Skip to content
OpsHero
Book a consultation

The right way to build, test, secure and ship at your company

Delivered as working pipeline stages and starter repos your teams own, instead of a wiki page nobody reads. The load-bearing words are working and own.

Where it lands
  • Your Git provider, your CI, your cluster, your Vault
  • You own the artifacts and run them without us
  • No OpsHero runtime dependency
  • Opinionated and supported — never mandatory

Leaving the path is allowed. You just leave the support behind with it.

Nobody arrives asking for golden paths

Every repo is a snowflake. We keep rebuilding the same pipeline. We have no idea which services have scanning turned on. Onboarding takes a month.

  • A new service took three weeks to get to production, and most of that was plumbing.
  • A security finding traced back to a repo nobody had wired scanning into.
  • An audit asked which services enforce which controls, and the answer took a week to assemble.
  • A team joined through acquisition or growth and rebuilt CI from scratch, differently.
  • The platform team of two is drowning in tickets for things that should be self-service.
  • Agent-generated pull requests went up and the review queue stopped coping.

Concrete artifacts, not a recommendation deck

Depending on what the assessment finds, and shipped into your own stack.

Blueprint repos per tech stack

Wired for build, test and deploy from the first commit.

CI stages for your stack

Build, test, lint, scan, package.

A deploy stage

Targeting your Kubernetes cluster.

A universal Helm chart

Parameterised across services, so one chart covers the estate.

Vault integration

A secrets structure that works the same way for every service.

Gates that run every time

Security scanning on every repo, linting on every feature branch.

Assess, build, hand over

The assessment

We review the stacks in play, the repos, the CI setup, the cluster, the secrets handling and the security gates. It is a real deliverable, not a sales call in disguise, and you can act on it without buying the build.

A golden path is a set of working artifacts. You can have every one of them without buying or building a platform first.

You are here

SDLC Golden Paths

Working artifacts in your own stack. The lighter, cheaper answer, and the right one for most companies at this size.

The heavier answer

Internal Developer Platform

The step up, for organisations where self-service itself is the bottleneck. If you need the whole platform, that page is honest about when you do.

The market consensus is that golden paths live inside an internal developer platform. We disagree. For a lot of companies the platform is the expensive way to get the thing they actually wanted — and saying so out loud costs us the bigger sale sometimes.

This is also not a developer portal and not a managed service. Each of those has its own page and its own reason to exist.

Day 50 and Day 500, not Day 1

Most golden-path efforts over-invest in project creation, which is a vanishingly small part of an application’s life, and under-invest in everything that happens afterwards. Ours are weighted to the recurring work: every feature branch gets linted, every repo gets scanned, every deploy goes through the same stage. Twenty years of production operations sit behind the defaults — the chart, the secrets layout and the gates are what we run for people who page us, not what looks tidy in a demo.

Build it in-house

You can, and you have not, because it is nobody’s full-time job and it loses every prioritisation call to shipping features. We do it in weeks because we have done it many times — and then you own it.

Buy an IDP product

A big commitment that does not answer the question. The product is the container; somebody still has to write the paths that go inside it.

A generalist consultancy

Which will learn your stack on your budget.

Nothing

The default, and the most common competitor.

The questions we get asked

Our stack is too bespoke for templates.

Usually half true. The assessment exists precisely to find where you are genuinely unusual and where you only think you are. Most bespoke turns out to be undocumented rather than special.

We tried standardising and the teams ignored it.

The most serious objection, and usually the reason the last attempt failed. A golden path is opinionated and supported, not mandatory. Leaving the path is allowed — you just leave the support behind with it. The aim is that the easy route is also the correct one, not that anyone is made to comply.

Isn’t this just a Backstage project?

No. A portal is a container; this is the content that would go inside one. You can have the content without the container, which is the whole argument of this page.

We would be locked into OpsHero.

Everything ships into your own stack — your Git provider, your CI, your cluster, your Vault — and you own it. There is no OpsHero runtime dependency.

Our platform team could do this.

They could. Then point at the calendar.

Book the assessment

It is a real deliverable. You can act on it without buying the build phase.

  • A written map of how software currently gets from commit to production
  • A prioritised list of the paths worth paving, and in what order
  • A scope and price for the build
Book the assessment
Not ready to talk? Both of these surface the same drift

Where to go next

SDLC Golden Paths: Pipelines and Starter Repos — OpsHero