%3CLINGO-SUB%20id%3D%22lingo-sub-1677941%22%20slang%3D%22en-US%22%3EBuilding%20workload%20specific%20Azure%20landing%20zones%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1677941%22%20slang%3D%22en-US%22%3E%3CP%3EBuilding%20Azure%20landing%20zones%20means%20to%20leverage%20a%20scalable%2C%20modular%20approach%20to%20building%20out%20your%20environment%20based%20on%20a%20common%20set%20of%20design%20areas.%20Consequently%2C%20knowing%20and%20understanding%20the%20type%20of%20the%20application%20and%20workload%20(consequently%20called%20archetype)%20is%20important%2C%20as%20some%20of%20the%20Azure%20services%20do%20have%20specific%20requirements%20and%20platform%20dependencies.%3C%2FP%3E%0A%3CP%3EThe%20importance%20of%20the%20archetype%20also%20called%20out%20in%20the%20critical%20design%20areas%2C%20for%20example%20Red%20Hat%20OpenShift%20with%20regards%20to%20the%20DNS%20infrastructure.%5B1%5D%20Furthermore%2C%20this%20is%20also%20one%20of%20the%20reasons%20why%20you%20see%20different%20management%20groups%20below%20the%20landing%20zone%20management%20group.%5B2%5D%20In%20this%20specific%20case%2C%20which%20basically%20is%20the%20Contoso%20reference%20implementation%2C%20there%20are%20three%20specific%20landing%20zones%3A%20SAP%2C%20Corp%20and%20Online.%3C%2FP%3E%0A%3CDIV%20id%3D%22tinyMceEditorDominik%20Zemp_0%22%20class%3D%22mceNonEditable%20lia-copypaste-placeholder%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22Picture1.png%22%20style%3D%22width%3A%20277px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F219126i2F7072C69FC48CF4%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22Picture1.png%22%20alt%3D%22Figure%201%3A%20Proposed%20management%20group%20structure%20with%20the%20Contoso%20reference%20implementation.%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EFigure%201%3A%20Proposed%20management%20group%20structure%20with%20the%20Contoso%20reference%20implementation.%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFrom%20the%20Contoso%20reference%20implementation%3A%5B3%5D%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ECorp%20Landing%20Zones%20will%20include%20all%20Virtual%20Networks%20that%20do%20not%20expose%20public%20endpoints%20and%20that%20require%20connectivity%20to%20on-premises%2C%20as%20well%20as%20connectivity%20to%20other%20Landing%20Zones.%3C%2FLI%3E%0A%3CLI%3EOnline%20Landing%20Zones%20include%20all%20Virtual%20Networks%20that%20have%20internet-facing%20applications%20via%20an%20Azure%20Application%20Gateway%20(v2).%3C%2FLI%3E%0A%3CLI%3ESAP%20represents%20a%20workload%20that%20merits%20separation%20given%20the%20implied%20specialization.%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EHow%20to%20build%20archetype%20landing%20zones%3F%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EIn%20order%20to%20build%20a%20landing%20zone%20for%20an%20used%20archetype%2C%20you%20need%20to%20understand%20all%20the%20specific%20requirements%20and%20dependencies.%20Unfortunately%2C%20there%20is%20no%20single%20place%20where%20you%20can%20find%20this%20information%2C%20but%20you%20need%20to%20gather%20this%20information%20for%20every%20Azure%20service%20used%20with%20this%20archetype.%3C%2FP%3E%0A%3CP%3EHowever%2C%20a%20general%20recommendation%20is%20to%20leverage%20the%20Azure%20Architecture%20Center%20where%20you%20can%20find%20many%20useful%20information.%20One%20specific%20example%20I%20would%20like%20to%20mention%20is%20Azure%20Kubernetes%20Service%20(AKS)%20within%20the%20Architecture%20Center.%5B4%5D%3C%2FP%3E%0A%3CP%3EIn%20the%20AKS%20production%20baseline%20(reference%20architecture)%2C%20you%20will%20find%20a%20baseline%20infrastructure%20that%20deploys%20an%20AKS%20cluster%2C%20with%20focus%20on%20security.%20The%20baseline%20includes%20recommendations%20for%20networking%2C%20security%2C%20identity%2C%20management%2C%20and%20monitoring%20of%20the%20cluster.%20Consequently%2C%20it%E2%80%99s%20aligned%20with%20the%20critical%20design%20areas%20in%20Enterprise-Scale.%3C%2FP%3E%0A%3CP%3ELet%E2%80%99s%20look%20at%20one%20of%20the%20covered%20topics%2C%20which%20is%20networking%20security.%20The%20documented%20ingress%20and%20egress%20traffic%20flow%20are%20aligned%20with%20the%20recommendation%20you%20will%20find%20in%20Enterprise-Scale.%5B7%5D%5B8%5D%20To%20be%20specific%2C%20using%20an%20Application%20Gateway%20and%20Web%20Application%20Firewall%20(WAF)%20to%20protect%20ingress%20traffic%20and%20use%20a%20Firewall%2C%20deployed%20in%20the%20(managed)%20hub%2C%20to%20protect%20egress%20traffic.%20But%20something%20that%20you%20will%20not%20find%20mentioned%20specifically%20in%20Enterprise-Scale%20are%20the%20recommended%20Azure%20Policy%20add-on%20for%20AKS.%5B6%5D%20Although%20policy-driven%20governance%20is%20one%20design%20principles%20in%20Enterprise-Scale%2C%20at%20this%20juncture%20you%20may%20have%20to%20build%20an%20AKS%20landing%20zone%20including%20all%20the%20required%20policy%20and%20also%20role%20configurations%20specifically%20addressing%20AKS.%20This%20may%20include%20network%2C%20storage%2C%20RBAC%2C%20and%20others.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThus%2C%20in%20a%20nutshell%2C%20and%20also%20my%20personal%20approach%20(now%20independent%20of%20AKS)%3A%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EAssess%20the%20required%20archetype-specific%20policyDefinition%2C%20policyAssignments%2C%20roleDefinitions%20and%20roleAssignments.%3C%2FLI%3E%0A%3CLI%3EAssess%20whether%20there%20are%20overlaps%20with%20existing%20landing%20zones%20(management%20groups)%20and%20existing%20policyAssignments%20and%20roleAssignments.%3C%2FLI%3E%0A%3CLI%3EAssess%20whether%20a%20new%20dedicated%20management%20group%2C%20including%20the%20policyAssignments%20and%20roleAssignments%2C%20does%20not%20make%20the%20management%20more%20complicated%20(no%20need%20to%20create%20the%20same%20assignments%20on%20multiple%20management%20groups).%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3EThe%20role%20of%20Well-Architected%20Framework%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EThe%20AKS%20production%20baseline%20mentioned%20above%20also%20follows%20the%20Azure%20Well-Architected%20Framework.%5B5%5D%20Though%20this%20is%20an%20AKS%20specific%20use%20case%2C%20all%20the%20deployed%20applications%20should%20follow%20the%20Well-Architected%20Framework%2C%20and%20therefore%20should%20address%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3ECost%20optimization%3C%2FLI%3E%0A%3CLI%3EOperation%20excellence%3C%2FLI%3E%0A%3CLI%3EPerformance%20efficiency%3C%2FLI%3E%0A%3CLI%3EReliability%3C%2FLI%3E%0A%3CLI%3ESecurity%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EOr%20in%20other%20words%3A%20Enterprise-Scale%20provides%20the%20all%20important%20recommendations%20for%20the%20platform%20engineering%2C%20the%20Well-Architected%20Framework%20all%20important%20recommendations%20for%20applications%20and%20workloads.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%5B1%5D%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-adoption-framework%2Fready%2Fenterprise-scale%2Fnetwork-topology-and-connectivity%23configure-dns-and-name-resolution-for-on-premises-and-azure-resources%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-adoption-framework%2Fready%2Fenterprise-scale%2Fnetwork-topology-and-connectivity%23configure-dns-and-name-resolution-for-on-premises-and-azure-resources%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%5B2%5D%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-adoption-framework%2Fready%2Fenterprise-scale%2Fmanagement-group-and-subscription-organization%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-adoption-framework%2Fready%2Fenterprise-scale%2Fmanagement-group-and-subscription-organization%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%5B3%5D%20%3CA%20href%3D%22https%3A%2F%2Fgithub.com%2FAzure%2FEnterprise-Scale%2Fblob%2Fmain%2Fdocs%2Freference%2Fcontoso%2FReadme.md%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fgithub.com%2FAzure%2FEnterprise-Scale%2Fblob%2Fmain%2Fdocs%2Freference%2Fcontoso%2FReadme.md%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%5B4%5D%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Farchitecture%2Freference-architectures%2Fcontainers%2Faks%2Fsecure-baseline-aks%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Farchitecture%2Freference-architectures%2Fcontainers%2Faks%2Fsecure-baseline-aks%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%5B5%5D%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Farchitecture%2Fframework%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Farchitecture%2Fframework%2F%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%5B6%5D%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fgovernance%2Fpolicy%2Fconcepts%2Fpolicy-for-kubernetes%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fgovernance%2Fpolicy%2Fconcepts%2Fpolicy-for-kubernetes%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%5B7%5D%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Farchitecture%2Freference-architectures%2Fcontainers%2Faks%2Fsecure-baseline-aks%23secure-the-network-flow%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Farchitecture%2Freference-architectures%2Fcontainers%2Faks%2Fsecure-baseline-aks%23secure-the-network-flow%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%5B8%5D%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-adoption-framework%2Fready%2Fenterprise-scale%2Fnetwork-topology-and-connectivity%23plan-for-inbound-and-outbound-internet-connectivity%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fcloud-adoption-framework%2Fready%2Fenterprise-scale%2Fnetwork-topology-and-connectivity%23plan-for-inbound-and-outbound-internet-connectivity%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1677941%22%20slang%3D%22en-US%22%3E%3CP%3EBuilding%20Azure%20landing%20zones%20means%20to%20leverage%20a%20scalable%2C%20modular%20approach%20to%20building%20out%20your%20environment%20based%20on%20a%20common%20set%20of%20design%20areas.%20Consequently%2C%20knowing%20and%20understanding%20the%20type%20of%20the%20application%20and%20workload%20(consequently%20called%20archetype)%20is%20important%2C%20as%20some%20of%20the%20Azure%20services%20do%20have%20specific%20requirements%20and%20platform%20dependencies.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1677941%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EApplication%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EApps%20%26amp%3B%20DevOps%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EInfrastructure%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

Building Azure landing zones means to leverage a scalable, modular approach to building out your environment based on a common set of design areas. Consequently, knowing and understanding the type of the application and workload (consequently called archetype) is important, as some of the Azure services do have specific requirements and platform dependencies.

The importance of the archetype also called out in the critical design areas, for example Red Hat OpenShift with regards to the DNS infrastructure.[1] Furthermore, this is also one of the reasons why you see different management groups below the landing zone management group.[2] In this specific case, which basically is the Contoso reference implementation, there are three specific landing zones: SAP, Corp and Online.

 

Figure 1: Proposed management group structure with the Contoso reference implementation.Figure 1: Proposed management group structure with the Contoso reference implementation.

 

From the Contoso reference implementation:[3]

  • Corp Landing Zones will include all Virtual Networks that do not expose public endpoints and that require connectivity to on-premises, as well as connectivity to other Landing Zones.
  • Online Landing Zones include all Virtual Networks that have internet-facing applications via an Azure Application Gateway (v2).
  • SAP represents a workload that merits separation given the implied specialization.

 

How to build archetype landing zones?

In order to build a landing zone for an used archetype, you need to understand all the specific requirements and dependencies. Unfortunately, there is no single place where you can find this information, but you need to gather this information for every Azure service used with this archetype.

However, a general recommendation is to leverage the Azure Architecture Center where you can find many useful information. One specific example I would like to mention is Azure Kubernetes Service (AKS) within the Architecture Center.[4]

In the AKS production baseline (reference architecture), you will find a baseline infrastructure that deploys an AKS cluster, with focus on security. The baseline includes recommendations for networking, security, identity, management, and monitoring of the cluster. Consequently, it’s aligned with the critical design areas in Enterprise-Scale.

Let’s look at one of the covered topics, which is networking security. The documented ingress and egress traffic flow are aligned with the recommendation you will find in Enterprise-Scale.[7][8] To be specific, using an Application Gateway and Web Application Firewall (WAF) to protect ingress traffic and use a Firewall, deployed in the (managed) hub, to protect egress traffic. But something that you will not find mentioned specifically in Enterprise-Scale are the recommended Azure Policy add-on for AKS.[6] Although policy-driven governance is one design principles in Enterprise-Scale, at this juncture you may have to build an AKS landing zone including all the required policy and also role configurations specifically addressing AKS. This may include network, storage, RBAC, and others.

 

Thus, in a nutshell, and also my personal approach (now independent of AKS):

  1. Assess the required archetype-specific policyDefinition, policyAssignments, roleDefinitions and roleAssignments.
  2. Assess whether there are overlaps with existing landing zones (management groups) and existing policyAssignments and roleAssignments.
  3. Assess whether a new dedicated management group, including the policyAssignments and roleAssignments, does not make the management more complicated (no need to create the same assignments on multiple management groups).

 

The role of Well-Architected Framework

The AKS production baseline mentioned above also follows the Azure Well-Architected Framework.[5] Though this is an AKS specific use case, all the deployed applications should follow the Well-Architected Framework, and therefore should address:

  • Cost optimization
  • Operation excellence
  • Performance efficiency
  • Reliability
  • Security

 

Or in other words: Enterprise-Scale provides the all important recommendations for the platform engineering, the Well-Architected Framework all important recommendations for applications and workloads.

 

[1] https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/ready/enterprise-scale/network-topol...

[2] https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/ready/enterprise-scale/management-gr...

[3] https://github.com/Azure/Enterprise-Scale/blob/main/docs/reference/contoso/Readme.md

[4] https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/containers/aks/secure-ba...

[5] https://docs.microsoft.com/en-us/azure/architecture/framework/

[6] https://docs.microsoft.com/en-us/azure/governance/policy/concepts/policy-for-kubernetes

[7] https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/containers/aks/secure-ba...

[8] https://docs.microsoft.com/en-us/azure/cloud-adoption-framework/ready/enterprise-scale/network-topol...