Architecture overview
The Web App Blueprint runs a working web application in the dev, staging and prod subscriptions of the Azure Enterprise Baseline: a Python Flask API on Azure Kubernetes Service (AKS) and a React single-page app served from a storage static website, both reached only through Azure Front Door, with Azure Cosmos DB for MongoDB vCore for data and Azure Managed Redis for caching. ArgoCD inside each cluster deploys the API from a GitOps repository, so a commit reaches production through pull requests.
How it works
Front Door is the only public entry. It serves the app host blueprint-app.<stage>.company.com from the storage account and forwards the API host blueprint-api.<stage>.company.com to the cluster's ingress controller. The API reads and writes items in Cosmos DB and caches reads in Redis. Both data stores sit behind private endpoints and accept Microsoft Entra tokens only: no database password and no cache access key exists. ArgoCD watches the GitOps repository and rolls the API forward when a stage's image tag changes.
Three repositories
| Repository | What it holds |
|---|---|
acme-azure-blueprint-webapp-infra | The infrastructure of every stage as OpenTofu modules and Terragrunt units: AKS and its add-ons, the data stores, the application vault, the SPA storage and Front Door |
acme-azure-blueprint-webapp-gitops | The Helm chart ArgoCD reconciles into each cluster, the hand-maintained values per stage and the image each stage runs |
acme-azure-blueprint-webapp-code | The Flask API, the React app, the tests and the build, release and promotion workflows |
The infrastructure repository creates the platform, including ArgoCD. The code repository builds images and opens pull requests against the GitOps repository. ArgoCD applies what the GitOps repository says. Repositories describes who changes what.
One stage, one stack
Each stage lives in its own platform subscription, acme-plat-dev, acme-plat-staging or acme-plat-prod, and is built from the same template of 13 Terragrunt units in two groups:
- Shared infrastructure: the AKS cluster, the Node Auto Provisioning objects for application nodes, the managed NGINX ingress controllers, the External Secrets Operator, cert-manager and ArgoCD.
- The application: the application Key Vault, the application namespace and its workload identity, Azure Managed Redis, Cosmos DB for MongoDB vCore, the SPA storage account, Front Door and Application Insights.
Only a handful of values change between stages. Dev runs the Free AKS tier, Front Door Standard and single-node data stores. Staging and prod run the Standard AKS tier, Front Door Premium with Private Link origins, and zone-redundant Cosmos DB and Redis. Prod alone adds delete locks on the vault and the data stores and a manual sync in ArgoCD. Sizing per stage has the full table.
Inside the cluster
The cluster has two kinds of node. A zonal system pool, tainted so that only platform components land on it, runs the add-ons the infrastructure repository installs. Node Auto Provisioning adds untainted nodes for the application pods when they are pending and removes them when they go. The API server is private, people and pipelines sign in with Microsoft Entra ID, and Cilium enforces the chart's network policy. The AKS cluster page starts the details.
Delivery chain
The image is built once, on merge, pushed to Azure Container Registry in the Baseline's acme-core-artifacts subscription and locked against overwrite and deletion. A release adds a version tag to the same image, and promotion to production is a manual workflow that opens a pull request a person merges. The React build is uploaded to the stage's storage static website and the Front Door endpoint is purged. The pattern is described in immutable artifacts and environments and promotion.
What it builds on
The blueprint creates no network and no subscription. At plan time it reads the values it needs from the stage's platform Key Vault, kv-acme-eus2-<stage>-plat, which the Baseline publishes: subnet and route table IDs, DNS zones, the Private Link zone map, the stage's Log Analytics workspace, the registry, the action group, the web application firewall template and the code pipeline's identity. Egress from the cluster leaves through the Baseline's hub firewall, and the pipelines run on the Baseline's self-hosted runners because the vaults, the API server and the staging and prod storage are private. Application secrets that the Secrets Blueprint delivers land in the blueprint's application vault, where the pods read them. The landing zone contract lists every value.
For the full list of services, see the service inventory. For what a customer receives, see what you receive.