Before
Manual SSH deploys, secrets in config, no staging parity, Friday releases off the table.
SaaS québécois — pipeline GitHub Actions → AKS par Pouya K; réseau Azure et Key Vault par Amir KH.

Industry
technology
Services involved
2
Delivery record
Published case study
A Quebec SaaS team shipping React/Next.js frontends and NestJS APIs was spending half a day per release — manual deploys, secrets in config files, no staging gate. Pouya K designed the GitHub Actions → AKS pipeline, containerized the services, and added automated smoke tests; Amir KH handled Azure networking, Key Vault integration, and the DigitalOcean-to-AKS cutover plan.
Friday deploys were banned. Secrets lived in repo env files. Staging did not mirror production ingress or TLS, so “works in staging” was not trusted.
Before
Manual SSH deploys, secrets in config, no staging parity, Friday releases off the table.
After
Containerized workloads, Key Vault-backed secrets, and sub-60-minute release cadence with automated smoke gates — Friday deploys back on the calendar.




Phase 1
Sprint 1: Staging AKS + pipeline skeleton + Key Vault wiring
Phase 2
Sprint 2: Service containerization and smoke test suite
Phase 3
Sprint 3: Production cutover, DNS/ingress swap, team training
Deploy anxiety dropped. The platform engineer said it was the first time staging actually matched how production behaved behind TLS and ingress.
"Pouya K owned the pipeline and tests; Amir made the Azure networking make sense. We finally ship on Friday without fear." — CTO, anonymized Quebec SaaS
GitHub Actions, Azure Kubernetes Service, Key Vault, NestJS, Next.js, Docker, Amen DevOps retainer.