Trust is earned, not given

A different perspective

2017-10-19 · Projects

DevOps on Azure, part 1: The map — services and how they fit together

Part 1from the DevOps on Azure series · 6 parts in all

This series mirrors our AWS tour on Microsoft Azure, with the same three sample companies: MapleCart (e-commerce), FleetView (SaaS logistics), NewsGrid (spiky-traffic news). Part 1 is the map — and if you read the AWS series, every concept here has a cousin, which is exactly the point: the cloud layers are universal, only the product names change.

The layered model, in Azure terms

  1. Identity — Microsoft Entra ID (formerly Azure AD) is the IAM of this cloud. Service principals and managed identities play the role of IAM roles; RBAC role assignments grant permissions.
  2. Compute — Virtual Machines, App Service (PaaS web hosting), Azure Kubernetes Service (AKS), Container Apps, and Azure Functions.
  3. Data — Azure SQL Database, PostgreSQL/MySQL Flexible Server, Cosmos DB (multi-model NoSQL), Blob Storage, Redis for Azure.
  4. Network — Virtual Network (VNet), subnets, Network Security Groups (NSGs), Application Gateway/Front Door (L7 load balancing + CDN), Azure DNS.
  5. Delivery — Azure DevOps Pipelines or GitHub Actions; artifact registries via Azure Container Registry.
  6. Observability — Azure Monitor + Application Insights (one product for metrics, logs, traces, and alerts).

The request path, one sentence

A customer request lands on Azure DNS, resolves to Front Door (global L7 LB + CDN + WAF), which forwards to your app in an App Service VNet-integrated into a VNet subnet; the app reaches Azure SQL over a private endpoint using its managed identity — no passwords anywhere — and everything it emits lands in Application Insights, whose alerts email or page you. Sound familiar? It should: it's the same skeleton as the AWS one-liner in that series' part 1.

How the three companies map

Where Azure has its own personality

Three things are genuinely different here: Entra ID is the best-in-class identity plane (if your company is Microsoft-365 based, this decides the cloud); App Service's deployment slots (staging → production swap in one operation, with auto-swap warm-up) are the best blue/green in the industry; and Azure Monitor + Application Insights is observability unified into one product rather than four. The next five parts walk compute, data, network/identity, pipelines, and the one-batch Terraform finale.