Infrastructure that survives isolation.
Kubernetes, sovereign environments, and AI that runs inside your perimeter.

Most Kubernetes consultancies assume a working internet connection. A registry to pull from, a chart to fetch, a control plane somebody else operates. I build the clusters where none of that exists, and run the virtualization and the hardened Linux underneath them.
The same problem is now arriving for AI. Regulated organisations across Europe want agentic systems and cannot send their data to an inference API in another jurisdiction. Solving that means running models on your own hardware, behind your own gateway, inside your own perimeter.
It is the same discipline, applied twice.
See the capabilitiesThe founder
Hi, I'm Yaro.
I founded Lõhmus Tech, and I'm the person you actually work with. No account managers, no handoffs, no "let me check with the team." You get the engineer who does the work.
What I do
Sovereign infrastructure
Clusters and platforms that keep running when the outside world is not available.
Air-gapped and sovereign environments
Offline registry mirroring, artifact provenance, and a patch and CVE process that works with no egress at all.
Kubernetes, cloud to bare metal
On-premise, managed, and hybrid clusters. GitOps delivery. Multi-cluster topologies that fail independently.
Virtualization platforms
Proxmox and VMware as the substrate under the cluster, designed and operated as a first-class layer rather than an afterthought.
Hardened Linux
Minimal images, controlled supply chain, a baseline you can defend in an audit.
Cross-cloud and hybrid
Depth in GCP and Azure, and the connective work that joins them to what you already run.
Resilience and disaster recovery
Redundancy design, recovery planning, and systems that heal without waking anyone up.
Sovereign AI
Agentic systems that run on your hardware, under your policy, inside your network.
Self-hosted inference
Running open models on your own GPUs. Scheduling, serving and lifecycle on Kubernetes, including fully disconnected.
AI gateways
One controlled ingress for model traffic. Routing, quotas, cost attribution, audit logging, key management.
Guardrails
Input and output policy at the model boundary. Prompt-injection defence and data-loss prevention that a security team can actually reason about.
Agent fleets and harnesses
Orchestrating and operating fleets of agents, and the harness around them: tool boundaries, permissions, isolation, observability.
Retrieval over private corpora
RAG pipelines where the documents, the embeddings and the index never leave the perimeter.
Agentic development
Putting agentic workflows into a real delivery process, with review gates that hold.
Beneath both, the software itself: full systems from design to delivery, legacy modernised, built with agentic coding under close human steering. More in the capabilities.
Eight years of building this.
As an employee, as a consultant, and on ventures I founded or co-founded. Almost always alongside other people.
- Atmos Group FinlandAir-gapped medical system
- BookkeriCo-founder, high-availability SaaS
- St1Cloud architect and team lead
- Suomen RahapajaBackend and coin-recognition ML