment: 18-person product team · Montreal

  - Primary stakeholders: CTO, platform engineer, product leads

Challenge

Friday deploys were banned. Secrets lived in repo env files. Staging did not mirror production ingress or TLS, so “works in staging” was not trusted.

Scope delivered

  - AKS cluster baseline with staging + production namespaces

  - GitHub Actions pipeline with manual approval gate to production

  - Azure Key Vault for secrets — zero secrets in git

  - Automated smoke tests on every deploy artifact

Before / after

  - Before: Manual SSH deploys, secrets in config, no staging parity, Friday releases off the table.

  - After: Containerized workloads, Key Vault-backed secrets, and sub-60-minute release cadence with automated smoke gates — Friday deploys back on the calendar.

Before: manual deploy rituals and scattered secrets
After: GitHub Actions pipeline with staging gate and smoke tests

Visual proof placeholders

  - GitHub Actions workflow run showing green staging + prod promotion

  - AKS deployment dashboard with revision history

  - Release checklist the CTO signs digitally before prod gate

Delivery timeline

  - Sprint 1: Staging AKS + pipeline skeleton + Key Vault wiring

  - Sprint 2: Service containerization and smoke test suite

  - Sprint 3: Production cutover, DNS/ingress swap, team training

Outcome

Deploy anxiety dropped. The platform engineer said it was the first time staging actually matched how production behaved behind TLS and ingress.

"Pouya K owned the pipeline and tests; Amir made the Azure networking make sense. We finally ship on Friday without fear." — CTO, anonymized Quebec SaaS

Technology stack

GitHub Actions, Azure Kubernetes Service, Key Vault, NestJS, Next.js, Docker, Amen DevOps retainer.

Visual evidence

AKS cluster operations — staging and production namespaces
Implementation evidence — automated release pipeline on screen

---
Source page: https://amensecurity.ca/en/projects/saas-devops-pipeline
Markdown version for AI agents · Amen Security
Email: info@amensecurity.ca
Phone: +1 (204) 514-3536
