Azure foundations, governance và cost
Azure mapping với AWS chỉ ở capability; hierarchy, identity, network constructs, availability và service semantics cần học theo Microsoft docs.
Hierarchy and identity
Entra tenant → management groups → subscriptions → resource groups/resources. Azure Policy/initiatives, locks, tags and Defender. Entra ID/RBAC roles, managed identities, workload identity federation, PIM for privileged access. Resource group là lifecycle/management boundary, không network boundary.
Network/edge
VNet/subnets, route tables, NSGs, NAT Gateway, Azure DNS, Front Door global edge, Application Gateway L7/WAF, Load Balancer L4, Private Link, VNet peering and hub-spoke/Virtual WAN. Region pairs are platform concept, not automatic app DR.
Compute/data
VM Scale Sets, App Service, Container Apps, AKS, Functions; Blob Storage; Azure SQL/PostgreSQL; Cosmos DB partition/consistency. Choose based control, scaling, cold start, networking, data model and team.
Messaging/security/ops
Service Bus queues/topics, Event Grid events, Event Hubs streams. Key Vault, managed HSM, Defender, Azure Monitor/Log Analytics/Application Insights, Activity Log. Managed identity avoids stored secrets but RBAC/network still required.
Reliability and FinOps
Availability Sets/Zones, zone-redundant services, paired/secondary regions only when RPO/RTO justify. Azure Backup/Site Recovery/service-native PITR. Cost Management budgets, reservations/savings plan, Hybrid Benefit, spot, storage tiers, egress/log ingestion and rightsizing. Compare business capability/TCO, not list price alone.