Part 13 · CI/CD, Git & Cloud

Azure foundations, governance và cost

Azure mapping với AWS chỉ ở capability; hierarchy, identity, network constructs, availability và service semantics cần học theo Microsoft docs.

Hierarchy and identity

Entra tenant → management groups → subscriptions → resource groups/resources. Azure Policy/initiatives, locks, tags and Defender. Entra ID/RBAC roles, managed identities, workload identity federation, PIM for privileged access. Resource group là lifecycle/management boundary, không network boundary.

Network/edge

VNet/subnets, route tables, NSGs, NAT Gateway, Azure DNS, Front Door global edge, Application Gateway L7/WAF, Load Balancer L4, Private Link, VNet peering and hub-spoke/Virtual WAN. Region pairs are platform concept, not automatic app DR.

Compute/data

VM Scale Sets, App Service, Container Apps, AKS, Functions; Blob Storage; Azure SQL/PostgreSQL; Cosmos DB partition/consistency. Choose based control, scaling, cold start, networking, data model and team.

Messaging/security/ops

Service Bus queues/topics, Event Grid events, Event Hubs streams. Key Vault, managed HSM, Defender, Azure Monitor/Log Analytics/Application Insights, Activity Log. Managed identity avoids stored secrets but RBAC/network still required.

Reliability and FinOps

Availability Sets/Zones, zone-redundant services, paired/secondary regions only when RPO/RTO justify. Azure Backup/Site Recovery/service-native PITR. Cost Management budgets, reservations/savings plan, Hybrid Benefit, spot, storage tiers, egress/log ingestion and rightsizing. Compare business capability/TCO, not list price alone.

Tài liệu: Azure Well-Architected · Azure Landing Zones · Azure Cost Management