Skip to main content

Service inventory

The Web App Blueprint deploys eighteen Azure services and features and five Kubernetes components into each stage subscription, and relies on shared services that the Azure Enterprise Baseline runs in the stage and core subscriptions. Everything in the first two tables is created by the blueprint's own code; the third lists what it uses from the Baseline.

How the pieces group​

Azure services​

ServiceUnitWhat it does in the blueprintStage defaults
Azure Kubernetes Service (AKS)aksOne cluster per stage, acme-eus2-<stage>-aks, with a private API server, Microsoft Entra ID and Azure RBAC for Kubernetes, Workload ID and a zonal system poolFree tier in dev, Standard in staging and prod
Node Auto Provisioningaks, node-poolsThe only application capacity: one NodePool and one AKSNodeClass that buy D- and E-family VMs, spot firstCPU ceiling 32 in dev, 64 in staging, 128 in prod
Application routing add-onaks, ingressManaged NGINX: nginx-internal in every stage, nginx-public in dev; writes internal records in internal.company.comInternal controller with 2 minimum replicas in dev, 3 in staging and prod
Azure Load Balanceringress (created by AKS)An internal load balancer in snet-ingress for nginx-internal; in dev also a public one for nginx-public, open only to Front Door's service tagPublic load balancer and its static public IP in dev only
Azure Private Link Serviceingress (created by AKS)acme-eus2-<stage>-ingress-pls in snet-pls, the private path from Front Door Premium to the internal load balancerStaging and prod
Azure Front Doorfront-doorProfile acme-eus2-<stage>-afd with the app and API endpoints, custom domains with managed certificates, origins and routes; WAF logs, failed health probes and metrics go to the stage workspace, access logs where front_door_access_logs is onStandard in dev, Premium in staging and prod; access logs in staging and prod
Front Door web application firewallfront-doorA WAF policy in Prevention mode built from the Baseline's template: custom rules on every SKU, Microsoft's Default Rule Set and Bot Manager rule set on PremiumManaged rule sets in staging and prod
Azure Storage static websitefrontend-storagestacmeeus2<stage>frontend, zone-redundant, Entra-only uploads, versioning and 7-day soft delete; serves the React buildPublic network access off, with a blob private endpoint, in staging and prod
Azure Cosmos DB for MongoDB vCoremongo-clusteracme-eus2-<stage>-mongo, MongoDB 8.0, Microsoft Entra authentication only, the application identity as a database userM10, 32 GiB, no high availability in dev; M30, 128 GiB, zone-redundant elsewhere
Azure Managed Redismanaged-redisacme-eus2-<stage>-redis, TLS on port 10000, access keys off, the application identity on the access policyBalanced_B0 without high availability in dev; Balanced_B1 with it elsewhere
Azure Key Vaultapp-key-vaultThe application vault kv-acme-eus2-<stage>-app: RBAC authorization, purge protection, private from creationDelete lock in prod
Private endpointsapp-key-vault, mongo-cluster, managed-redis, frontend-storageOne per vault, database and cache in snet-endpoints, registered in the Baseline's central Private Link zonesStorage blob endpoint in staging and prod
Managed identitiesaks, external-secrets, cert-manager, app-namespaceThe cluster's control-plane and kubelet identities, and workload identities for External Secrets, cert-manager and the applicationSame in every stage
Application Insightsapp-insightsacme-eus2-<stage>-appi on the stage's Log Analytics workspace; its connection string goes to the application vaultAvailability test on /health and its alert in staging and prod
Container InsightsaksA data collection rule that sends container logs and inventory to the stage's Log Analytics workspaceSame in every stage
Azure Policy add-on and Deployment SafeguardsaksBest-practice checks on workloads, in Warn modeSame in every stage
Azure DNSfront-doorThe CNAME and _dnsauth validation records for the two hosts, in the Baseline's public zone of the stageSame in every stage
Management locksapp-key-vault, mongo-cluster, managed-redisCanNotDelete on the application vault and both data storesProd only

Kubernetes components​

ComponentUnitRole
ArgoCDargocdSyncs the application's Helm chart from the GitOps repository; two replicas per component in staging and prod
External Secrets Operatorexternal-secretsCopies host names, ports and application secrets from the application vault into Kubernetes Secrets
cert-managercert-managerOrigin certificates from Let's Encrypt through DNS-01, and an internal certificate authority for internal hosts
Managed NGINX ingress controllersingressThe origins of the Front Door API route and the ArgoCD ingress
CiliumaksThe cluster's data plane and the engine that enforces the chart's default-deny network policy

The add-ons and where they run are on cluster add-ons.

Used from the Baseline​

ServiceWhere it livesUse
Platform Key Vault (the contract)Each stage subscriptionThe landing-zone values every unit reads at plan time, and four values the blueprint writes back
Virtual network and route tableEach stage subscriptionsnet-aks, snet-ingress, snet-pls and snet-endpoints; egress through the hub firewall, or the spoke NAT gateway in the spoke_nat mode
Azure Firewallacme-core-networkThe cluster's only way out to the internet in the default egress mode
Private DNS zonesacme-core-networkinternal.company.com and the privatelink.* zones of the API server, vault, database, cache and storage
Public DNS zonesacme-core-dns<stage>.company.com, where Front Door's records and cert-manager's challenges are written
Azure Container Registryacme-core-artifactsThe API image, with locked tags; the kubelet identity holds AcrPull
Log Analytics workspaceEach stage subscriptionContainer Insights, Key Vault, Cosmos DB and Front Door diagnostics, and Application Insights
Action groupacme-core-securityReceives the availability alert of staging and prod
GitHub federated identities and runnersacme-core-autoThe deployer identities of the infrastructure and code repositories, and the self-hosted runners that reach the private endpoints

The exact versions of the tools, providers and charts are on the versions page. How the values cross from the Baseline is on landing zone contract, and how they change per stage on sizing per stage.