Service inventory
The Web App Blueprint deploys eighteen Azure services and features and five Kubernetes components into each stage subscription, and relies on shared services that the Azure Enterprise Baseline runs in the stage and core subscriptions. Everything in the first two tables is created by the blueprint's own code; the third lists what it uses from the Baseline.
How the pieces group
Azure services
| Service | Unit | What it does in the blueprint | Stage defaults |
|---|---|---|---|
| Azure Kubernetes Service (AKS) | aks | One cluster per stage, acme-eus2-<stage>-aks, with a private API server, Microsoft Entra ID and Azure RBAC for Kubernetes, Workload ID and a zonal system pool | Free tier in dev, Standard in staging and prod |
| Node Auto Provisioning | aks, node-pools | The only application capacity: one NodePool and one AKSNodeClass that buy D- and E-family VMs, spot first | CPU ceiling 32 in dev, 64 in staging, 128 in prod |
| Application routing add-on | aks, ingress | Managed NGINX: nginx-internal in every stage, nginx-public in dev; writes internal records in internal.company.com | Internal controller with 2 minimum replicas in dev, 3 in staging and prod |
| Azure Load Balancer | ingress (created by AKS) | An internal load balancer in snet-ingress for nginx-internal; in dev also a public one for nginx-public, open only to Front Door's service tag | Public load balancer and its static public IP in dev only |
| Azure Private Link Service | ingress (created by AKS) | acme-eus2-<stage>-ingress-pls in snet-pls, the private path from Front Door Premium to the internal load balancer | Staging and prod |
| Azure Front Door | front-door | Profile acme-eus2-<stage>-afd with the app and API endpoints, custom domains with managed certificates, origins and routes; WAF logs, failed health probes and metrics go to the stage workspace, access logs where front_door_access_logs is on | Standard in dev, Premium in staging and prod; access logs in staging and prod |
| Front Door web application firewall | front-door | A WAF policy in Prevention mode built from the Baseline's template: custom rules on every SKU, Microsoft's Default Rule Set and Bot Manager rule set on Premium | Managed rule sets in staging and prod |
| Azure Storage static website | frontend-storage | stacmeeus2<stage>frontend, zone-redundant, Entra-only uploads, versioning and 7-day soft delete; serves the React build | Public network access off, with a blob private endpoint, in staging and prod |
| Azure Cosmos DB for MongoDB vCore | mongo-cluster | acme-eus2-<stage>-mongo, MongoDB 8.0, Microsoft Entra authentication only, the application identity as a database user | M10, 32 GiB, no high availability in dev; M30, 128 GiB, zone-redundant elsewhere |
| Azure Managed Redis | managed-redis | acme-eus2-<stage>-redis, TLS on port 10000, access keys off, the application identity on the access policy | Balanced_B0 without high availability in dev; Balanced_B1 with it elsewhere |
| Azure Key Vault | app-key-vault | The application vault kv-acme-eus2-<stage>-app: RBAC authorization, purge protection, private from creation | Delete lock in prod |
| Private endpoints | app-key-vault, mongo-cluster, managed-redis, frontend-storage | One per vault, database and cache in snet-endpoints, registered in the Baseline's central Private Link zones | Storage blob endpoint in staging and prod |
| Managed identities | aks, external-secrets, cert-manager, app-namespace | The cluster's control-plane and kubelet identities, and workload identities for External Secrets, cert-manager and the application | Same in every stage |
| Application Insights | app-insights | acme-eus2-<stage>-appi on the stage's Log Analytics workspace; its connection string goes to the application vault | Availability test on /health and its alert in staging and prod |
| Container Insights | aks | A data collection rule that sends container logs and inventory to the stage's Log Analytics workspace | Same in every stage |
| Azure Policy add-on and Deployment Safeguards | aks | Best-practice checks on workloads, in Warn mode | Same in every stage |
| Azure DNS | front-door | The CNAME and _dnsauth validation records for the two hosts, in the Baseline's public zone of the stage | Same in every stage |
| Management locks | app-key-vault, mongo-cluster, managed-redis | CanNotDelete on the application vault and both data stores | Prod only |
Kubernetes components
| Component | Unit | Role |
|---|---|---|
| ArgoCD | argocd | Syncs the application's Helm chart from the GitOps repository; two replicas per component in staging and prod |
| External Secrets Operator | external-secrets | Copies host names, ports and application secrets from the application vault into Kubernetes Secrets |
| cert-manager | cert-manager | Origin certificates from Let's Encrypt through DNS-01, and an internal certificate authority for internal hosts |
| Managed NGINX ingress controllers | ingress | The origins of the Front Door API route and the ArgoCD ingress |
| Cilium | aks | The cluster's data plane and the engine that enforces the chart's default-deny network policy |
The add-ons and where they run are on cluster add-ons.
Used from the Baseline
| Service | Where it lives | Use |
|---|---|---|
| Platform Key Vault (the contract) | Each stage subscription | The landing-zone values every unit reads at plan time, and four values the blueprint writes back |
| Virtual network and route table | Each stage subscription | snet-aks, snet-ingress, snet-pls and snet-endpoints; egress through the hub firewall, or the spoke NAT gateway in the spoke_nat mode |
| Azure Firewall | acme-core-network | The cluster's only way out to the internet in the default egress mode |
| Private DNS zones | acme-core-network | internal.company.com and the privatelink.* zones of the API server, vault, database, cache and storage |
| Public DNS zones | acme-core-dns | <stage>.company.com, where Front Door's records and cert-manager's challenges are written |
| Azure Container Registry | acme-core-artifacts | The API image, with locked tags; the kubelet identity holds AcrPull |
| Log Analytics workspace | Each stage subscription | Container Insights, Key Vault, Cosmos DB and Front Door diagnostics, and Application Insights |
| Action group | acme-core-security | Receives the availability alert of staging and prod |
| GitHub federated identities and runners | acme-core-auto | The deployer identities of the infrastructure and code repositories, and the self-hosted runners that reach the private endpoints |
The exact versions of the tools, providers and charts are on the versions page. How the values cross from the Baseline is on landing zone contract, and how they change per stage on sizing per stage.