1---2name: azure-architecture-patterns3description: Well-Architected Framework principles and Azure best practices4---5
6# Azure Architecture Patterns
7
8
9> Well-Architected Framework principles, reference architectures, and Azure best practices.
10
11## The Five Pillars
12
13| Pillar | Focus | Key Question |
14|--------|-------|--------------|
15| Reliability | Resiliency, availability | Will it stay up? |
16| Security | Protection, compliance | Is it safe? |
17| Cost Optimization | Efficiency, value | Is it worth it? |
18| Operational Excellence | Manageability, observability | Can we run it? |
19| Performance Efficiency | Scalability, responsiveness | Is it fast enough? |
20
21## Reliability Patterns
22
23### Key Patterns
24
25- **Circuit Breaker**: Fail fast when downstream unhealthy (Polly)
26- **Retry with Backoff**: Handle transient failures with exponential delays
27- **Availability Zones**: Distribute across datacenters
28
29### Reliability Checklist
30
31- [ ] Single points of failure identified and mitigated
32- [ ] Health endpoints implemented (`/health`, `/ready`)
33- [ ] Retry policies with backoff
34- [ ] Circuit breakers for external dependencies
35- [ ] Availability zones utilized
36- [ ] RTO/RPO defined and tested
37
38## Security Patterns
39
40### Zero Trust
41
42| Principle | Implementation |
43|-----------|----------------|
44| Verify explicitly | Always authenticate/authorize |
45| Least privilege | Minimal necessary permissions |
46| Assume breach | Segment, encrypt, detect |
47
48### Identity
49
50- **Managed Identity**: Eliminate credential management
51- **RBAC**: Built-in roles, scope to resource group, use groups
52
53### Network
54
55- **Private Endpoints**: Keep traffic on Azure backbone
56- **NSG**: Default deny, explicit allow (priority 100-4096)
57
58### Security Checklist
59
60- [ ] Managed identities (no stored credentials)
61- [ ] Key Vault for secrets/certificates
62- [ ] Private endpoints for PaaS services
63- [ ] NSG rules deny-by-default
64- [ ] TLS 1.2+ enforced
65- [ ] Microsoft Defender enabled
66
67## Cost Optimization
68
69| Strategy | Impact |
70|----------|--------|
71| Right-size | Match SKU to workload |
72| Reserved Instances | 40-72% savings |
73| Spot VMs | 90% discount (interruptible) |
74| Auto-shutdown | Dev/test off at night |
75| Serverless | Pay per execution |
76
77### Compute Selection
78
79| Workload | Recommended |
80|----------|-------------|
81| Steady-state web | App Service Premium |
82| Event-driven | Azure Functions |
83| Batch processing | Container Apps + KEDA |
84| Big compute | Spot VMs + Batch |
85| Dev/test | B-series VMs |
86
87### Storage Tiers
88
89| Tier | Use Case | Cost |
90|------|----------|------|
91| Hot | Frequent access | ~$0.02/GB |
92| Cool | Infrequent (30+ days) | ~$0.01/GB |
93| Archive | Rarely accessed | ~$0.002/GB |
94
95### Cost Checklist
96
97- [ ] Azure Advisor recommendations reviewed
98- [ ] Reserved Instances for predictable workloads
99- [ ] Auto-shutdown for non-prod
100- [ ] Right-sized based on utilization
101- [ ] Storage lifecycle policies
102- [ ] Cost alerts and budgets set
103
104## Operational Excellence
105
106### IaC Tools
107
108| Tool | Best For |
109|------|----------|
110| Bicep | Azure-native, declarative |
111| Terraform | Multi-cloud, state management |
112| ARM | Legacy (avoid for new) |
113
114### Observability Stack
115
116| Layer | Service |
117|-------|---------|
118| Logs | Log Analytics |
119| Metrics | Azure Monitor |
120| Traces | Application Insights |
121| Alerts | Azure Alerts |
122| Dashboards | Azure Workbooks |
123
124### Operational Checklist
125
126- [ ] IaC for all resources (Bicep/Terraform)
127- [ ] CI/CD pipelines for deployment
128- [ ] Diagnostic settings to Log Analytics
129- [ ] Application Insights integrated
130- [ ] Alerts for critical metrics
131
132## Performance Efficiency
133
134### Scalability
135
136| Service | Mechanism |
137|---------|-----------|
138| App Service | Autoscale rules |
139| Azure Functions | Event-driven automatic |
140| AKS | HPA + Cluster Autoscaler |
141| VMSS | Autoscale rules |
142
143### Caching Strategy
144
145| Type | Use Case | Service |
146|------|----------|---------|
147| CDN | Static content | Azure Front Door |
148| Distributed | Session, computed | Redis Cache |
149| Local | Hot data | In-memory |
150
151### Performance Checklist
152
153- [ ] Autoscaling configured and tested
154- [ ] CDN for static content
155- [ ] Redis cache for hot data
156- [ ] Database indexes reviewed
157- [ ] Load testing completed
158
159## Reference Architectures
160
161### Web Application
162
163```
164Internet → Front Door → App Service → Azure SQL + Redis
165```
166
167### Microservices
168
169```
170Internet → API Management → AKS → Cosmos DB + Service Bus
171```
172
173### Serverless
174
175```
176Events → Event Grid → Functions → Cosmos DB + Storage
177```
178
179## SKU Selection
180
181| Series | Use Case |
182|--------|----------|
183| B-series | Dev/test (burstable) |
184| D-series | Most production |
185| E-series | Memory-optimized |
186| F-series | Compute-optimized |
187
188## Anti-Patterns
189
190| Anti-Pattern | Fix |
191|--------------|-----|
192| Monolithic deployment | Microservices or modular |
193| Hardcoded config | App Configuration, Key Vault |
194| Single region | Multi-region + Traffic Manager |
195| Over-provisioned | Right-size + autoscale |
196| No IaC | Bicep/Terraform everything |
197
198## MCP Tools Available
199
200| Tool | Use Case |
201|------|----------|
202| `mcp_azure_mcp_cloudarchitect` | Interactive architecture design |
203| `mcp_azure_mcp_documentation` | Search Azure docs |
204| `mcp_azure_mcp_get_bestpractices` | Code gen, deployment patterns |
205| Service-specific tools | AKS, App Service, Functions, Cosmos, SQL |