Azure Web App Blueprint
The Web App Blueprint for Azure is a working, production-ready web application deployed on the Azure Enterprise Baseline: a Flask API on Azure Kubernetes Service (AKS) and a React single-page application, both served through Azure Front Door, with Cosmos DB for MongoDB vCore, Azure Managed Redis and the GitOps delivery chain that takes a commit to production. This overview section is public.
What it deploys
The blueprint is three repositories, deployed into the dev, staging and prod platform subscriptions of the Baseline.
| Repository | What it holds |
|---|---|
acme-azure-blueprint-webapp-infra | Per stage: an AKS cluster with a private API server, Azure CNI Overlay with Cilium, Microsoft Entra ID and Azure role-based access control (RBAC) for Kubernetes, and Node Auto Provisioning for application nodes; the managed NGINX ingress; Front Door with a web application firewall (WAF) as the only public entry; Cosmos DB for MongoDB vCore and Azure Managed Redis behind private endpoints; an application Key Vault; Application Insights; and the cluster add-ons External Secrets, cert-manager and ArgoCD |
acme-azure-blueprint-webapp-gitops | The Helm chart ArgoCD reconciles into each stage, with per-stage values and a default-deny network policy |
acme-azure-blueprint-webapp-code | The Flask API and the React front end, with GitHub Actions pipelines that build each image once, tag it immutably in Azure Container Registry and promote it by pull request: automatically to dev and staging, after a review to prod |
The application holds no password and no access key. Its pods authenticate to Cosmos DB and Managed Redis with Microsoft Entra tokens from their workload identity, and the pipelines sign in with federated identities. GitOps explains the promotion model the delivery chain follows.
The complete Web App Blueprint documentation for Azure is available to customers who hold it. Read the blueprints page for how blueprints work, then sign in from the navigation bar to open the full Web App Blueprint documentation, or contact BuiltForProd to purchase it.