[Discussion]Azure's most appropriate architecture for big data sharing and utilization

%3CLINGO-SUB%20id%3D%22lingo-sub-1260840%22%20slang%3D%22en-US%22%3E%5BDiscussion%5DAzure's%20most%20appropriate%20architecture%20for%20big%20data%20sharing%20and%20utilization%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1260840%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20making%20this%20thread%20with%20a%20couple%20a%20questions%20which%20I%20hope%20could%20lead%20to%20a%20discussion%20with%20people%20whose%20knowledge%20in%20Azure%20or%20cloud%20service%20for%20big%20data%20in%20this%20site.%20so%2C%20the%20background%20is%20I%20want%20to%20make%20a%20system%20for%20my%20client%20which%20would%20make%20it%20possible%20for%20them%20to%20collect%20data%20from%20their%20products%20in%20one%20big%20pot%20in%20the%20cloud%20side.%20now%2C%20this%20system%20would%20be%20implemented%20on%20Azure%20with%20this%20kind%20of%20capability%20as%20target%20%3A%3C%2FP%3E%3COL%3E%3CLI%3Ethe%20data%20which%20has%20been%20collected%20will%20be%20separated%20per%20department%20(R%26amp%3BD%2C%20sales%2C%20HR%2C%20Production%2C%20and%20on).%20in%20principle%20a%20department%20would%20only%20have%20full%20authorization%20to%20read%20%26amp%3B%20write%20their%20own%20department's%20space%20and%20data%20but%20in%20some%20case%2C%20they%20could%20also%20have%20the%20authority%20to%20access%20specific%20data%20from%20another%20departments%20space%20after%20they%20got%20the%20permission%20from%20the%20department's%20admin%3C%2FLI%3E%3CLI%3Ethe%20collected%20data%20access%20tiers%20would%20be%20changed%20with%20rules%20after%20the%20latest%20date%20of%20it%20was%20accessed%2C%20but%20also%20possible%20for%20the%20user%20to%20change%20it%20manually%3C%2FLI%3E%3CLI%3Ethe%20data%20lake%20for%20this%20system%20would%20have%20enough%20security%20for%20highly%20classified%20data%20and%20personal%20information.%3C%2FLI%3E%3C%2FOL%3E%3CP%3Eso%20after%20reading%20some%20book%20and%20information%20about%20azure%2C%20I'm%20thinking%20an%20architecture%20which%20looks%20like%20this%3A%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22archi.jpg%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F180118iF2F6BADA8EEFE697%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20title%3D%22archi.jpg%22%20alt%3D%22archi.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ein%20this%20architecture%2C%20I'm%20thinking%203%20steps%20are%20available%20for%20the%20service%3A%3C%2FP%3E%3COL%3E%3CLI%3Edata%20input%20%3A%20data%20from%20another%20service%20or%20local%20server%20would%20be%20collected%20into%20azure.%20if%20the%20data%20size%20big%20and%20my%20client%20network%20capacity%20is%20not%20enough%20to%20handle%20it%20I'm%20thinking%20to%20use%20Data%20Box%20to%20upload%20the%20data.%20while%20if%20my%20client%20network%20has%20to%20capacity%20to%20upload%20all%20data%20that%20they%20have%2C%20I%20would%20use%20Data%20Factory.%20while%20for%20small%20size%20data%2C%20they%20could%20upload%20it%20directly%20from%20Storage%20Explorer.%20and%20of%20course%2C%20Database%20Migration%20to%20migrate%20their%20DB%20to%20azure.%3C%2FLI%3E%3CLI%3Edata%20storage%20%3A%20I'm%20using%20Azure%20Storage%20for%20non-relational%20data%20with%20a%20file%20like%20CSV%20and%20log%20mainly%2C%20and%20SQL%20database%20for%20their%20relational%20DB.%20with%20Azure%20storage%20I%20could%20also%20set%20rules%20to%20change%20my%20file%20access%20tiers%20automatically.%3C%2FLI%3E%3CLI%3Edata%20access%20%3A%20my%20client%20will%20access%20this%20system%20through%20their%20PC%2C%20with%20A%20web%20apps%20hosted%20on%20App%20Sevices%20as%20their%20UI.%20to%20access%20into%20this%20UI%20they%20will%20first%20do%20an%20authentication%20process%20with%20their%20ADID%20and%20from%20there%2C%20my%20system%20would%20get%20the%20user%20department%20and%20only%20showing%20each%20user%20access-allowed%20space%20and%20files.%20here%20is%20where%20the%20first%20target%20function%20will%20be%20achieved.%20user%20will%20also%20have%20some%20access%20request%20function%20on%20this%20UI%20to%20ask%20for%20permission%20to%20another%20dept%20space%20or%20files.%20and%20user%20with%20Admin%20privilege%20would%20be%20able%20to%20accept%20or%20decline%20this%20request.%20not%20only%20that%2C%20but%20admin%20would%20also%20have%20the%20privilege%20to%20change%20each%20files%20access%20tiers%20manually.%3C%2FLI%3E%3C%2FOL%3E%3CP%3Enow%2C%20these%20are%20the%20questions%20that%20I%20want%20to%20discuss%20%3A%3C%2FP%3E%3COL%3E%3CLI%3Eis%20this%20architecture%20appropriate%20for%20big%20data%20service%20and%20utilization%3Fif%20not%2C%20what%20kind%20of%20thing%20that%20I%20am%20missing%3F%3C%2FLI%3E%3CLI%3Efor%20most%20of%20the%20data%20access%2C%20I'm%20mainly%20thinking%20to%20build%20an%20app%20from%20scratch.%20but%20is%20there%20any%20service%20in%20Azure%2C%20or%20that%20could%20be%20integrated%20to%20Azure%20to%20do%20this%20kind%20of%20function%3F%3C%2FLI%3E%3CLI%3Ewhat%20kind%20of%20security%20that%20usually%20you%20set%20for%20this%20kind%20of%20service%20with%20highly%20confidential%20and%20personal%20information%20data%3F%3C%2FLI%3E%3CLI%3Eis%20it%20possible%20for%20azure%20to%20calculate%20each%20departments%20member%20access%20so%20we%20could%20know%20which%20department%20is%20highly%20using%20the%20services%3F%3C%2FLI%3E%3C%2FOL%3E%3CP%3Ebests%2C%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1260840%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Resource%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EData%20%2B%20Storage%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMonitoring%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EProtection%20%26amp%3B%20Recovery%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%20%26amp%3B%20Compliance%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Occasional Contributor

I'm making this thread with a couple a questions which I hope could lead to a discussion with people whose knowledge in Azure or cloud service for big data in this site. so, the background is I want to make a system for my client which would make it possible for them to collect data from their products in one big pot in the cloud side. now, this system would be implemented on Azure with this kind of capability as target :

  1. the data which has been collected will be separated per department (R&D, sales, HR, Production, and on). in principle a department would only have full authorization to read & write their own department's space and data but in some case, they could also have the authority to access specific data from another departments space after they got the permission from the department's admin
  2. the collected data access tiers would be changed with rules after the latest date of it was accessed, but also possible for the user to change it manually
  3. the data lake for this system would have enough security for highly classified data and personal information.

so after reading some book and information about azure, I'm thinking an architecture which looks like this:

archi.jpg

 

in this architecture, I'm thinking 3 steps are available for the service:

  1. data input : data from another service or local server would be collected into azure. if the data size big and my client network capacity is not enough to handle it I'm thinking to use Data Box to upload the data. while if my client network has to capacity to upload all data that they have, I would use Data Factory. while for small size data, they could upload it directly from Storage Explorer. and of course, Database Migration to migrate their DB to azure.
  2. data storage : I'm using Azure Storage for non-relational data with a file like CSV and log mainly, and SQL database for their relational DB. with Azure storage I could also set rules to change my file access tiers automatically.
  3. data access : my client will access this system through their PC, with A web apps hosted on App Sevices as their UI. to access into this UI they will first do an authentication process with their ADID and from there, my system would get the user department and only showing each user access-allowed space and files. here is where the first target function will be achieved. user will also have some access request function on this UI to ask for permission to another dept space or files. and user with Admin privilege would be able to accept or decline this request. not only that, but admin would also have the privilege to change each files access tiers manually.

now, these are the questions that I want to discuss :

  1. is this architecture appropriate for big data service and utilization?if not, what kind of thing that I am missing?
  2. for most of the data access, I'm mainly thinking to build an app from scratch. but is there any service in Azure, or that could be integrated to Azure to do this kind of function?
  3. what kind of security that usually you set for this kind of service with highly confidential and personal information data?
  4. is it possible for azure to calculate each departments member access so we could know which department is highly using the services?

bests,

0 Replies