What you receive
You receive four things: the Baseline's Git repository customized for your organization, the documentation to run it, a complete 14-subscription Azure environment deployed into your tenant by the BuiltForProd team, and a handover after which your engineers own and change all of it. Blueprints, if you buy them, arrive the same way, each in its own repositories.
How delivery works
The BuiltForProd team customizes the base repositories for your organization, deploys them into your Microsoft Entra ID tenant and subscriptions, and hands them over ready for your teams to deploy workloads or customize further. The work is fully executed by BuiltForProd in every deployment option.
The repository
The core deliverable is the landing-zone repository, acme-azure-platform-baseline in the sample naming, where acme becomes your organization's abbreviation. It holds the whole foundation as code:
| Path | What it contains |
|---|---|
environments/ | The deployment tree, management group, then subscription, then region or global; each folder's stack file lists the units deployed there |
units/ | One definition per unit type, the catalog every stack file draws from |
stacks/ | The workload-subscription template and the two includes every core subscription uses |
modules/ | 33 OpenTofu modules, one resource category each, written for this repository |
root.hcl, common.hcl | Shared configuration every unit inherits: providers, state, naming, tags; the namespace, tenant, domain and home region |
network.hcl, security.hcl | The feature switches of the hub network and of the security services |
vnet_map.yaml, vnet_map_compact.yaml | The address plan, the only place an IP range is written, and its compact alternative |
policies/ | The web application firewall rule template the blueprints build their Front Door policy from |
runner-image/ | The self-hosted GitHub runner image |
scripts/, .pre-commit-config.yaml | The guard scripts that pre-commit and CI run before any plan |
.github/ | Four workflows (plan, apply, drift detection, runner image) and the code-owner rules |
Every value your deployment must set (namespace, tenant, domain, billing scope or subscription IDs, GitHub organization, mailboxes) is marked in the code with a TODO: comment. Every optional choice (a feature switch, a compliance initiative, a paid option) carries an @optional: comment with its list price beside it. Nothing deployment-specific is hidden in logic, so git grep "@optional: " lists every decision you can revisit.
The related repositories
| Repository | What it holds |
|---|---|
acme-azure-blueprint-webapp-infra | Infrastructure of the container web application platform |
acme-azure-blueprint-webapp-code | The web application's API and front end |
acme-azure-blueprint-webapp-gitops | The deployment definitions ArgoCD reconciles into the cluster |
acme-azure-blueprint-etl-infra | Infrastructure of the data lake and ETL platform |
acme-azure-blueprint-etl-code | The ETL jobs and their trigger |
acme-azure-blueprint-secrets | Encrypted application secrets, synchronized into the workload subscriptions |
The blueprints build on the Baseline without changing it: they deploy into the four workload subscriptions and read the values the Baseline publishes for them. Polyrepo strategy explains how the repositories connect. With Full Deployment with Blueprints you receive two of them: the Web App Blueprint, the Data and ETL Blueprint or the Secrets Blueprint.
The documentation
This documentation set is the handover documentation: the architecture and its design decisions, the subscriptions, networking, security, compliance, observability and pipelines, how-to guides, runbooks and scaling guidance. The documentation overview holds the concepts behind it. Sign-in unlocks the full set for your organization, and pages show your own values (namespace, tenant, region, subscription IDs) in place of the samples.
The deployed environment
When BuiltForProd finishes, your tenant runs:
- 14 subscriptions under
mg-acme: ten core subscriptions and four workload subscriptions (sandbox, dev, staging, prod), each with the subscription baseline applied. - The hub-and-spoke network: the hub VNet with Azure Firewall and the DNS Private Resolver, four spokes and the runner VNet, the central private DNS zones and the public DNS zones.
- Governance: the guardrail, region, audit-protection and tag initiatives at
mg-acme, and the Microsoft cloud security benchmark and SOC 2 baseline initiatives. - Security and audit: Defender for Cloud in every subscription, the audit workspace and immutable audit storage with its customer-managed key, the security workspace, and the activity-log and KQL alerts.
- Identity: Entra ID groups mapped to Azure RBAC, Conditional Access in report-only mode, and one federated managed identity per repository.
- Delivery: the state storage account, the container registry, the Container Apps runners and the four workflows in your GitHub organization.
Paid options such as the VPN gateway, DDoS Network Protection, Microsoft Sentinel and further Defender plans are built into the code and switched on when your deployment needs them. The architecture overview shows how the pieces connect.
The handover
At handover you own the repositories and the environment. Changes go through pull requests: CI plans them, code owners approve changes to the tenant structure, network and guardrails, and merging applies them behind the prod environment's reviewers. Changes made in the Azure portal are reported as drift.
The repositories are licensed under the PolyForm Internal Use License 1.0.0, as LICENSE.md states. You may deploy, manage and scale your internal Azure infrastructure with the code, modify it, and share it with employees and contractors working for your organization. You may not resell or sub-license it, host it in a public repository, use it to provide managed services to third parties, or remove its notices. The terms are summarized under purchasing and licensing.
Deployment options
| Option | What it includes |
|---|---|
| Standard Deployment | The Baseline: the 14-subscription environment set up by BuiltForProd, the customized repository and the documentation |
| Full Deployment with Blueprints | Everything in Standard, plus any two blueprints deployed and working |
| Blueprint Deployment | For customers who already run the Baseline: additional blueprints deployed by BuiltForProd |
Ongoing help after handover is a separate, optional service, BuiltForProd Managed, in three options: On-Demand, Support SLA and Team Augmentation.