Step 2: Architecture Assessment - pci-dss-gw
Generated by architect agent | 2026-02-09
Requirements Validation ✅
| Requirement |
Status |
Notes |
| 10,000 TPS sustained, 15,000 TPS peak |
✅ Validated |
AKS with D8s_v5 nodes (3-20) supports horizontal scaling via KEDA |
| 99.99% SLA |
✅ Validated |
Zone-redundant AKS + PostgreSQL HA + Cosmos DB multi-AZ achieves composite SLA |
| P50 ≤ 100 ms, P99 ≤ 500 ms |
✅ Validated |
AKS in-cluster networking + Cosmos DB sub-10ms reads + PostgreSQL ≤ 20ms |
| PCI-DSS v4.0 Level 1 |
✅ Validated |
AKS dedicated node pools, network policies, Firewall Premium IDPS, Key Vault HSM |
| GDPR / EU data residency |
✅ Validated |
swedencentral primary, germanywestcentral failover — both EU |
| PostgreSQL for ACID transactions |
✅ Validated |
Flexible Server Memory Optimized E16s v5, zone-redundant HA |
| Cosmos DB for session/cache |
✅ Validated |
NoSQL API with Session consistency, autoscale RU/s |
| AKS over ACA |
✅ Validated |
PCI CDE isolation requires dedicated node pools + Kubernetes network policies |
| Hub-spoke with Azure Firewall |
✅ Validated |
Premium tier for IDPS, east-west traffic inspection per PCI-DSS Req 1 |
| DDoS Network Protection |
✅ Validated |
Full VNet coverage for CDE — $2,944/mo |
| API Management Premium |
✅ Validated |
VNet-integrated for CDE, OAuth, rate limiting — $2,795/mo |
| Budget range validated |
⚠️ Adjusted |
Revised to $16,200 – $27,800/mo with all services included |
[!IMPORTANT]
All critical requirements from 01-requirements.md are architecturally feasible. Budget has been refined with live Azure Pricing MCP data.
Executive Summary
Architecture Overview
This is a PCI-DSS Level 1 payment gateway on Azure, designed for 10,000 TPS sustained throughput with 99.99% availability. The architecture follows a hub-spoke network topology with AKS as the compute platform, PostgreSQL Flexible Server for transactional data, and Cosmos DB for low-latency session state.
Primary Optimization Pillar
Security — PCI-DSS v4.0 Level 1 compliance drives architectural decisions. All other pillars are optimized within PCI constraints.
Architecture Pattern
| Attribute |
Value |
| Pattern |
Hub-Spoke with Dedicated CDE |
| Compute |
AKS Standard tier with zone-redundant node pools |
| Data Tier |
PostgreSQL Flexible Server (ACID) + Cosmos DB (cache/session) |
| Network Edge |
Azure Front Door Premium (WAF + DDoS) → Azure Firewall Premium (IDPS) → AKS |
| API Layer |
API Management Premium (VNet-integrated) |
| Messaging |
Service Bus Premium (dedicated capacity) |
| Secrets |
Key Vault Premium (HSM-backed) |
| Identity |
Entra ID + Workload Identity + PIM |
| Monitoring |
Azure Monitor + Log Analytics (1-year retention) + Defender for Cloud |
Key Architecture Decisions
| Decision |
Choice |
Rationale |
| Compute platform |
AKS over ACA |
PCI CDE isolation via dedicated node pools, Kubernetes network policies, OPA Gatekeeper |
| Database strategy |
Dual DB (PostgreSQL + Cosmos DB) |
ACID for transactions + sub-10ms for session/cache; reduces PostgreSQL connection pressure |
| Network segmentation |
Hub-spoke + Azure Firewall Premium |
IDPS required for PCI-DSS Req 1; east-west inspection between CDE and non-CDE |
| API gateway |
APIM Premium (VNet) + Front Door Premium |
VNet integration keeps API gateway inside CDE; Front Door provides global WAF + DDoS |
| Cosmos DB consistency |
Session consistency |
Sufficient for session state; avoids Strong consistency latency penalty while ensuring read-your-writes |
| Multi-region strategy |
Active-Passive |
Minimizes cost and Cosmos DB complexity; RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup |
WAF Pillar Assessment
🔒 Security — 9/10 (Confidence: High)
| Area |
Score |
Assessment |
| Identity & Access |
9/10 |
Entra ID + Workload Identity for all service-to-service auth. PIM for JIT admin access. No shared accounts or passwords. |
| Network Security |
9/10 |
Hub-spoke with Azure Firewall Premium (IDPS), NSGs, AKS network policies. Private endpoints for all data services. No public endpoints for CDE. |
| Data Protection |
9/10 |
AES-256 encryption at rest with CMK for cardholder data. TLS 1.2+ everywhere. Key Vault Premium (HSM) for cryptographic keys. Tokenization for PAN. |
| Threat Detection |
8/10 |
Defender for Containers, Defender for Cloud, Azure Firewall IDPS. Container image scanning pre-deployment. |
| Compliance |
9/10 |
PCI-DSS v4.0 controls mapped to Azure services. 1-year log retention. Tamper-proof audit trail via Log Analytics. |
Strengths: Comprehensive PCI-DSS control mapping. Zero-trust architecture with managed identity everywhere. HSM-backed key management.
Gaps:
- Penetration testing schedule not yet defined (PCI Req 11)
- QSA validation of Azure Firewall IDPS as acceptable IDS/IPS control is pending
Recommendations:
- Schedule quarterly penetration tests with a PCI-certified ASV
- Implement Azure Policy deny rules for non-compliant configurations
- Enable Defender for Key Vault for anomaly detection on cryptographic operations
🔄 Reliability — 8/10 (Confidence: High)
| Area |
Score |
Assessment |
| High Availability |
9/10 |
Zone-redundant AKS (3 AZs), PostgreSQL zone-redundant HA, Cosmos DB multi-AZ. Front Door global anycast. |
| Disaster Recovery |
7/10 |
Active-passive to germanywestcentral. PostgreSQL geo-redundant backup (RPO ≤ 5 min). Manual failover process. |
| Resilience |
8/10 |
KEDA autoscaling, pod disruption budgets, Service Bus dead-letter queues, idempotent transaction processing. |
| Health Monitoring |
8/10 |
Liveness/readiness probes, Azure Monitor alerts, Defender continuous monitoring. Sub-minute alerting. |
Strengths: Zone-redundant deployment across all tiers. Idempotent transaction design prevents duplicate charges. Service Bus DLQ handles transient failures.
Gaps:
- Active-passive failover is manual — RTO ≤ 30 min depends on operator response time
- Cosmos DB failover to germanywestcentral is not yet configured
- No documented chaos engineering / game day testing plan
Recommendations:
- Implement automated failover runbook with Azure Automation for RTO ≤ 15 min
- Configure Cosmos DB multi-region with germanywestcentral as read-replica (can promote on failover)
- Schedule quarterly chaos engineering tests (AKS node drain, zone failure simulation)
Composite SLA Calculation:
| Service |
SLA |
Zone-Redundant |
| AKS Standard |
99.95% |
99.99% (with AZs) |
| PostgreSQL Flex HA |
99.99% |
Yes |
| Cosmos DB (single-region) |
99.99% |
Yes |
| Front Door Premium |
99.99% |
Global |
| Azure Firewall |
99.99% |
Yes (with AZs) |
| Key Vault |
99.99% |
Yes |
| Service Bus Premium |
99.99% |
Yes |
Composite SLA: 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% = 99.93%
[!WARNING]
Composite SLA (99.93%) is below the 99.99% target. To achieve 99.99%, implement multi-region active-active for the most critical path (Front Door → AKS → PostgreSQL) or accept 99.95%+ with strong DR automation.
⚡ Performance — 8/10 (Confidence: Medium)
| Area |
Score |
Assessment |
| Throughput |
8/10 |
AKS D8s_v5 nodes (8 vCPU, 32 GB) with KEDA autoscaling. 3-20 nodes supports 10-15k TPS. PgBouncer for connection pooling. |
| Latency |
8/10 |
In-region P50 ≤ 100ms achievable. Cosmos DB session reads ≤ 10ms. PostgreSQL ≤ 20ms with connection pooling. |
| Scalability |
8/10 |
Horizontal pod autoscaling + cluster autoscaler. Cosmos DB autoscale RU/s. PostgreSQL read replicas for reporting. |
| Caching |
7/10 |
Cosmos DB for session/cache. No dedicated Redis layer — may need for response caching under extreme load. |
Strengths: KEDA enables event-driven scaling tied to Service Bus queue depth. Dual-database architecture offloads read-heavy cache operations from PostgreSQL.
Gaps:
- No dedicated Redis cache for API response caching — Cosmos DB may add latency vs. Redis for hot-path caching
- Load testing plan not yet defined to validate 15k TPS peak
- PgBouncer configuration (pool size, mode) needs tuning for 10k TPS
Recommendations:
- Conduct Azure Load Testing at 15k TPS to validate node count and latency targets
- Consider Azure Cache for Redis (Enterprise, 6 GB) as a hot-path cache if Cosmos DB latency exceeds targets under load
- Configure PgBouncer in transaction mode with pool_size = 200 per pod
💰 Cost — 7/10 (Confidence: Medium)
| Area |
Score |
Assessment |
| Right-Sizing |
7/10 |
D8s_v5 nodes are appropriate for 10k TPS. PostgreSQL E16s v5 may be oversized initially. |
| Optimization |
7/10 |
Reserved instances recommended but not yet committed. Cosmos DB autoscale prevents over-provisioning. |
| Monitoring |
7/10 |
Cost alerts should be configured. No FinOps process documented. |
| Waste Prevention |
6/10 |
Dev/staging environments could use smaller SKUs. Spot nodes viable for non-CDE workloads. |
Estimated Monthly Cost (from Azure Pricing MCP — swedencentral):
| Category |
Service |
SKU |
Unit Price |
Monthly Cost |
| 💻 Compute (AKS management) |
AKS Standard |
Standard |
$0.60/hr |
$438 |
| 💻 Compute (AKS nodes × 6 avg) |
D8s_v5 Linux |
Standard_D8s_v5 |
~$0.408/hr |
$1,787 |
| 💾 Database (Primary) |
PostgreSQL Flex Server |
Memory Opt E16s v5 (16 vCores) |
$2.056/hr |
$1,501 |
| 💾 Database (Cache) |
Cosmos DB NoSQL |
Autoscale 10K-50K RU/s |
$0.012/hr per 100 RU/s |
$876 – $4,380 |
| 🔐 Security |
Key Vault Premium |
HSM-backed |
$0.03/10K ops |
$22+ |
| 🌐 Network |
Azure Firewall Premium |
Premium |
$1.75/hr |
$1,278 |
| 🌐 Network |
Azure Front Door |
Premium |
~$330 base + per-request |
$500 – $1,200 |
| 🛡️ DDoS |
DDoS Network Protection |
Standard |
Fixed monthly |
$2,944 |
| 🔀 API Gateway |
API Management |
Premium (1 unit) |
$3.829/hr |
$2,795 |
| 📊 Monitoring |
Log Analytics |
Per-GB ingestion |
$2.99/GB |
$300 – $1,500 |
| 📦 Container Registry |
ACR Premium |
Premium |
$0.333/day |
$10+ |
| 📨 Messaging |
Service Bus |
Premium (1 MU) |
$0.9275/hr |
$677 |
| 👤 Identity |
Entra ID P2 + PIM |
Per-user |
— |
$200 – $500 |
|
TOTAL |
|
|
$13,328 – $19,032 |
[!NOTE]
💰 Prices sourced from Azure Pricing MCP (swedencentral, 2026-02-09). Production with full HA (20 nodes, max Cosmos RU/s) could reach ~$27,800/mo. Reserved Instances (1-year) save ~35% on compute and PostgreSQL.
Savings Opportunities:
| Opportunity |
Est. Savings |
Effort |
| 1-year Reserved Instances (AKS nodes + PostgreSQL) |
35% on compute ($1,150/mo) |
Low |
| Spot nodes for non-CDE workloads (dev/test) |
Up to 80% on dev compute |
Medium |
| Cosmos DB autoscale floor (scale to zero off-peak) |
20-60% variable |
Low |
| Log Analytics Commitment Tier (100 GB/day) |
~30% on ingestion |
Low |
| Start with APIM Standard v2 → upgrade to Premium later |
~$2,100/mo initially |
Medium — requires re-architecture for VNet |
🔧 Operations — 8/10 (Confidence: High)
| Area |
Score |
Assessment |
| IaC |
9/10 |
Bicep with Azure Verified Modules. GitOps for AKS config. Repeatable, auditable deployments. |
| CI/CD |
8/10 |
GitHub Actions with blue-green deployment. Container image scanning in pipeline. Automated rollback. |
| Monitoring |
8/10 |
Azure Monitor + Application Insights + Defender. Distributed tracing. Alert thresholds defined. |
| Incident Response |
7/10 |
On-call rotation assumed but not documented. Runbook templates needed. |
| Documentation |
7/10 |
Requirements doc comprehensive. Operations runbook, DR plan needed before go-live. |
Strengths: Full IaC approach with Bicep/AVM. Blue-green deployment minimizes downtime. Container scanning gates prevent vulnerable images.
Gaps:
- No documented incident response playbook specific to payment failures
- Runbook for database failover not yet created
- Change management process for PCI CDE changes undefined
Recommendations:
- Create payment transaction failure runbook with escalation paths
- Document CDE change management process for PCI-DSS Req 6 compliance
- Implement GitOps (Flux v2) for AKS workload deployments with audit trail
Resource SKU Recommendations
| Resource |
Recommended SKU |
Region |
Justification |
| AKS |
Standard tier, D8s_v5 nodes |
swedencentral |
8 vCPU/32 GB per node. Standard tier required for financial SLA. Zone-redundant node pools. |
| PostgreSQL Flexible Server |
Memory Optimized E16s v5, 16 vCores |
swedencentral |
Memory-optimized for write-heavy payment transactions. Zone-redundant HA. |
| Cosmos DB |
NoSQL API, Autoscale 10K-50K RU/s |
swedencentral |
Session consistency. Autoscale handles variable session/cache load. |
| Azure Firewall |
Premium |
swedencentral |
IDPS capability required for PCI-DSS network segmentation. |
| Azure Front Door |
Premium |
Global |
WAF with OWASP 3.2, bot protection, DDoS at edge. |
| API Management |
Premium (1 unit) |
swedencentral |
VNet integration required for CDE. OAuth, rate limiting per merchant. |
| Key Vault |
Premium (HSM-backed) |
swedencentral |
PCI-DSS requires HSM for cryptographic key storage. |
| Service Bus |
Premium (1 Messaging Unit) |
swedencentral |
Dedicated capacity for transaction queues. Dead-letter support. |
| Container Registry |
Premium |
swedencentral |
Geo-replication to failover region. Vulnerability scanning. Content trust. |
| Log Analytics |
Per-GB (Analytics Logs) |
swedencentral |
$2.99/GB. 1-year retention for PCI-DSS § 10.7. |
| DDoS Protection |
Network Protection (Standard) |
swedencentral |
Full VNet coverage for CDE network. $2,944/mo fixed. |
Service Maturity Assessment
| Service |
GA Status |
AVM Module |
Notes |
| AKS |
GA |
br/public:avm/res/container-service/managed-cluster |
Production-ready, well-documented PCI guidance |
| PostgreSQL Flexible Server |
GA |
Available |
Zone-redundant HA, read replicas GA |
| Cosmos DB NoSQL |
GA |
br/public:avm/res/document-db/database-account |
Autoscale GA, PITR GA |
| Azure Firewall Premium |
GA |
Available |
IDPS GA, TLS inspection GA |
| Azure Front Door Premium |
GA |
br/public:avm/res/cdn/profile |
WAF policies GA |
| API Management Premium |
GA |
Available |
VNet integration GA |
| Key Vault Premium |
GA |
br/public:avm/res/key-vault/vault |
HSM-backed keys GA |
| Service Bus Premium |
GA |
br/public:avm/res/service-bus/namespace |
Zone-redundant GA |
| DDoS Network Protection |
GA |
Available |
Standard tier GA |
| Container Registry Premium |
GA |
br/public:avm/res/container-registry/registry |
Geo-replication GA |
[!TIP]
All recommended services are Generally Available (GA) with Azure Verified Modules where available. No preview or deprecated services in this architecture.
Architecture Decision Summary
| # |
Decision |
Options Considered |
Choice |
Rationale |
| ADR-001 |
Compute Platform |
AKS vs. ACA |
AKS |
PCI CDE requires dedicated node pools, Kubernetes network policies, OPA Gatekeeper. ACA lacks node-level isolation. |
| ADR-002 |
Database Strategy |
PostgreSQL-only vs. PostgreSQL + Cosmos DB |
Dual DB |
Offloads session/cache reads from PostgreSQL. Reduces connection pressure at 10k TPS. Sub-10ms cache reads. |
| ADR-003 |
Network Topology |
Flat VNet vs. Hub-Spoke |
Hub-Spoke |
PCI-DSS Req 1 requires network segmentation. Azure Firewall Premium provides IDPS + east-west inspection. |
| ADR-004 |
API Gateway |
Front Door only vs. Front Door + APIM |
Front Door + APIM |
Front Door for WAF/DDoS at edge. APIM Premium for VNet-integrated API management inside CDE. |
| ADR-005 |
Cosmos DB Consistency |
Strong vs. Session vs. Eventual |
Session |
Read-your-writes for session state. Avoids Strong consistency latency penalty. Sufficient for cache/session use case. |
| ADR-006 |
Multi-Region |
Active-Active vs. Active-Passive |
Active-Passive |
Lower cost and complexity. RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup. Active-Active adds Cosmos DB multi-region write cost. |
| ADR-007 |
DDoS Protection |
IP Protection vs. Network Protection |
Network Protection |
Full VNet coverage for CDE. Higher cost ($2,944/mo) but covers all public IPs and provides advanced telemetry. |
| ADR-008 |
Connection Pooling |
PgBouncer vs. Azure-native |
PgBouncer sidecar |
Required at 10k TPS to prevent PostgreSQL connection exhaustion. Transaction mode with pool_size=200/pod. |
Implementation Handoff
For Bicep Plan Agent
- Network: Hub VNet (firewall, bastion) + Spoke VNet (AKS, PostgreSQL, Cosmos DB, APIM). Private endpoints for all data services.
- Compute: AKS with system node pool (D4s_v5 × 3) + user CDE node pool (D8s_v5 × 3-20). KEDA add-on. Workload Identity.
- Data: PostgreSQL Flexible Server E16s v5 zone-redundant HA. Cosmos DB NoSQL autoscale 10K-50K RU/s.
- Security: Key Vault Premium. Azure Firewall Premium. NSGs on all subnets. AKS network policies (Calico).
- Edge: Front Door Premium + WAF policy. APIM Premium VNet-integrated.
- Messaging: Service Bus Premium 1 MU.
- Monitoring: Log Analytics workspace (1-year retention) + Application Insights + Defender for Cloud + Defender for Containers.
- DDoS: Network Protection on hub VNet.
- Identity: Managed identities for all service-to-service. Workload Identity for AKS pods. PIM for admin access.
AVM Modules to Use
| Resource |
AVM Module |
Min Version |
| AKS |
br/public:avm/res/container-service/managed-cluster |
Latest |
| Key Vault |
br/public:avm/res/key-vault/vault |
0.11.0 |
| Cosmos DB |
br/public:avm/res/document-db/database-account |
0.10.0 |
| Service Bus |
br/public:avm/res/service-bus/namespace |
0.10.0 |
| Container Registry |
br/public:avm/res/container-registry/registry |
0.6.0 |
| Virtual Network |
br/public:avm/res/network/virtual-network |
0.5.0 |
| NSG |
br/public:avm/res/network/network-security-group |
0.5.0 |
| Log Analytics |
br/public:avm/res/operational-insights/workspace |
0.9.0 |
| Front Door |
br/public:avm/res/cdn/profile |
0.7.0 |
Required Tags
tags: {
Environment: environment // 'dev' | 'staging' | 'prod'
ManagedBy: 'Bicep'
Project: 'pci-dss-gw'
Owner: '<to-be-confirmed>'
}
Approval Gate
| Pillar |
Score |
Confidence |
| 🔒 Security |
9/10 |
High |
| 🔄 Reliability |
8/10 |
High |
| ⚡ Performance |
8/10 |
Medium |
| 💰 Cost |
7/10 |
Medium |
| 🔧 Operations |
8/10 |
High |
| Composite WAF Score |
8.0/10 |
|
Estimated Monthly Cost: $13,328 – $19,032 (typical prod), up to ~$27,800 at peak scale
[!IMPORTANT]
⚠️ Composite SLA (99.93%) is slightly below 99.99% target. Mitigation: implement automated DR runbook to achieve operational SLA ≥ 99.99% with rapid failover. Alternatively, accept 99.95%+ with strong DR automation.
Top Risks:
- Composite SLA gap — mitigate with multi-region or accept 99.95%
- DDoS + APIM Premium are large fixed costs ($5,739/mo combined) — validate necessity with QSA
- Load testing not yet conducted — 15k TPS peak is untested assumption
Reply "approve" to proceed to bicep-plan, or provide feedback.
References
[!NOTE]
📚 The following Microsoft Learn resources provide additional guidance.
1---2name: step-2-architecture-assessment-pci-dss-gw-23description: This is a PCI-DSS Level 1 payment gateway on Azure, designed for 10,000 TPS sustained throughput with 99.99% availability.4---5# Step 2: Architecture Assessment - pci-dss-gw67> Generated by architect agent | 2026-02-0989---1011## Requirements Validation ✅1213| Requirement | Status | Notes |14| --- | --- | --- |15| 10,000 TPS sustained, 15,000 TPS peak | ✅ Validated | AKS with D8s_v5 nodes (3-20) supports horizontal scaling via KEDA |16| 99.99% SLA | ✅ Validated | Zone-redundant AKS + PostgreSQL HA + Cosmos DB multi-AZ achieves composite SLA |17| P50 ≤ 100 ms, P99 ≤ 500 ms | ✅ Validated | AKS in-cluster networking + Cosmos DB sub-10ms reads + PostgreSQL ≤ 20ms |18| PCI-DSS v4.0 Level 1 | ✅ Validated | AKS dedicated node pools, network policies, Firewall Premium IDPS, Key Vault HSM |19| GDPR / EU data residency | ✅ Validated | swedencentral primary, germanywestcentral failover — both EU |20| PostgreSQL for ACID transactions | ✅ Validated | Flexible Server Memory Optimized E16s v5, zone-redundant HA |21| Cosmos DB for session/cache | ✅ Validated | NoSQL API with Session consistency, autoscale RU/s |22| AKS over ACA | ✅ Validated | PCI CDE isolation requires dedicated node pools + Kubernetes network policies |23| Hub-spoke with Azure Firewall | ✅ Validated | Premium tier for IDPS, east-west traffic inspection per PCI-DSS Req 1 |24| DDoS Network Protection | ✅ Validated | Full VNet coverage for CDE — $2,944/mo |25| API Management Premium | ✅ Validated | VNet-integrated for CDE, OAuth, rate limiting — $2,795/mo |26| Budget range validated | ⚠️ Adjusted | Revised to $16,200 – $27,800/mo with all services included |2728> [!IMPORTANT]29> All critical requirements from `01-requirements.md` are architecturally feasible. Budget has been refined with live Azure Pricing MCP data.3031---3233## Executive Summary3435### Architecture Overview3637This is a **PCI-DSS Level 1 payment gateway** on Azure, designed for 10,000 TPS sustained throughput with 99.99% availability. The architecture follows a **hub-spoke network topology** with AKS as the compute platform, PostgreSQL Flexible Server for transactional data, and Cosmos DB for low-latency session state.3839### Primary Optimization Pillar4041**Security** — PCI-DSS v4.0 Level 1 compliance drives architectural decisions. All other pillars are optimized within PCI constraints.4243### Architecture Pattern4445| Attribute | Value |46| --- | --- |47| **Pattern** | Hub-Spoke with Dedicated CDE |48| **Compute** | AKS Standard tier with zone-redundant node pools |49| **Data Tier** | PostgreSQL Flexible Server (ACID) + Cosmos DB (cache/session) |50| **Network Edge** | Azure Front Door Premium (WAF + DDoS) → Azure Firewall Premium (IDPS) → AKS |51| **API Layer** | API Management Premium (VNet-integrated) |52| **Messaging** | Service Bus Premium (dedicated capacity) |53| **Secrets** | Key Vault Premium (HSM-backed) |54| **Identity** | Entra ID + Workload Identity + PIM |55| **Monitoring** | Azure Monitor + Log Analytics (1-year retention) + Defender for Cloud |5657### Key Architecture Decisions5859| Decision | Choice | Rationale |60| --- | --- | --- |61| Compute platform | AKS over ACA | PCI CDE isolation via dedicated node pools, Kubernetes network policies, OPA Gatekeeper |62| Database strategy | Dual DB (PostgreSQL + Cosmos DB) | ACID for transactions + sub-10ms for session/cache; reduces PostgreSQL connection pressure |63| Network segmentation | Hub-spoke + Azure Firewall Premium | IDPS required for PCI-DSS Req 1; east-west inspection between CDE and non-CDE |64| API gateway | APIM Premium (VNet) + Front Door Premium | VNet integration keeps API gateway inside CDE; Front Door provides global WAF + DDoS |65| Cosmos DB consistency | Session consistency | Sufficient for session state; avoids Strong consistency latency penalty while ensuring read-your-writes |66| Multi-region strategy | Active-Passive | Minimizes cost and Cosmos DB complexity; RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup |6768---6970## WAF Pillar Assessment7172### 🔒 Security — 9/10 (Confidence: High)7374| Area | Score | Assessment |75| --- | --- | --- |76| **Identity & Access** | 9/10 | Entra ID + Workload Identity for all service-to-service auth. PIM for JIT admin access. No shared accounts or passwords. |77| **Network Security** | 9/10 | Hub-spoke with Azure Firewall Premium (IDPS), NSGs, AKS network policies. Private endpoints for all data services. No public endpoints for CDE. |78| **Data Protection** | 9/10 | AES-256 encryption at rest with CMK for cardholder data. TLS 1.2+ everywhere. Key Vault Premium (HSM) for cryptographic keys. Tokenization for PAN. |79| **Threat Detection** | 8/10 | Defender for Containers, Defender for Cloud, Azure Firewall IDPS. Container image scanning pre-deployment. |80| **Compliance** | 9/10 | PCI-DSS v4.0 controls mapped to Azure services. 1-year log retention. Tamper-proof audit trail via Log Analytics. |8182**Strengths**: Comprehensive PCI-DSS control mapping. Zero-trust architecture with managed identity everywhere. HSM-backed key management.8384**Gaps**: 85- Penetration testing schedule not yet defined (PCI Req 11)86- QSA validation of Azure Firewall IDPS as acceptable IDS/IPS control is pending8788**Recommendations**:891. Schedule quarterly penetration tests with a PCI-certified ASV902. Implement Azure Policy deny rules for non-compliant configurations913. Enable Defender for Key Vault for anomaly detection on cryptographic operations9293---9495### 🔄 Reliability — 8/10 (Confidence: High)9697| Area | Score | Assessment |98| --- | --- | --- |99| **High Availability** | 9/10 | Zone-redundant AKS (3 AZs), PostgreSQL zone-redundant HA, Cosmos DB multi-AZ. Front Door global anycast. |100| **Disaster Recovery** | 7/10 | Active-passive to germanywestcentral. PostgreSQL geo-redundant backup (RPO ≤ 5 min). Manual failover process. |101| **Resilience** | 8/10 | KEDA autoscaling, pod disruption budgets, Service Bus dead-letter queues, idempotent transaction processing. |102| **Health Monitoring** | 8/10 | Liveness/readiness probes, Azure Monitor alerts, Defender continuous monitoring. Sub-minute alerting. |103104**Strengths**: Zone-redundant deployment across all tiers. Idempotent transaction design prevents duplicate charges. Service Bus DLQ handles transient failures.105106**Gaps**:107- Active-passive failover is manual — RTO ≤ 30 min depends on operator response time108- Cosmos DB failover to germanywestcentral is not yet configured109- No documented chaos engineering / game day testing plan110111**Recommendations**:1121. Implement automated failover runbook with Azure Automation for RTO ≤ 15 min1132. Configure Cosmos DB multi-region with germanywestcentral as read-replica (can promote on failover)1143. Schedule quarterly chaos engineering tests (AKS node drain, zone failure simulation)115116**Composite SLA Calculation**:117118| Service | SLA | Zone-Redundant |119| --- | --- | --- |120| AKS Standard | 99.95% | 99.99% (with AZs) |121| PostgreSQL Flex HA | 99.99% | Yes |122| Cosmos DB (single-region) | 99.99% | Yes |123| Front Door Premium | 99.99% | Global |124| Azure Firewall | 99.99% | Yes (with AZs) |125| Key Vault | 99.99% | Yes |126| Service Bus Premium | 99.99% | Yes |127128**Composite SLA**: 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% = **99.93%**129130> [!WARNING]131> Composite SLA (99.93%) is below the 99.99% target. To achieve 99.99%, implement multi-region active-active for the most critical path (Front Door → AKS → PostgreSQL) or accept 99.95%+ with strong DR automation.132133---134135### ⚡ Performance — 8/10 (Confidence: Medium)136137| Area | Score | Assessment |138| --- | --- | --- |139| **Throughput** | 8/10 | AKS D8s_v5 nodes (8 vCPU, 32 GB) with KEDA autoscaling. 3-20 nodes supports 10-15k TPS. PgBouncer for connection pooling. |140| **Latency** | 8/10 | In-region P50 ≤ 100ms achievable. Cosmos DB session reads ≤ 10ms. PostgreSQL ≤ 20ms with connection pooling. |141| **Scalability** | 8/10 | Horizontal pod autoscaling + cluster autoscaler. Cosmos DB autoscale RU/s. PostgreSQL read replicas for reporting. |142| **Caching** | 7/10 | Cosmos DB for session/cache. No dedicated Redis layer — may need for response caching under extreme load. |143144**Strengths**: KEDA enables event-driven scaling tied to Service Bus queue depth. Dual-database architecture offloads read-heavy cache operations from PostgreSQL.145146**Gaps**:147- No dedicated Redis cache for API response caching — Cosmos DB may add latency vs. Redis for hot-path caching148- Load testing plan not yet defined to validate 15k TPS peak149- PgBouncer configuration (pool size, mode) needs tuning for 10k TPS150151**Recommendations**:1521. Conduct Azure Load Testing at 15k TPS to validate node count and latency targets1532. Consider Azure Cache for Redis (Enterprise, 6 GB) as a hot-path cache if Cosmos DB latency exceeds targets under load1543. Configure PgBouncer in transaction mode with pool_size = 200 per pod155156---157158### 💰 Cost — 7/10 (Confidence: Medium)159160| Area | Score | Assessment |161| --- | --- | --- |162| **Right-Sizing** | 7/10 | D8s_v5 nodes are appropriate for 10k TPS. PostgreSQL E16s v5 may be oversized initially. |163| **Optimization** | 7/10 | Reserved instances recommended but not yet committed. Cosmos DB autoscale prevents over-provisioning. |164| **Monitoring** | 7/10 | Cost alerts should be configured. No FinOps process documented. |165| **Waste Prevention** | 6/10 | Dev/staging environments could use smaller SKUs. Spot nodes viable for non-CDE workloads. |166167**Estimated Monthly Cost** (from Azure Pricing MCP — swedencentral):168169| Category | Service | SKU | Unit Price | Monthly Cost |170| --- | --- | --- | --- | --- |171| 💻 Compute (AKS management) | AKS Standard | Standard | $0.60/hr | $438 |172| 💻 Compute (AKS nodes × 6 avg) | D8s_v5 Linux | Standard_D8s_v5 | ~$0.408/hr | $1,787 |173| 💾 Database (Primary) | PostgreSQL Flex Server | Memory Opt E16s v5 (16 vCores) | $2.056/hr | $1,501 |174| 💾 Database (Cache) | Cosmos DB NoSQL | Autoscale 10K-50K RU/s | $0.012/hr per 100 RU/s | $876 – $4,380 |175| 🔐 Security | Key Vault Premium | HSM-backed | $0.03/10K ops | $22+ |176| 🌐 Network | Azure Firewall Premium | Premium | $1.75/hr | $1,278 |177| 🌐 Network | Azure Front Door | Premium | ~$330 base + per-request | $500 – $1,200 |178| 🛡️ DDoS | DDoS Network Protection | Standard | Fixed monthly | $2,944 |179| 🔀 API Gateway | API Management | Premium (1 unit) | $3.829/hr | $2,795 |180| 📊 Monitoring | Log Analytics | Per-GB ingestion | $2.99/GB | $300 – $1,500 |181| 📦 Container Registry | ACR Premium | Premium | $0.333/day | $10+ |182| 📨 Messaging | Service Bus | Premium (1 MU) | $0.9275/hr | $677 |183| 👤 Identity | Entra ID P2 + PIM | Per-user | — | $200 – $500 |184| | **TOTAL** | | | **$13,328 – $19,032** |185186> [!NOTE]187> 💰 Prices sourced from Azure Pricing MCP (swedencentral, 2026-02-09). Production with full HA (20 nodes, max Cosmos RU/s) could reach ~$27,800/mo. Reserved Instances (1-year) save ~35% on compute and PostgreSQL.188189**Savings Opportunities**:190191| Opportunity | Est. Savings | Effort |192| --- | --- | --- |193| 1-year Reserved Instances (AKS nodes + PostgreSQL) | ~35% on compute (~$1,150/mo) | Low |194| Spot nodes for non-CDE workloads (dev/test) | Up to 80% on dev compute | Medium |195| Cosmos DB autoscale floor (scale to zero off-peak) | 20-60% variable | Low |196| Log Analytics Commitment Tier (100 GB/day) | ~30% on ingestion | Low |197| Start with APIM Standard v2 → upgrade to Premium later | ~$2,100/mo initially | Medium — requires re-architecture for VNet |198199---200201### 🔧 Operations — 8/10 (Confidence: High)202203| Area | Score | Assessment |204| --- | --- | --- |205| **IaC** | 9/10 | Bicep with Azure Verified Modules. GitOps for AKS config. Repeatable, auditable deployments. |206| **CI/CD** | 8/10 | GitHub Actions with blue-green deployment. Container image scanning in pipeline. Automated rollback. |207| **Monitoring** | 8/10 | Azure Monitor + Application Insights + Defender. Distributed tracing. Alert thresholds defined. |208| **Incident Response** | 7/10 | On-call rotation assumed but not documented. Runbook templates needed. |209| **Documentation** | 7/10 | Requirements doc comprehensive. Operations runbook, DR plan needed before go-live. |210211**Strengths**: Full IaC approach with Bicep/AVM. Blue-green deployment minimizes downtime. Container scanning gates prevent vulnerable images.212213**Gaps**:214- No documented incident response playbook specific to payment failures215- Runbook for database failover not yet created216- Change management process for PCI CDE changes undefined217218**Recommendations**:2191. Create payment transaction failure runbook with escalation paths2202. Document CDE change management process for PCI-DSS Req 6 compliance2213. Implement GitOps (Flux v2) for AKS workload deployments with audit trail222223---224225## Resource SKU Recommendations226227| Resource | Recommended SKU | Region | Justification |228| --- | --- | --- | --- |229| **AKS** | Standard tier, D8s_v5 nodes | swedencentral | 8 vCPU/32 GB per node. Standard tier required for financial SLA. Zone-redundant node pools. |230| **PostgreSQL Flexible Server** | Memory Optimized E16s v5, 16 vCores | swedencentral | Memory-optimized for write-heavy payment transactions. Zone-redundant HA. |231| **Cosmos DB** | NoSQL API, Autoscale 10K-50K RU/s | swedencentral | Session consistency. Autoscale handles variable session/cache load. |232| **Azure Firewall** | Premium | swedencentral | IDPS capability required for PCI-DSS network segmentation. |233| **Azure Front Door** | Premium | Global | WAF with OWASP 3.2, bot protection, DDoS at edge. |234| **API Management** | Premium (1 unit) | swedencentral | VNet integration required for CDE. OAuth, rate limiting per merchant. |235| **Key Vault** | Premium (HSM-backed) | swedencentral | PCI-DSS requires HSM for cryptographic key storage. |236| **Service Bus** | Premium (1 Messaging Unit) | swedencentral | Dedicated capacity for transaction queues. Dead-letter support. |237| **Container Registry** | Premium | swedencentral | Geo-replication to failover region. Vulnerability scanning. Content trust. |238| **Log Analytics** | Per-GB (Analytics Logs) | swedencentral | $2.99/GB. 1-year retention for PCI-DSS § 10.7. |239| **DDoS Protection** | Network Protection (Standard) | swedencentral | Full VNet coverage for CDE network. $2,944/mo fixed. |240241### Service Maturity Assessment242243| Service | GA Status | AVM Module | Notes |244| --- | --- | --- | --- |245| AKS | GA | `br/public:avm/res/container-service/managed-cluster` | Production-ready, well-documented PCI guidance |246| PostgreSQL Flexible Server | GA | Available | Zone-redundant HA, read replicas GA |247| Cosmos DB NoSQL | GA | `br/public:avm/res/document-db/database-account` | Autoscale GA, PITR GA |248| Azure Firewall Premium | GA | Available | IDPS GA, TLS inspection GA |249| Azure Front Door Premium | GA | `br/public:avm/res/cdn/profile` | WAF policies GA |250| API Management Premium | GA | Available | VNet integration GA |251| Key Vault Premium | GA | `br/public:avm/res/key-vault/vault` | HSM-backed keys GA |252| Service Bus Premium | GA | `br/public:avm/res/service-bus/namespace` | Zone-redundant GA |253| DDoS Network Protection | GA | Available | Standard tier GA |254| Container Registry Premium | GA | `br/public:avm/res/container-registry/registry` | Geo-replication GA |255256> [!TIP]257> All recommended services are Generally Available (GA) with Azure Verified Modules where available. No preview or deprecated services in this architecture.258259---260261## Architecture Decision Summary262263| # | Decision | Options Considered | Choice | Rationale |264| --- | --- | --- | --- | --- |265| ADR-001 | Compute Platform | AKS vs. ACA | **AKS** | PCI CDE requires dedicated node pools, Kubernetes network policies, OPA Gatekeeper. ACA lacks node-level isolation. |266| ADR-002 | Database Strategy | PostgreSQL-only vs. PostgreSQL + Cosmos DB | **Dual DB** | Offloads session/cache reads from PostgreSQL. Reduces connection pressure at 10k TPS. Sub-10ms cache reads. |267| ADR-003 | Network Topology | Flat VNet vs. Hub-Spoke | **Hub-Spoke** | PCI-DSS Req 1 requires network segmentation. Azure Firewall Premium provides IDPS + east-west inspection. |268| ADR-004 | API Gateway | Front Door only vs. Front Door + APIM | **Front Door + APIM** | Front Door for WAF/DDoS at edge. APIM Premium for VNet-integrated API management inside CDE. |269| ADR-005 | Cosmos DB Consistency | Strong vs. Session vs. Eventual | **Session** | Read-your-writes for session state. Avoids Strong consistency latency penalty. Sufficient for cache/session use case. |270| ADR-006 | Multi-Region | Active-Active vs. Active-Passive | **Active-Passive** | Lower cost and complexity. RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup. Active-Active adds Cosmos DB multi-region write cost. |271| ADR-007 | DDoS Protection | IP Protection vs. Network Protection | **Network Protection** | Full VNet coverage for CDE. Higher cost ($2,944/mo) but covers all public IPs and provides advanced telemetry. |272| ADR-008 | Connection Pooling | PgBouncer vs. Azure-native | **PgBouncer sidecar** | Required at 10k TPS to prevent PostgreSQL connection exhaustion. Transaction mode with pool_size=200/pod. |273274---275276## Implementation Handoff277278### For Bicep Plan Agent2792801. **Network**: Hub VNet (firewall, bastion) + Spoke VNet (AKS, PostgreSQL, Cosmos DB, APIM). Private endpoints for all data services.2812. **Compute**: AKS with system node pool (D4s_v5 × 3) + user CDE node pool (D8s_v5 × 3-20). KEDA add-on. Workload Identity.2823. **Data**: PostgreSQL Flexible Server E16s v5 zone-redundant HA. Cosmos DB NoSQL autoscale 10K-50K RU/s.2834. **Security**: Key Vault Premium. Azure Firewall Premium. NSGs on all subnets. AKS network policies (Calico).2845. **Edge**: Front Door Premium + WAF policy. APIM Premium VNet-integrated.2856. **Messaging**: Service Bus Premium 1 MU.2867. **Monitoring**: Log Analytics workspace (1-year retention) + Application Insights + Defender for Cloud + Defender for Containers.2878. **DDoS**: Network Protection on hub VNet.2889. **Identity**: Managed identities for all service-to-service. Workload Identity for AKS pods. PIM for admin access.289290### AVM Modules to Use291292| Resource | AVM Module | Min Version |293| --- | --- | --- |294| AKS | `br/public:avm/res/container-service/managed-cluster` | Latest |295| Key Vault | `br/public:avm/res/key-vault/vault` | `0.11.0` |296| Cosmos DB | `br/public:avm/res/document-db/database-account` | `0.10.0` |297| Service Bus | `br/public:avm/res/service-bus/namespace` | `0.10.0` |298| Container Registry | `br/public:avm/res/container-registry/registry` | `0.6.0` |299| Virtual Network | `br/public:avm/res/network/virtual-network` | `0.5.0` |300| NSG | `br/public:avm/res/network/network-security-group` | `0.5.0` |301| Log Analytics | `br/public:avm/res/operational-insights/workspace` | `0.9.0` |302| Front Door | `br/public:avm/res/cdn/profile` | `0.7.0` |303304### Required Tags305306```bicep307tags: {308 Environment: environment // 'dev' | 'staging' | 'prod'309 ManagedBy: 'Bicep'310 Project: 'pci-dss-gw'311 Owner: '<to-be-confirmed>'312}313```314315---316317## Approval Gate318319| Pillar | Score | Confidence |320| --- | --- | --- |321| 🔒 Security | 9/10 | High |322| 🔄 Reliability | 8/10 | High |323| ⚡ Performance | 8/10 | Medium |324| 💰 Cost | 7/10 | Medium |325| 🔧 Operations | 8/10 | High |326| **Composite WAF Score** | **8.0/10** | |327328**Estimated Monthly Cost**: $13,328 – $19,032 (typical prod), up to ~$27,800 at peak scale329330> [!IMPORTANT]331> ⚠️ Composite SLA (99.93%) is slightly below 99.99% target. Mitigation: implement automated DR runbook to achieve operational SLA ≥ 99.99% with rapid failover. Alternatively, accept 99.95%+ with strong DR automation.332333**Top Risks**:3341. Composite SLA gap — mitigate with multi-region or accept 99.95%3352. DDoS + APIM Premium are large fixed costs ($5,739/mo combined) — validate necessity with QSA3363. Load testing not yet conducted — 15k TPS peak is untested assumption337338Reply **"approve"** to proceed to bicep-plan, or provide feedback.339340---341342## References343344> [!NOTE]345> 📚 The following Microsoft Learn resources provide additional guidance.346347| Topic | Link |348| --- | --- |349| AKS PCI-DSS Baseline | [AKS regulated cluster](https://learn.microsoft.com/azure/aks/operator-best-practices-cluster-security) |350| AKS Well-Architected Review | [AKS WAF review](https://learn.microsoft.com/azure/well-architected/service-guides/azure-kubernetes-service) |351| PostgreSQL Flexible Server HA | [HA concepts](https://learn.microsoft.com/azure/postgresql/flexible-server/concepts-high-availability) |352| Cosmos DB Consistency Levels | [Consistency levels](https://learn.microsoft.com/azure/cosmos-db/consistency-levels) |353| Azure Firewall Premium Features | [Firewall Premium](https://learn.microsoft.com/azure/firewall/premium-features) |354| Azure Front Door WAF | [WAF on Front Door](https://learn.microsoft.com/azure/web-application-firewall/afds/afds-overview) |355| API Management VNet Integration | [APIM VNet](https://learn.microsoft.com/azure/api-management/api-management-using-with-vnet) |356| PCI-DSS on Azure | [PCI compliance blueprint](https://learn.microsoft.com/azure/compliance/offerings/offering-pci-dss) |357| DDoS Protection Overview | [DDoS Protection](https://learn.microsoft.com/azure/ddos-protection/ddos-protection-overview) |358| Azure Well-Architected Framework | [WAF overview](https://learn.microsoft.com/azure/well-architected/) |359| Azure Pricing Calculator | [Pricing calculator](https://azure.microsoft.com/pricing/calculator/) |