🏗️ Step 2: Architecture Assessment - pci-dss-gw
Generated by @architect agent | 2026-02-09
| ⬅️ Previous |
📑 Index |
Next ➡️ |
| 01-requirements.md |
README |
03-des-cost-estimate.md |
✅ Requirements Validation
| Requirement |
Status |
Notes |
| 10,000 TPS sustained, 15,000 TPS peak |
✅ Validated |
AKS with D8s_v5 nodes (3-20) supports horizontal scaling via KEDA |
| 99.99% SLA |
✅ Validated |
Zone-redundant AKS + PostgreSQL HA + Cosmos DB multi-AZ achieves composite SLA |
| P50 ≤ 100 ms, P99 ≤ 500 ms |
✅ Validated |
AKS in-cluster networking + Cosmos DB sub-10ms reads + PostgreSQL ≤ 20ms |
| PCI-DSS v4.0 Level 1 |
✅ Validated |
AKS dedicated node pools, network policies, Firewall Premium IDPS, Key Vault HSM |
| GDPR / EU data residency |
✅ Validated |
swedencentral primary, germanywestcentral failover — both EU |
| PostgreSQL for ACID transactions |
✅ Validated |
Flexible Server Memory Optimized E16s v5, zone-redundant HA |
| Cosmos DB for session/cache |
✅ Validated |
NoSQL API with Session consistency, autoscale RU/s |
| AKS over ACA |
✅ Validated |
PCI CDE isolation requires dedicated node pools + Kubernetes network policies |
| Hub-spoke with Azure Firewall |
✅ Validated |
Premium tier for IDPS, east-west traffic inspection per PCI-DSS Req 1 |
| DDoS Network Protection |
✅ Validated |
Full VNet coverage for CDE — $2,944/mo |
| API Management Premium |
✅ Validated |
VNet-integrated for CDE, OAuth, rate limiting — $2,795/mo |
| Budget range validated |
⚠️ Adjusted |
Revised to $16,200 – $27,800/mo with all services included |
[!IMPORTANT]
All critical requirements from 01-requirements.md are architecturally feasible. Budget has been refined with live Azure Pricing MCP data.
💎 Executive Summary
Architecture Overview
This is a PCI-DSS Level 1 payment gateway on Azure, designed for 10,000 TPS sustained throughput with 99.99% availability. The architecture follows a hub-spoke network topology with AKS as the compute platform, PostgreSQL Flexible Server for transactional data, and Cosmos DB for low-latency session state.
Primary Optimization Pillar
Security — PCI-DSS v4.0 Level 1 compliance drives architectural decisions. All other pillars are optimized within PCI constraints.
Architecture Pattern
| Attribute |
Value |
| Pattern |
Hub-Spoke with Dedicated CDE |
| Compute |
AKS Standard tier with zone-redundant node pools |
| Data Tier |
PostgreSQL Flexible Server (ACID) + Cosmos DB (cache/session) |
| Network Edge |
Azure Front Door Premium (WAF + DDoS) → Azure Firewall Premium (IDPS) → AKS |
| API Layer |
API Management Premium (VNet-integrated) |
| Messaging |
Service Bus Premium (dedicated capacity) |
| Secrets |
Key Vault Premium (HSM-backed) |
| Identity |
Entra ID + Workload Identity + PIM |
| Monitoring |
Azure Monitor + Log Analytics (1-year retention) + Defender for Cloud |
Key Architecture Decisions
| Decision |
Choice |
Rationale |
| Compute platform |
AKS over ACA |
PCI CDE isolation via dedicated node pools, Kubernetes network policies, OPA Gatekeeper |
| Database strategy |
Dual DB (PostgreSQL + Cosmos DB) |
ACID for transactions + sub-10ms for session/cache; reduces PostgreSQL connection pressure |
| Network segmentation |
Hub-spoke + Azure Firewall Premium |
IDPS required for PCI-DSS Req 1; east-west inspection between CDE and non-CDE |
| API gateway |
APIM Premium (VNet) + Front Door Premium |
VNet integration keeps API gateway inside CDE; Front Door provides global WAF + DDoS |
| Cosmos DB consistency |
Session consistency |
Sufficient for session state; avoids Strong consistency latency penalty while ensuring read-your-writes |
| Multi-region strategy |
Active-Passive |
Minimizes cost and Cosmos DB complexity; RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup |
🏛️ WAF Pillar Assessment
🔒 Security — 9/10 (Confidence: High)
| Area |
Score |
Assessment |
| Identity & Access |
9/10 |
Entra ID + Workload Identity for all service-to-service auth. PIM for JIT admin access. No shared accounts or passwords. |
| Network Security |
9/10 |
Hub-spoke with Azure Firewall Premium (IDPS), NSGs, AKS network policies. Private endpoints for all data services. No public endpoints for CDE. |
| Data Protection |
9/10 |
AES-256 encryption at rest with CMK for cardholder data. TLS 1.2+ everywhere. Key Vault Premium (HSM) for cryptographic keys. Tokenization for PAN. |
| Threat Detection |
8/10 |
Defender for Containers, Defender for Cloud, Azure Firewall IDPS. Container image scanning pre-deployment. |
| Compliance |
9/10 |
PCI-DSS v4.0 controls mapped to Azure services. 1-year log retention. Tamper-proof audit trail via Log Analytics. |
Strengths: Comprehensive PCI-DSS control mapping. Zero-trust architecture with managed identity everywhere. HSM-backed key management.
Gaps:
- Penetration testing schedule not yet defined (PCI Req 11)
- QSA validation of Azure Firewall IDPS as acceptable IDS/IPS control is pending
Recommendations:
- Schedule quarterly penetration tests with a PCI-certified ASV
- Implement Azure Policy deny rules for non-compliant configurations
- Enable Defender for Key Vault for anomaly detection on cryptographic operations
🔄 Reliability — 8/10 (Confidence: High)
| Area |
Score |
Assessment |
| High Availability |
9/10 |
Zone-redundant AKS (3 AZs), PostgreSQL zone-redundant HA, Cosmos DB multi-AZ. Front Door global anycast. |
| Disaster Recovery |
7/10 |
Active-passive to germanywestcentral. PostgreSQL geo-redundant backup (RPO ≤ 5 min). Manual failover process. |
| Resilience |
8/10 |
KEDA autoscaling, pod disruption budgets, Service Bus dead-letter queues, idempotent transaction processing. |
| Health Monitoring |
8/10 |
Liveness/readiness probes, Azure Monitor alerts, Defender continuous monitoring. Sub-minute alerting. |
Strengths: Zone-redundant deployment across all tiers. Idempotent transaction design prevents duplicate charges. Service Bus DLQ handles transient failures.
Gaps:
- Active-passive failover is manual — RTO ≤ 30 min depends on operator response time
- Cosmos DB failover to germanywestcentral is not yet configured
- No documented chaos engineering / game day testing plan
Recommendations:
- Implement automated failover runbook with Azure Automation for RTO ≤ 15 min
- Configure Cosmos DB multi-region with germanywestcentral as read-replica (can promote on failover)
- Schedule quarterly chaos engineering tests (AKS node drain, zone failure simulation)
Composite SLA Calculation:
| Service |
SLA |
Zone-Redundant |
| AKS Standard |
99.95% |
99.99% (with AZs) |
| PostgreSQL Flex HA |
99.99% |
Yes |
| Cosmos DB (single-region) |
99.99% |
Yes |
| Front Door Premium |
99.99% |
Global |
| Azure Firewall |
99.99% |
Yes (with AZs) |
| Key Vault |
99.99% |
Yes |
| Service Bus Premium |
99.99% |
Yes |
Composite SLA: 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% = 99.93%
[!WARNING]
Composite SLA (99.93%) is below the 99.99% target. To achieve 99.99%, implement multi-region active-active for the most critical path (Front Door → AKS → PostgreSQL) or accept 99.95%+ with strong DR automation.
⚡ Performance — 8/10 (Confidence: Medium)
| Area |
Score |
Assessment |
| Throughput |
8/10 |
AKS D8s_v5 nodes (8 vCPU, 32 GB) with KEDA autoscaling. 3-20 nodes supports 10-15k TPS. PgBouncer for connection pooling. |
| Latency |
8/10 |
In-region P50 ≤ 100ms achievable. Cosmos DB session reads ≤ 10ms. PostgreSQL ≤ 20ms with connection pooling. |
| Scalability |
8/10 |
Horizontal pod autoscaling + cluster autoscaler. Cosmos DB autoscale RU/s. PostgreSQL read replicas for reporting. |
| Caching |
7/10 |
Cosmos DB for session/cache. No dedicated Redis layer — may need for response caching under extreme load. |
Strengths: KEDA enables event-driven scaling tied to Service Bus queue depth. Dual-database architecture offloads read-heavy cache operations from PostgreSQL.
Gaps:
- No dedicated Redis cache for API response caching — Cosmos DB may add latency vs. Redis for hot-path caching
- Load testing plan not yet defined to validate 15k TPS peak
- PgBouncer configuration (pool size, mode) needs tuning for 10k TPS
Recommendations:
- Conduct Azure Load Testing at 15k TPS to validate node count and latency targets
- Consider Azure Cache for Redis (Enterprise, 6 GB) as a hot-path cache if Cosmos DB latency exceeds targets under load
- Configure PgBouncer in transaction mode with pool_size = 200 per pod
💰 Cost — 7/10 (Confidence: Medium)
| Area |
Score |
Assessment |
| Right-Sizing |
7/10 |
D8s_v5 nodes are appropriate for 10k TPS. PostgreSQL E16s v5 may be oversized initially. |
| Optimization |
7/10 |
Reserved instances recommended but not yet committed. Cosmos DB autoscale prevents over-provisioning. |
| Monitoring |
7/10 |
Cost alerts should be configured. No FinOps process documented. |
| Waste Prevention |
6/10 |
Dev/staging environments could use smaller SKUs. Spot nodes viable for non-CDE workloads. |
Estimated Monthly Cost (from Azure Pricing MCP — swedencentral):
| Category |
Service |
SKU |
Unit Price |
Monthly Cost |
| 💻 Compute (AKS management) |
AKS Standard |
Standard |
$0.60/hr |
$438 |
| 💻 Compute (AKS nodes × 6 avg) |
D8s_v5 Linux |
Standard_D8s_v5 |
~$0.408/hr |
$1,787 |
| 💾 Database (Primary) |
PostgreSQL Flex Server |
Memory Opt E16s v5 (16 vCores) |
$2.056/hr |
$1,501 |
| 💾 Database (Cache) |
Cosmos DB NoSQL |
Autoscale 10K-50K RU/s |
$0.012/hr per 100 RU/s |
$876 – $4,380 |
| 🔐 Security |
Key Vault Premium |
HSM-backed |
$0.03/10K ops |
$22+ |
| 🌐 Network |
Azure Firewall Premium |
Premium |
$1.75/hr |
$1,278 |
| 🌐 Network |
Azure Front Door |
Premium |
~$330 base + per-request |
$500 – $1,200 |
| 🛡️ DDoS |
DDoS Network Protection |
Standard |
Fixed monthly |
$2,944 |
| 🔀 API Gateway |
API Management |
Premium (1 unit) |
$3.829/hr |
$2,795 |
| 📊 Monitoring |
Log Analytics |
Per-GB ingestion |
$2.99/GB |
$300 – $1,500 |
| 📦 Container Registry |
ACR Premium |
Premium |
$0.333/day |
$10+ |
| 📨 Messaging |
Service Bus |
Premium (1 MU) |
$0.9275/hr |
$677 |
| 👤 Identity |
Entra ID P2 + PIM |
Per-user |
— |
$200 – $500 |
|
TOTAL |
|
|
$13,328 – $19,032 |
[!NOTE]
💰 Prices sourced from Azure Pricing MCP (swedencentral, 2026-02-09). Production with full HA (20 nodes, max Cosmos RU/s) could reach ~$27,800/mo. Reserved Instances (1-year) save ~35% on compute and PostgreSQL.
Savings Opportunities:
| Opportunity |
Est. Savings |
Effort |
| 1-year Reserved Instances (AKS nodes + PostgreSQL) |
35% on compute ($1,150/mo) |
Low |
| Spot nodes for non-CDE workloads (dev/test) |
Up to 80% on dev compute |
Medium |
| Cosmos DB autoscale floor (scale to zero off-peak) |
20-60% variable |
Low |
| Log Analytics Commitment Tier (100 GB/day) |
~30% on ingestion |
Low |
| Start with APIM Standard v2 → upgrade to Premium later |
~$2,100/mo initially |
Medium — requires re-architecture for VNet |
🔧 Operations — 8/10 (Confidence: High)
| Area |
Score |
Assessment |
| IaC |
9/10 |
Bicep with Azure Verified Modules. GitOps for AKS config. Repeatable, auditable deployments. |
| CI/CD |
8/10 |
GitHub Actions with blue-green deployment. Container image scanning in pipeline. Automated rollback. |
| Monitoring |
8/10 |
Azure Monitor + Application Insights + Defender. Distributed tracing. Alert thresholds defined. |
| Incident Response |
7/10 |
On-call rotation assumed but not documented. Runbook templates needed. |
| Documentation |
7/10 |
Requirements doc comprehensive. Operations runbook, DR plan needed before go-live. |
Strengths: Full IaC approach with Bicep/AVM. Blue-green deployment minimizes downtime. Container scanning gates prevent vulnerable images.
Gaps:
- No documented incident response playbook specific to payment failures
- Runbook for database failover not yet created
- Change management process for PCI CDE changes undefined
Recommendations:
- Create payment transaction failure runbook with escalation paths
- Document CDE change management process for PCI-DSS Req 6 compliance
- Implement GitOps (Flux v2) for AKS workload deployments with audit trail
📦 Resource SKU Recommendations
| Resource |
Recommended SKU |
Region |
Justification |
| AKS |
Standard tier, D8s_v5 nodes |
swedencentral |
8 vCPU/32 GB per node. Standard tier required for financial SLA. Zone-redundant node pools. |
| PostgreSQL Flexible Server |
Memory Optimized E16s v5, 16 vCores |
swedencentral |
Memory-optimized for write-heavy payment transactions. Zone-redundant HA. |
| Cosmos DB |
NoSQL API, Autoscale 10K-50K RU/s |
swedencentral |
Session consistency. Autoscale handles variable session/cache load. |
| Azure Firewall |
Premium |
swedencentral |
IDPS capability required for PCI-DSS network segmentation. |
| Azure Front Door |
Premium |
Global |
WAF with OWASP 3.2, bot protection, DDoS at edge. |
| API Management |
Premium (1 unit) |
swedencentral |
VNet integration required for CDE. OAuth, rate limiting per merchant. |
| Key Vault |
Premium (HSM-backed) |
swedencentral |
PCI-DSS requires HSM for cryptographic key storage. |
| Service Bus |
Premium (1 Messaging Unit) |
swedencentral |
Dedicated capacity for transaction queues. Dead-letter support. |
| Container Registry |
Premium |
swedencentral |
Geo-replication to failover region. Vulnerability scanning. Content trust. |
| Log Analytics |
Per-GB (Analytics Logs) |
swedencentral |
$2.99/GB. 1-year retention for PCI-DSS § 10.7. |
| DDoS Protection |
Network Protection (Standard) |
swedencentral |
Full VNet coverage for CDE network. $2,944/mo fixed. |
Service Maturity Assessment
| Service |
GA Status |
AVM Module |
Notes |
| AKS |
GA |
br/public:avm/res/container-service/managed-cluster |
Production-ready, well-documented PCI guidance |
| PostgreSQL Flexible Server |
GA |
Available |
Zone-redundant HA, read replicas GA |
| Cosmos DB NoSQL |
GA |
br/public:avm/res/document-db/database-account |
Autoscale GA, PITR GA |
| Azure Firewall Premium |
GA |
Available |
IDPS GA, TLS inspection GA |
| Azure Front Door Premium |
GA |
br/public:avm/res/cdn/profile |
WAF policies GA |
| API Management Premium |
GA |
Available |
VNet integration GA |
| Key Vault Premium |
GA |
br/public:avm/res/key-vault/vault |
HSM-backed keys GA |
| Service Bus Premium |
GA |
br/public:avm/res/service-bus/namespace |
Zone-redundant GA |
| DDoS Network Protection |
GA |
Available |
Standard tier GA |
| Container Registry Premium |
GA |
br/public:avm/res/container-registry/registry |
Geo-replication GA |
[!TIP]
All recommended services are Generally Available (GA) with Azure Verified Modules where available. No preview or deprecated services in this architecture.
🎯 Architecture Decision Summary
| # |
Decision |
Options Considered |
Choice |
Rationale |
| ADR-001 |
Compute Platform |
AKS vs. ACA |
AKS |
PCI CDE requires dedicated node pools, Kubernetes network policies, OPA Gatekeeper. ACA lacks node-level isolation. |
| ADR-002 |
Database Strategy |
PostgreSQL-only vs. PostgreSQL + Cosmos DB |
Dual DB |
Offloads session/cache reads from PostgreSQL. Reduces connection pressure at 10k TPS. Sub-10ms cache reads. |
| ADR-003 |
Network Topology |
Flat VNet vs. Hub-Spoke |
Hub-Spoke |
PCI-DSS Req 1 requires network segmentation. Azure Firewall Premium provides IDPS + east-west inspection. |
| ADR-004 |
API Gateway |
Front Door only vs. Front Door + APIM |
Front Door + APIM |
Front Door for WAF/DDoS at edge. APIM Premium for VNet-integrated API management inside CDE. |
| ADR-005 |
Cosmos DB Consistency |
Strong vs. Session vs. Eventual |
Session |
Read-your-writes for session state. Avoids Strong consistency latency penalty. Sufficient for cache/session use case. |
| ADR-006 |
Multi-Region |
Active-Active vs. Active-Passive |
Active-Passive |
Lower cost and complexity. RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup. Active-Active adds Cosmos DB multi-region write cost. |
| ADR-007 |
DDoS Protection |
IP Protection vs. Network Protection |
Network Protection |
Full VNet coverage for CDE. Higher cost ($2,944/mo) but covers all public IPs and provides advanced telemetry. |
| ADR-008 |
Connection Pooling |
PgBouncer vs. Azure-native |
PgBouncer sidecar |
Required at 10k TPS to prevent PostgreSQL connection exhaustion. Transaction mode with pool_size=200/pod. |
🚀 Implementation Handoff
For Bicep Plan Agent
- Network: Hub VNet (firewall, bastion) + Spoke VNet (AKS, PostgreSQL, Cosmos DB, APIM). Private endpoints for all data services.
- Compute: AKS with system node pool (D4s_v5 × 3) + user CDE node pool (D8s_v5 × 3-20). KEDA add-on. Workload Identity.
- Data: PostgreSQL Flexible Server E16s v5 zone-redundant HA. Cosmos DB NoSQL autoscale 10K-50K RU/s.
- Security: Key Vault Premium. Azure Firewall Premium. NSGs on all subnets. AKS network policies (Calico).
- Edge: Front Door Premium + WAF policy. APIM Premium VNet-integrated.
- Messaging: Service Bus Premium 1 MU.
- Monitoring: Log Analytics workspace (1-year retention) + Application Insights + Defender for Cloud + Defender for Containers.
- DDoS: Network Protection on hub VNet.
- Identity: Managed identities for all service-to-service. Workload Identity for AKS pods. PIM for admin access.
AVM Modules to Use
| Resource |
AVM Module |
Min Version |
| AKS |
br/public:avm/res/container-service/managed-cluster |
Latest |
| Key Vault |
br/public:avm/res/key-vault/vault |
0.11.0 |
| Cosmos DB |
br/public:avm/res/document-db/database-account |
0.10.0 |
| Service Bus |
br/public:avm/res/service-bus/namespace |
0.10.0 |
| Container Registry |
br/public:avm/res/container-registry/registry |
0.6.0 |
| Virtual Network |
br/public:avm/res/network/virtual-network |
0.5.0 |
| NSG |
br/public:avm/res/network/network-security-group |
0.5.0 |
| Log Analytics |
br/public:avm/res/operational-insights/workspace |
0.9.0 |
| Front Door |
br/public:avm/res/cdn/profile |
0.7.0 |
Required Tags
tags: {
Environment: environment // 'dev' | 'staging' | 'prod'
ManagedBy: 'Bicep'
Project: 'pci-dss-gw'
Owner: '<to-be-confirmed>'
}
🔒 Approval Gate
| Pillar |
Score |
Confidence |
| 🔒 Security |
9/10 |
High |
| 🔄 Reliability |
8/10 |
High |
| ⚡ Performance |
8/10 |
Medium |
| 💰 Cost |
7/10 |
Medium |
| 🔧 Operations |
8/10 |
High |
| Composite WAF Score |
8.0/10 |
|
Estimated Monthly Cost: $13,328 – $19,032 (typical prod), up to ~$27,800 at peak scale
[!IMPORTANT]
⚠️ Composite SLA (99.93%) is slightly below 99.99% target. Mitigation: implement automated DR runbook to achieve operational SLA ≥ 99.99% with rapid failover. Alternatively, accept 99.95%+ with strong DR automation.
Top Risks:
- Composite SLA gap — mitigate with multi-region or accept 99.95%
- DDoS + APIM Premium are large fixed costs ($5,739/mo combined) — validate necessity with QSA
- Load testing not yet conducted — 15k TPS peak is untested assumption
Reply "approve" to proceed to bicep-plan, or provide feedback.
References
[!NOTE]
📚 The following Microsoft Learn resources provide additional guidance.
Generated by Azure Agentic InfraOps | GitHub
1---2name: step-2-architecture-assessment-pci-dss-gw3description: This is a PCI-DSS Level 1 payment gateway on Azure, designed for 10,000 TPS sustained throughput with 99.99% availability.4---5# 🏗️ Step 2: Architecture Assessment - pci-dss-gw67891011<details open>12<summary><strong>📑 Assessment Overview</strong></summary>1314- [✅ Requirements Validation](#-requirements-validation)15- [📎 Executive Summary](#-executive-summary)16- [🏗️ WAF Pillar Assessment](#-waf-pillar-assessment)17- [📦 Resource SKU Recommendations](#-resource-sku-recommendations)18- [🎯 Architecture Decision Summary](#-architecture-decision-summary)19- [🚀 Implementation Handoff](#-implementation-handoff)20- [🔒 Approval Gate](#-approval-gate)21- [References](#references)2223</details>2425> Generated by @architect agent | 2026-02-092627| ⬅️ Previous | 📑 Index | Next ➡️ |28| ---------------------------------------- | ------------------- | -------------------------------------------------- |29| [01-requirements.md](01-requirements.md) | [README](README.md) | [03-des-cost-estimate.md](03-des-cost-estimate.md) |3031---3233## ✅ Requirements Validation3435| Requirement | Status | Notes |36| ------------------------------------- | ------------ | -------------------------------------------------------------------------------- |37| 10,000 TPS sustained, 15,000 TPS peak | ✅ Validated | AKS with D8s_v5 nodes (3-20) supports horizontal scaling via KEDA |38| 99.99% SLA | ✅ Validated | Zone-redundant AKS + PostgreSQL HA + Cosmos DB multi-AZ achieves composite SLA |39| P50 ≤ 100 ms, P99 ≤ 500 ms | ✅ Validated | AKS in-cluster networking + Cosmos DB sub-10ms reads + PostgreSQL ≤ 20ms |40| PCI-DSS v4.0 Level 1 | ✅ Validated | AKS dedicated node pools, network policies, Firewall Premium IDPS, Key Vault HSM |41| GDPR / EU data residency | ✅ Validated | swedencentral primary, germanywestcentral failover — both EU |42| PostgreSQL for ACID transactions | ✅ Validated | Flexible Server Memory Optimized E16s v5, zone-redundant HA |43| Cosmos DB for session/cache | ✅ Validated | NoSQL API with Session consistency, autoscale RU/s |44| AKS over ACA | ✅ Validated | PCI CDE isolation requires dedicated node pools + Kubernetes network policies |45| Hub-spoke with Azure Firewall | ✅ Validated | Premium tier for IDPS, east-west traffic inspection per PCI-DSS Req 1 |46| DDoS Network Protection | ✅ Validated | Full VNet coverage for CDE — $2,944/mo |47| API Management Premium | ✅ Validated | VNet-integrated for CDE, OAuth, rate limiting — $2,795/mo |48| Budget range validated | ⚠️ Adjusted | Revised to $16,200 – $27,800/mo with all services included |4950> [!IMPORTANT]51> All critical requirements from `01-requirements.md` are architecturally feasible. Budget has been refined with live Azure Pricing MCP data.5253---5455## 💎 Executive Summary5657### Architecture Overview5859This is a **PCI-DSS Level 1 payment gateway** on Azure, designed for 10,000 TPS sustained throughput with 99.99% availability. The architecture follows a **hub-spoke network topology** with AKS as the compute platform, PostgreSQL Flexible Server for transactional data, and Cosmos DB for low-latency session state.6061### Primary Optimization Pillar6263**Security** — PCI-DSS v4.0 Level 1 compliance drives architectural decisions. All other pillars are optimized within PCI constraints.6465### Architecture Pattern6667| Attribute | Value |68| ---------------- | --------------------------------------------------------------------------- |69| **Pattern** | Hub-Spoke with Dedicated CDE |70| **Compute** | AKS Standard tier with zone-redundant node pools |71| **Data Tier** | PostgreSQL Flexible Server (ACID) + Cosmos DB (cache/session) |72| **Network Edge** | Azure Front Door Premium (WAF + DDoS) → Azure Firewall Premium (IDPS) → AKS |73| **API Layer** | API Management Premium (VNet-integrated) |74| **Messaging** | Service Bus Premium (dedicated capacity) |75| **Secrets** | Key Vault Premium (HSM-backed) |76| **Identity** | Entra ID + Workload Identity + PIM |77| **Monitoring** | Azure Monitor + Log Analytics (1-year retention) + Defender for Cloud |7879### Key Architecture Decisions8081| Decision | Choice | Rationale |82| --------------------- | ---------------------------------------- | ------------------------------------------------------------------------------------------------------- |83| Compute platform | AKS over ACA | PCI CDE isolation via dedicated node pools, Kubernetes network policies, OPA Gatekeeper |84| Database strategy | Dual DB (PostgreSQL + Cosmos DB) | ACID for transactions + sub-10ms for session/cache; reduces PostgreSQL connection pressure |85| Network segmentation | Hub-spoke + Azure Firewall Premium | IDPS required for PCI-DSS Req 1; east-west inspection between CDE and non-CDE |86| API gateway | APIM Premium (VNet) + Front Door Premium | VNet integration keeps API gateway inside CDE; Front Door provides global WAF + DDoS |87| Cosmos DB consistency | Session consistency | Sufficient for session state; avoids Strong consistency latency penalty while ensuring read-your-writes |88| Multi-region strategy | Active-Passive | Minimizes cost and Cosmos DB complexity; RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup |8990---9192## 🏛️ WAF Pillar Assessment9394### 🔒 Security — 9/10 (Confidence: High)9596| Area | Score | Assessment |97| --------------------- | ----- | --------------------------------------------------------------------------------------------------------------------------------------------------- |98| **Identity & Access** | 9/10 | Entra ID + Workload Identity for all service-to-service auth. PIM for JIT admin access. No shared accounts or passwords. |99| **Network Security** | 9/10 | Hub-spoke with Azure Firewall Premium (IDPS), NSGs, AKS network policies. Private endpoints for all data services. No public endpoints for CDE. |100| **Data Protection** | 9/10 | AES-256 encryption at rest with CMK for cardholder data. TLS 1.2+ everywhere. Key Vault Premium (HSM) for cryptographic keys. Tokenization for PAN. |101| **Threat Detection** | 8/10 | Defender for Containers, Defender for Cloud, Azure Firewall IDPS. Container image scanning pre-deployment. |102| **Compliance** | 9/10 | PCI-DSS v4.0 controls mapped to Azure services. 1-year log retention. Tamper-proof audit trail via Log Analytics. |103104**Strengths**: Comprehensive PCI-DSS control mapping. Zero-trust architecture with managed identity everywhere. HSM-backed key management.105106**Gaps**:107108- Penetration testing schedule not yet defined (PCI Req 11)109- QSA validation of Azure Firewall IDPS as acceptable IDS/IPS control is pending110111**Recommendations**:1121131. Schedule quarterly penetration tests with a PCI-certified ASV1142. Implement Azure Policy deny rules for non-compliant configurations1153. Enable Defender for Key Vault for anomaly detection on cryptographic operations116117---118119### 🔄 Reliability — 8/10 (Confidence: High)120121| Area | Score | Assessment |122| --------------------- | ----- | ------------------------------------------------------------------------------------------------------------- |123| **High Availability** | 9/10 | Zone-redundant AKS (3 AZs), PostgreSQL zone-redundant HA, Cosmos DB multi-AZ. Front Door global anycast. |124| **Disaster Recovery** | 7/10 | Active-passive to germanywestcentral. PostgreSQL geo-redundant backup (RPO ≤ 5 min). Manual failover process. |125| **Resilience** | 8/10 | KEDA autoscaling, pod disruption budgets, Service Bus dead-letter queues, idempotent transaction processing. |126| **Health Monitoring** | 8/10 | Liveness/readiness probes, Azure Monitor alerts, Defender continuous monitoring. Sub-minute alerting. |127128**Strengths**: Zone-redundant deployment across all tiers. Idempotent transaction design prevents duplicate charges. Service Bus DLQ handles transient failures.129130**Gaps**:131132- Active-passive failover is manual — RTO ≤ 30 min depends on operator response time133- Cosmos DB failover to germanywestcentral is not yet configured134- No documented chaos engineering / game day testing plan135136**Recommendations**:1371381. Implement automated failover runbook with Azure Automation for RTO ≤ 15 min1392. Configure Cosmos DB multi-region with germanywestcentral as read-replica (can promote on failover)1403. Schedule quarterly chaos engineering tests (AKS node drain, zone failure simulation)141142**Composite SLA Calculation**:143144| Service | SLA | Zone-Redundant |145| ------------------------- | ------ | ----------------- |146| AKS Standard | 99.95% | 99.99% (with AZs) |147| PostgreSQL Flex HA | 99.99% | Yes |148| Cosmos DB (single-region) | 99.99% | Yes |149| Front Door Premium | 99.99% | Global |150| Azure Firewall | 99.99% | Yes (with AZs) |151| Key Vault | 99.99% | Yes |152| Service Bus Premium | 99.99% | Yes |153154**Composite SLA**: 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% = **99.93%**155156> [!WARNING]157> Composite SLA (99.93%) is below the 99.99% target. To achieve 99.99%, implement multi-region active-active for the most critical path (Front Door → AKS → PostgreSQL) or accept 99.95%+ with strong DR automation.158159---160161### ⚡ Performance — 8/10 (Confidence: Medium)162163| Area | Score | Assessment |164| --------------- | ----- | ------------------------------------------------------------------------------------------------------------------------- |165| **Throughput** | 8/10 | AKS D8s_v5 nodes (8 vCPU, 32 GB) with KEDA autoscaling. 3-20 nodes supports 10-15k TPS. PgBouncer for connection pooling. |166| **Latency** | 8/10 | In-region P50 ≤ 100ms achievable. Cosmos DB session reads ≤ 10ms. PostgreSQL ≤ 20ms with connection pooling. |167| **Scalability** | 8/10 | Horizontal pod autoscaling + cluster autoscaler. Cosmos DB autoscale RU/s. PostgreSQL read replicas for reporting. |168| **Caching** | 7/10 | Cosmos DB for session/cache. No dedicated Redis layer — may need for response caching under extreme load. |169170**Strengths**: KEDA enables event-driven scaling tied to Service Bus queue depth. Dual-database architecture offloads read-heavy cache operations from PostgreSQL.171172**Gaps**:173174- No dedicated Redis cache for API response caching — Cosmos DB may add latency vs. Redis for hot-path caching175- Load testing plan not yet defined to validate 15k TPS peak176- PgBouncer configuration (pool size, mode) needs tuning for 10k TPS177178**Recommendations**:1791801. Conduct Azure Load Testing at 15k TPS to validate node count and latency targets1812. Consider Azure Cache for Redis (Enterprise, 6 GB) as a hot-path cache if Cosmos DB latency exceeds targets under load1823. Configure PgBouncer in transaction mode with pool_size = 200 per pod183184---185186### 💰 Cost — 7/10 (Confidence: Medium)187188| Area | Score | Assessment |189| -------------------- | ----- | ----------------------------------------------------------------------------------------------------- |190| **Right-Sizing** | 7/10 | D8s_v5 nodes are appropriate for 10k TPS. PostgreSQL E16s v5 may be oversized initially. |191| **Optimization** | 7/10 | Reserved instances recommended but not yet committed. Cosmos DB autoscale prevents over-provisioning. |192| **Monitoring** | 7/10 | Cost alerts should be configured. No FinOps process documented. |193| **Waste Prevention** | 6/10 | Dev/staging environments could use smaller SKUs. Spot nodes viable for non-CDE workloads. |194195**Estimated Monthly Cost** (from Azure Pricing MCP — swedencentral):196197| Category | Service | SKU | Unit Price | Monthly Cost |198| ------------------------------ | ----------------------- | ------------------------------ | ------------------------ | --------------------- |199| 💻 Compute (AKS management) | AKS Standard | Standard | $0.60/hr | $438 |200| 💻 Compute (AKS nodes × 6 avg) | D8s_v5 Linux | Standard_D8s_v5 | ~$0.408/hr | $1,787 |201| 💾 Database (Primary) | PostgreSQL Flex Server | Memory Opt E16s v5 (16 vCores) | $2.056/hr | $1,501 |202| 💾 Database (Cache) | Cosmos DB NoSQL | Autoscale 10K-50K RU/s | $0.012/hr per 100 RU/s | $876 – $4,380 |203| 🔐 Security | Key Vault Premium | HSM-backed | $0.03/10K ops | $22+ |204| 🌐 Network | Azure Firewall Premium | Premium | $1.75/hr | $1,278 |205| 🌐 Network | Azure Front Door | Premium | ~$330 base + per-request | $500 – $1,200 |206| 🛡️ DDoS | DDoS Network Protection | Standard | Fixed monthly | $2,944 |207| 🔀 API Gateway | API Management | Premium (1 unit) | $3.829/hr | $2,795 |208| 📊 Monitoring | Log Analytics | Per-GB ingestion | $2.99/GB | $300 – $1,500 |209| 📦 Container Registry | ACR Premium | Premium | $0.333/day | $10+ |210| 📨 Messaging | Service Bus | Premium (1 MU) | $0.9275/hr | $677 |211| 👤 Identity | Entra ID P2 + PIM | Per-user | — | $200 – $500 |212| | **TOTAL** | | | **$13,328 – $19,032** |213214> [!NOTE]215> 💰 Prices sourced from Azure Pricing MCP (swedencentral, 2026-02-09). Production with full HA (20 nodes, max Cosmos RU/s) could reach ~$27,800/mo. Reserved Instances (1-year) save ~35% on compute and PostgreSQL.216217**Savings Opportunities**:218219| Opportunity | Est. Savings | Effort |220| ------------------------------------------------------ | ---------------------------- | ------------------------------------------ |221| 1-year Reserved Instances (AKS nodes + PostgreSQL) | ~35% on compute (~$1,150/mo) | Low |222| Spot nodes for non-CDE workloads (dev/test) | Up to 80% on dev compute | Medium |223| Cosmos DB autoscale floor (scale to zero off-peak) | 20-60% variable | Low |224| Log Analytics Commitment Tier (100 GB/day) | ~30% on ingestion | Low |225| Start with APIM Standard v2 → upgrade to Premium later | ~$2,100/mo initially | Medium — requires re-architecture for VNet |226227---228229### 🔧 Operations — 8/10 (Confidence: High)230231| Area | Score | Assessment |232| --------------------- | ----- | ---------------------------------------------------------------------------------------------------- |233| **IaC** | 9/10 | Bicep with Azure Verified Modules. GitOps for AKS config. Repeatable, auditable deployments. |234| **CI/CD** | 8/10 | GitHub Actions with blue-green deployment. Container image scanning in pipeline. Automated rollback. |235| **Monitoring** | 8/10 | Azure Monitor + Application Insights + Defender. Distributed tracing. Alert thresholds defined. |236| **Incident Response** | 7/10 | On-call rotation assumed but not documented. Runbook templates needed. |237| **Documentation** | 7/10 | Requirements doc comprehensive. Operations runbook, DR plan needed before go-live. |238239**Strengths**: Full IaC approach with Bicep/AVM. Blue-green deployment minimizes downtime. Container scanning gates prevent vulnerable images.240241**Gaps**:242243- No documented incident response playbook specific to payment failures244- Runbook for database failover not yet created245- Change management process for PCI CDE changes undefined246247**Recommendations**:2482491. Create payment transaction failure runbook with escalation paths2502. Document CDE change management process for PCI-DSS Req 6 compliance2513. Implement GitOps (Flux v2) for AKS workload deployments with audit trail252253---254255## 📦 Resource SKU Recommendations256257| Resource | Recommended SKU | Region | Justification |258| ------------------------------ | ----------------------------------- | ------------- | ------------------------------------------------------------------------------------------- |259| **AKS** | Standard tier, D8s_v5 nodes | swedencentral | 8 vCPU/32 GB per node. Standard tier required for financial SLA. Zone-redundant node pools. |260| **PostgreSQL Flexible Server** | Memory Optimized E16s v5, 16 vCores | swedencentral | Memory-optimized for write-heavy payment transactions. Zone-redundant HA. |261| **Cosmos DB** | NoSQL API, Autoscale 10K-50K RU/s | swedencentral | Session consistency. Autoscale handles variable session/cache load. |262| **Azure Firewall** | Premium | swedencentral | IDPS capability required for PCI-DSS network segmentation. |263| **Azure Front Door** | Premium | Global | WAF with OWASP 3.2, bot protection, DDoS at edge. |264| **API Management** | Premium (1 unit) | swedencentral | VNet integration required for CDE. OAuth, rate limiting per merchant. |265| **Key Vault** | Premium (HSM-backed) | swedencentral | PCI-DSS requires HSM for cryptographic key storage. |266| **Service Bus** | Premium (1 Messaging Unit) | swedencentral | Dedicated capacity for transaction queues. Dead-letter support. |267| **Container Registry** | Premium | swedencentral | Geo-replication to failover region. Vulnerability scanning. Content trust. |268| **Log Analytics** | Per-GB (Analytics Logs) | swedencentral | $2.99/GB. 1-year retention for PCI-DSS § 10.7. |269| **DDoS Protection** | Network Protection (Standard) | swedencentral | Full VNet coverage for CDE network. $2,944/mo fixed. |270271### Service Maturity Assessment272273| Service | GA Status | AVM Module | Notes |274| -------------------------- | --------- | ----------------------------------------------------- | ---------------------------------------------- |275| AKS | GA | `br/public:avm/res/container-service/managed-cluster` | Production-ready, well-documented PCI guidance |276| PostgreSQL Flexible Server | GA | Available | Zone-redundant HA, read replicas GA |277| Cosmos DB NoSQL | GA | `br/public:avm/res/document-db/database-account` | Autoscale GA, PITR GA |278| Azure Firewall Premium | GA | Available | IDPS GA, TLS inspection GA |279| Azure Front Door Premium | GA | `br/public:avm/res/cdn/profile` | WAF policies GA |280| API Management Premium | GA | Available | VNet integration GA |281| Key Vault Premium | GA | `br/public:avm/res/key-vault/vault` | HSM-backed keys GA |282| Service Bus Premium | GA | `br/public:avm/res/service-bus/namespace` | Zone-redundant GA |283| DDoS Network Protection | GA | Available | Standard tier GA |284| Container Registry Premium | GA | `br/public:avm/res/container-registry/registry` | Geo-replication GA |285286> [!TIP]287> All recommended services are Generally Available (GA) with Azure Verified Modules where available. No preview or deprecated services in this architecture.288289---290291## 🎯 Architecture Decision Summary292293| # | Decision | Options Considered | Choice | Rationale |294| ------- | --------------------- | ------------------------------------------ | ---------------------- | --------------------------------------------------------------------------------------------------------------------------------------------- |295| ADR-001 | Compute Platform | AKS vs. ACA | **AKS** | PCI CDE requires dedicated node pools, Kubernetes network policies, OPA Gatekeeper. ACA lacks node-level isolation. |296| ADR-002 | Database Strategy | PostgreSQL-only vs. PostgreSQL + Cosmos DB | **Dual DB** | Offloads session/cache reads from PostgreSQL. Reduces connection pressure at 10k TPS. Sub-10ms cache reads. |297| ADR-003 | Network Topology | Flat VNet vs. Hub-Spoke | **Hub-Spoke** | PCI-DSS Req 1 requires network segmentation. Azure Firewall Premium provides IDPS + east-west inspection. |298| ADR-004 | API Gateway | Front Door only vs. Front Door + APIM | **Front Door + APIM** | Front Door for WAF/DDoS at edge. APIM Premium for VNet-integrated API management inside CDE. |299| ADR-005 | Cosmos DB Consistency | Strong vs. Session vs. Eventual | **Session** | Read-your-writes for session state. Avoids Strong consistency latency penalty. Sufficient for cache/session use case. |300| ADR-006 | Multi-Region | Active-Active vs. Active-Passive | **Active-Passive** | Lower cost and complexity. RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup. Active-Active adds Cosmos DB multi-region write cost. |301| ADR-007 | DDoS Protection | IP Protection vs. Network Protection | **Network Protection** | Full VNet coverage for CDE. Higher cost ($2,944/mo) but covers all public IPs and provides advanced telemetry. |302| ADR-008 | Connection Pooling | PgBouncer vs. Azure-native | **PgBouncer sidecar** | Required at 10k TPS to prevent PostgreSQL connection exhaustion. Transaction mode with pool_size=200/pod. |303304---305306## 🚀 Implementation Handoff307308### For Bicep Plan Agent3093101. **Network**: Hub VNet (firewall, bastion) + Spoke VNet (AKS, PostgreSQL, Cosmos DB, APIM). Private endpoints for all data services.3112. **Compute**: AKS with system node pool (D4s_v5 × 3) + user CDE node pool (D8s_v5 × 3-20). KEDA add-on. Workload Identity.3123. **Data**: PostgreSQL Flexible Server E16s v5 zone-redundant HA. Cosmos DB NoSQL autoscale 10K-50K RU/s.3134. **Security**: Key Vault Premium. Azure Firewall Premium. NSGs on all subnets. AKS network policies (Calico).3145. **Edge**: Front Door Premium + WAF policy. APIM Premium VNet-integrated.3156. **Messaging**: Service Bus Premium 1 MU.3167. **Monitoring**: Log Analytics workspace (1-year retention) + Application Insights + Defender for Cloud + Defender for Containers.3178. **DDoS**: Network Protection on hub VNet.3189. **Identity**: Managed identities for all service-to-service. Workload Identity for AKS pods. PIM for admin access.319320### AVM Modules to Use321322| Resource | AVM Module | Min Version |323| ------------------ | ----------------------------------------------------- | ----------- |324| AKS | `br/public:avm/res/container-service/managed-cluster` | Latest |325| Key Vault | `br/public:avm/res/key-vault/vault` | `0.11.0` |326| Cosmos DB | `br/public:avm/res/document-db/database-account` | `0.10.0` |327| Service Bus | `br/public:avm/res/service-bus/namespace` | `0.10.0` |328| Container Registry | `br/public:avm/res/container-registry/registry` | `0.6.0` |329| Virtual Network | `br/public:avm/res/network/virtual-network` | `0.5.0` |330| NSG | `br/public:avm/res/network/network-security-group` | `0.5.0` |331| Log Analytics | `br/public:avm/res/operational-insights/workspace` | `0.9.0` |332| Front Door | `br/public:avm/res/cdn/profile` | `0.7.0` |333334### Required Tags335336```bicep337tags: {338 Environment: environment // 'dev' | 'staging' | 'prod'339 ManagedBy: 'Bicep'340 Project: 'pci-dss-gw'341 Owner: '<to-be-confirmed>'342}343```344345---346347## 🔒 Approval Gate348349| Pillar | Score | Confidence |350| ----------------------- | ---------- | ---------- |351| 🔒 Security | 9/10 | High |352| 🔄 Reliability | 8/10 | High |353| ⚡ Performance | 8/10 | Medium |354| 💰 Cost | 7/10 | Medium |355| 🔧 Operations | 8/10 | High |356| **Composite WAF Score** | **8.0/10** | |357358**Estimated Monthly Cost**: $13,328 – $19,032 (typical prod), up to ~$27,800 at peak scale359360> [!IMPORTANT]361> ⚠️ Composite SLA (99.93%) is slightly below 99.99% target. Mitigation: implement automated DR runbook to achieve operational SLA ≥ 99.99% with rapid failover. Alternatively, accept 99.95%+ with strong DR automation.362363**Top Risks**:3643651. Composite SLA gap — mitigate with multi-region or accept 99.95%3662. DDoS + APIM Premium are large fixed costs ($5,739/mo combined) — validate necessity with QSA3673. Load testing not yet conducted — 15k TPS peak is untested assumption368369Reply **"approve"** to proceed to bicep-plan, or provide feedback.370371---372373## References374375> [!NOTE]376> 📚 The following Microsoft Learn resources provide additional guidance.377378| Topic | Link |379| -------------------------------- | ------------------------------------------------------------------------------------------------------------ |380| AKS PCI-DSS Baseline | [AKS regulated cluster](https://learn.microsoft.com/azure/aks/operator-best-practices-cluster-security) |381| AKS Well-Architected Review | [AKS WAF review](https://learn.microsoft.com/azure/well-architected/service-guides/azure-kubernetes-service) |382| PostgreSQL Flexible Server HA | [HA concepts](https://learn.microsoft.com/azure/postgresql/flexible-server/concepts-high-availability) |383| Cosmos DB Consistency Levels | [Consistency levels](https://learn.microsoft.com/azure/cosmos-db/consistency-levels) |384| Azure Firewall Premium Features | [Firewall Premium](https://learn.microsoft.com/azure/firewall/premium-features) |385| Azure Front Door WAF | [WAF on Front Door](https://learn.microsoft.com/azure/web-application-firewall/afds/afds-overview) |386| API Management VNet Integration | [APIM VNet](https://learn.microsoft.com/azure/api-management/api-management-using-with-vnet) |387| PCI-DSS on Azure | [PCI compliance blueprint](https://learn.microsoft.com/azure/compliance/offerings/offering-pci-dss) |388| DDoS Protection Overview | [DDoS Protection](https://learn.microsoft.com/azure/ddos-protection/ddos-protection-overview) |389| Azure Well-Architected Framework | [WAF overview](https://learn.microsoft.com/azure/well-architected/) |390| Azure Pricing Calculator | [Pricing calculator](https://azure.microsoft.com/pricing/calculator/) |391392---393394<div align="center">395396_Generated by **Azure Agentic InfraOps** | [GitHub](https://github.com/jonathan-vella/azure-agentic-infraops)_397398</div>