DevOps on Azure, part 1: The map — services and how they fit together
Part 1from the DevOps on Azure series · 6 parts in all
This series mirrors our AWS tour on Microsoft Azure, with the same three sample companies: MapleCart (e-commerce), FleetView (SaaS logistics), NewsGrid (spiky-traffic news). Part 1 is the map — and if you read the AWS series, every concept here has a cousin, which is exactly the point: the cloud layers are universal, only the product names change.
The layered model, in Azure terms
- Identity — Microsoft Entra ID (formerly Azure AD) is the IAM of this cloud. Service principals and managed identities play the role of IAM roles; RBAC role assignments grant permissions.
- Compute — Virtual Machines, App Service (PaaS web hosting), Azure Kubernetes Service (AKS), Container Apps, and Azure Functions.
- Data — Azure SQL Database, PostgreSQL/MySQL Flexible Server, Cosmos DB (multi-model NoSQL), Blob Storage, Redis for Azure.
- Network — Virtual Network (VNet), subnets, Network Security Groups (NSGs), Application Gateway/Front Door (L7 load balancing + CDN), Azure DNS.
- Delivery — Azure DevOps Pipelines or GitHub Actions; artifact registries via Azure Container Registry.
- Observability — Azure Monitor + Application Insights (one product for metrics, logs, traces, and alerts).
The request path, one sentence
A customer request lands on Azure DNS, resolves to Front Door (global L7 LB + CDN + WAF), which forwards to your app in an App Service VNet-integrated into a VNet subnet; the app reaches Azure SQL over a private endpoint using its managed identity — no passwords anywhere — and everything it emits lands in Application Insights, whose alerts email or page you. Sound familiar? It should: it's the same skeleton as the AWS one-liner in that series' part 1.
How the three companies map
- MapleCart: App Service (two instances) + Azure SQL + Blob Storage for product images + Redis. The Microsoft-native stack — App Service is the fastest PaaS path for a .NET or Node web store.
- FleetView: AKS or Container Apps for the API fleet, Cosmos DB with per-tenant partition keys for telemetry, Entra ID B2B for customer SSO. Predictable load → reserved instances.
- NewsGrid: Static Web Apps for the site, Functions for the API — idle hours cost nothing, the viral spike just scales out. Azure's answer mirrors AWS's exactly.
Where Azure has its own personality
Three things are genuinely different here: Entra ID is the best-in-class identity plane (if your company is Microsoft-365 based, this decides the cloud); App Service's deployment slots (staging → production swap in one operation, with auto-swap warm-up) are the best blue/green in the industry; and Azure Monitor + Application Insights is observability unified into one product rather than four. The next five parts walk compute, data, network/identity, pipelines, and the one-batch Terraform finale.