# Step 2: Architecture Assessment - pci-dss-gw

> This is a PCI-DSS Level 1 payment gateway on Azure, designed for 10,000 TPS sustained throughput with 99.99% availability.

- Skill: `tools-only/step-2-architecture-assessment-pci-dss-gw-2` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add tools-only/step-2-architecture-assessment-pci-dss-gw-2`
- Raw SKILL.md: https://api.skillmd.com/api/skills/tools-only/step-2-architecture-assessment-pci-dss-gw-2/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: tools-only (https://skillmd.com/u/tools-only)
- Updated: 2026-09-29
- Page: https://skillmd.com/skills/tools-only/step-2-architecture-assessment-pci-dss-gw-2

---

# Step 2: Architecture Assessment - pci-dss-gw

> Generated by architect agent | 2026-02-09

---

## Requirements Validation ✅

| Requirement | Status | Notes |
| --- | --- | --- |
| 10,000 TPS sustained, 15,000 TPS peak | ✅ Validated | AKS with D8s_v5 nodes (3-20) supports horizontal scaling via KEDA |
| 99.99% SLA | ✅ Validated | Zone-redundant AKS + PostgreSQL HA + Cosmos DB multi-AZ achieves composite SLA |
| P50 ≤ 100 ms, P99 ≤ 500 ms | ✅ Validated | AKS in-cluster networking + Cosmos DB sub-10ms reads + PostgreSQL ≤ 20ms |
| PCI-DSS v4.0 Level 1 | ✅ Validated | AKS dedicated node pools, network policies, Firewall Premium IDPS, Key Vault HSM |
| GDPR / EU data residency | ✅ Validated | swedencentral primary, germanywestcentral failover — both EU |
| PostgreSQL for ACID transactions | ✅ Validated | Flexible Server Memory Optimized E16s v5, zone-redundant HA |
| Cosmos DB for session/cache | ✅ Validated | NoSQL API with Session consistency, autoscale RU/s |
| AKS over ACA | ✅ Validated | PCI CDE isolation requires dedicated node pools + Kubernetes network policies |
| Hub-spoke with Azure Firewall | ✅ Validated | Premium tier for IDPS, east-west traffic inspection per PCI-DSS Req 1 |
| DDoS Network Protection | ✅ Validated | Full VNet coverage for CDE — $2,944/mo |
| API Management Premium | ✅ Validated | VNet-integrated for CDE, OAuth, rate limiting — $2,795/mo |
| Budget range validated | ⚠️ Adjusted | Revised to $16,200 – $27,800/mo with all services included |

> [!IMPORTANT]
> All critical requirements from `01-requirements.md` are architecturally feasible. Budget has been refined with live Azure Pricing MCP data.

---

## Executive Summary

### Architecture Overview

This is a **PCI-DSS Level 1 payment gateway** on Azure, designed for 10,000 TPS sustained throughput with 99.99% availability. The architecture follows a **hub-spoke network topology** with AKS as the compute platform, PostgreSQL Flexible Server for transactional data, and Cosmos DB for low-latency session state.

### Primary Optimization Pillar

**Security** — PCI-DSS v4.0 Level 1 compliance drives architectural decisions. All other pillars are optimized within PCI constraints.

### Architecture Pattern

| Attribute | Value |
| --- | --- |
| **Pattern** | Hub-Spoke with Dedicated CDE |
| **Compute** | AKS Standard tier with zone-redundant node pools |
| **Data Tier** | PostgreSQL Flexible Server (ACID) + Cosmos DB (cache/session) |
| **Network Edge** | Azure Front Door Premium (WAF + DDoS) → Azure Firewall Premium (IDPS) → AKS |
| **API Layer** | API Management Premium (VNet-integrated) |
| **Messaging** | Service Bus Premium (dedicated capacity) |
| **Secrets** | Key Vault Premium (HSM-backed) |
| **Identity** | Entra ID + Workload Identity + PIM |
| **Monitoring** | Azure Monitor + Log Analytics (1-year retention) + Defender for Cloud |

### Key Architecture Decisions

| Decision | Choice | Rationale |
| --- | --- | --- |
| Compute platform | AKS over ACA | PCI CDE isolation via dedicated node pools, Kubernetes network policies, OPA Gatekeeper |
| Database strategy | Dual DB (PostgreSQL + Cosmos DB) | ACID for transactions + sub-10ms for session/cache; reduces PostgreSQL connection pressure |
| Network segmentation | Hub-spoke + Azure Firewall Premium | IDPS required for PCI-DSS Req 1; east-west inspection between CDE and non-CDE |
| API gateway | APIM Premium (VNet) + Front Door Premium | VNet integration keeps API gateway inside CDE; Front Door provides global WAF + DDoS |
| Cosmos DB consistency | Session consistency | Sufficient for session state; avoids Strong consistency latency penalty while ensuring read-your-writes |
| Multi-region strategy | Active-Passive | Minimizes cost and Cosmos DB complexity; RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup |

---

## WAF Pillar Assessment

### 🔒 Security — 9/10 (Confidence: High)

| Area | Score | Assessment |
| --- | --- | --- |
| **Identity & Access** | 9/10 | Entra ID + Workload Identity for all service-to-service auth. PIM for JIT admin access. No shared accounts or passwords. |
| **Network Security** | 9/10 | Hub-spoke with Azure Firewall Premium (IDPS), NSGs, AKS network policies. Private endpoints for all data services. No public endpoints for CDE. |
| **Data Protection** | 9/10 | AES-256 encryption at rest with CMK for cardholder data. TLS 1.2+ everywhere. Key Vault Premium (HSM) for cryptographic keys. Tokenization for PAN. |
| **Threat Detection** | 8/10 | Defender for Containers, Defender for Cloud, Azure Firewall IDPS. Container image scanning pre-deployment. |
| **Compliance** | 9/10 | PCI-DSS v4.0 controls mapped to Azure services. 1-year log retention. Tamper-proof audit trail via Log Analytics. |

**Strengths**: Comprehensive PCI-DSS control mapping. Zero-trust architecture with managed identity everywhere. HSM-backed key management.

**Gaps**: 
- Penetration testing schedule not yet defined (PCI Req 11)
- QSA validation of Azure Firewall IDPS as acceptable IDS/IPS control is pending

**Recommendations**:
1. Schedule quarterly penetration tests with a PCI-certified ASV
2. Implement Azure Policy deny rules for non-compliant configurations
3. Enable Defender for Key Vault for anomaly detection on cryptographic operations

---

### 🔄 Reliability — 8/10 (Confidence: High)

| Area | Score | Assessment |
| --- | --- | --- |
| **High Availability** | 9/10 | Zone-redundant AKS (3 AZs), PostgreSQL zone-redundant HA, Cosmos DB multi-AZ. Front Door global anycast. |
| **Disaster Recovery** | 7/10 | Active-passive to germanywestcentral. PostgreSQL geo-redundant backup (RPO ≤ 5 min). Manual failover process. |
| **Resilience** | 8/10 | KEDA autoscaling, pod disruption budgets, Service Bus dead-letter queues, idempotent transaction processing. |
| **Health Monitoring** | 8/10 | Liveness/readiness probes, Azure Monitor alerts, Defender continuous monitoring. Sub-minute alerting. |

**Strengths**: Zone-redundant deployment across all tiers. Idempotent transaction design prevents duplicate charges. Service Bus DLQ handles transient failures.

**Gaps**:
- Active-passive failover is manual — RTO ≤ 30 min depends on operator response time
- Cosmos DB failover to germanywestcentral is not yet configured
- No documented chaos engineering / game day testing plan

**Recommendations**:
1. Implement automated failover runbook with Azure Automation for RTO ≤ 15 min
2. Configure Cosmos DB multi-region with germanywestcentral as read-replica (can promote on failover)
3. Schedule quarterly chaos engineering tests (AKS node drain, zone failure simulation)

**Composite SLA Calculation**:

| Service | SLA | Zone-Redundant |
| --- | --- | --- |
| AKS Standard | 99.95% | 99.99% (with AZs) |
| PostgreSQL Flex HA | 99.99% | Yes |
| Cosmos DB (single-region) | 99.99% | Yes |
| Front Door Premium | 99.99% | Global |
| Azure Firewall | 99.99% | Yes (with AZs) |
| Key Vault | 99.99% | Yes |
| Service Bus Premium | 99.99% | Yes |

**Composite SLA**: 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% × 99.99% = **99.93%**

> [!WARNING]
> Composite SLA (99.93%) is below the 99.99% target. To achieve 99.99%, implement multi-region active-active for the most critical path (Front Door → AKS → PostgreSQL) or accept 99.95%+ with strong DR automation.

---

### ⚡ Performance — 8/10 (Confidence: Medium)

| Area | Score | Assessment |
| --- | --- | --- |
| **Throughput** | 8/10 | AKS D8s_v5 nodes (8 vCPU, 32 GB) with KEDA autoscaling. 3-20 nodes supports 10-15k TPS. PgBouncer for connection pooling. |
| **Latency** | 8/10 | In-region P50 ≤ 100ms achievable. Cosmos DB session reads ≤ 10ms. PostgreSQL ≤ 20ms with connection pooling. |
| **Scalability** | 8/10 | Horizontal pod autoscaling + cluster autoscaler. Cosmos DB autoscale RU/s. PostgreSQL read replicas for reporting. |
| **Caching** | 7/10 | Cosmos DB for session/cache. No dedicated Redis layer — may need for response caching under extreme load. |

**Strengths**: KEDA enables event-driven scaling tied to Service Bus queue depth. Dual-database architecture offloads read-heavy cache operations from PostgreSQL.

**Gaps**:
- No dedicated Redis cache for API response caching — Cosmos DB may add latency vs. Redis for hot-path caching
- Load testing plan not yet defined to validate 15k TPS peak
- PgBouncer configuration (pool size, mode) needs tuning for 10k TPS

**Recommendations**:
1. Conduct Azure Load Testing at 15k TPS to validate node count and latency targets
2. Consider Azure Cache for Redis (Enterprise, 6 GB) as a hot-path cache if Cosmos DB latency exceeds targets under load
3. Configure PgBouncer in transaction mode with pool_size = 200 per pod

---

### 💰 Cost — 7/10 (Confidence: Medium)

| Area | Score | Assessment |
| --- | --- | --- |
| **Right-Sizing** | 7/10 | D8s_v5 nodes are appropriate for 10k TPS. PostgreSQL E16s v5 may be oversized initially. |
| **Optimization** | 7/10 | Reserved instances recommended but not yet committed. Cosmos DB autoscale prevents over-provisioning. |
| **Monitoring** | 7/10 | Cost alerts should be configured. No FinOps process documented. |
| **Waste Prevention** | 6/10 | Dev/staging environments could use smaller SKUs. Spot nodes viable for non-CDE workloads. |

**Estimated Monthly Cost** (from Azure Pricing MCP — swedencentral):

| Category | Service | SKU | Unit Price | Monthly Cost |
| --- | --- | --- | --- | --- |
| 💻 Compute (AKS management) | AKS Standard | Standard | $0.60/hr | $438 |
| 💻 Compute (AKS nodes × 6 avg) | D8s_v5 Linux | Standard_D8s_v5 | ~$0.408/hr | $1,787 |
| 💾 Database (Primary) | PostgreSQL Flex Server | Memory Opt E16s v5 (16 vCores) | $2.056/hr | $1,501 |
| 💾 Database (Cache) | Cosmos DB NoSQL | Autoscale 10K-50K RU/s | $0.012/hr per 100 RU/s | $876 – $4,380 |
| 🔐 Security | Key Vault Premium | HSM-backed | $0.03/10K ops | $22+ |
| 🌐 Network | Azure Firewall Premium | Premium | $1.75/hr | $1,278 |
| 🌐 Network | Azure Front Door | Premium | ~$330 base + per-request | $500 – $1,200 |
| 🛡️ DDoS | DDoS Network Protection | Standard | Fixed monthly | $2,944 |
| 🔀 API Gateway | API Management | Premium (1 unit) | $3.829/hr | $2,795 |
| 📊 Monitoring | Log Analytics | Per-GB ingestion | $2.99/GB | $300 – $1,500 |
| 📦 Container Registry | ACR Premium | Premium | $0.333/day | $10+ |
| 📨 Messaging | Service Bus | Premium (1 MU) | $0.9275/hr | $677 |
| 👤 Identity | Entra ID P2 + PIM | Per-user | — | $200 – $500 |
| | **TOTAL** | | | **$13,328 – $19,032** |

> [!NOTE]
> 💰 Prices sourced from Azure Pricing MCP (swedencentral, 2026-02-09). Production with full HA (20 nodes, max Cosmos RU/s) could reach ~$27,800/mo. Reserved Instances (1-year) save ~35% on compute and PostgreSQL.

**Savings Opportunities**:

| Opportunity | Est. Savings | Effort |
| --- | --- | --- |
| 1-year Reserved Instances (AKS nodes + PostgreSQL) | ~35% on compute (~$1,150/mo) | Low |
| Spot nodes for non-CDE workloads (dev/test) | Up to 80% on dev compute | Medium |
| Cosmos DB autoscale floor (scale to zero off-peak) | 20-60% variable | Low |
| Log Analytics Commitment Tier (100 GB/day) | ~30% on ingestion | Low |
| Start with APIM Standard v2 → upgrade to Premium later | ~$2,100/mo initially | Medium — requires re-architecture for VNet |

---

### 🔧 Operations — 8/10 (Confidence: High)

| Area | Score | Assessment |
| --- | --- | --- |
| **IaC** | 9/10 | Bicep with Azure Verified Modules. GitOps for AKS config. Repeatable, auditable deployments. |
| **CI/CD** | 8/10 | GitHub Actions with blue-green deployment. Container image scanning in pipeline. Automated rollback. |
| **Monitoring** | 8/10 | Azure Monitor + Application Insights + Defender. Distributed tracing. Alert thresholds defined. |
| **Incident Response** | 7/10 | On-call rotation assumed but not documented. Runbook templates needed. |
| **Documentation** | 7/10 | Requirements doc comprehensive. Operations runbook, DR plan needed before go-live. |

**Strengths**: Full IaC approach with Bicep/AVM. Blue-green deployment minimizes downtime. Container scanning gates prevent vulnerable images.

**Gaps**:
- No documented incident response playbook specific to payment failures
- Runbook for database failover not yet created
- Change management process for PCI CDE changes undefined

**Recommendations**:
1. Create payment transaction failure runbook with escalation paths
2. Document CDE change management process for PCI-DSS Req 6 compliance
3. Implement GitOps (Flux v2) for AKS workload deployments with audit trail

---

## Resource SKU Recommendations

| Resource | Recommended SKU | Region | Justification |
| --- | --- | --- | --- |
| **AKS** | Standard tier, D8s_v5 nodes | swedencentral | 8 vCPU/32 GB per node. Standard tier required for financial SLA. Zone-redundant node pools. |
| **PostgreSQL Flexible Server** | Memory Optimized E16s v5, 16 vCores | swedencentral | Memory-optimized for write-heavy payment transactions. Zone-redundant HA. |
| **Cosmos DB** | NoSQL API, Autoscale 10K-50K RU/s | swedencentral | Session consistency. Autoscale handles variable session/cache load. |
| **Azure Firewall** | Premium | swedencentral | IDPS capability required for PCI-DSS network segmentation. |
| **Azure Front Door** | Premium | Global | WAF with OWASP 3.2, bot protection, DDoS at edge. |
| **API Management** | Premium (1 unit) | swedencentral | VNet integration required for CDE. OAuth, rate limiting per merchant. |
| **Key Vault** | Premium (HSM-backed) | swedencentral | PCI-DSS requires HSM for cryptographic key storage. |
| **Service Bus** | Premium (1 Messaging Unit) | swedencentral | Dedicated capacity for transaction queues. Dead-letter support. |
| **Container Registry** | Premium | swedencentral | Geo-replication to failover region. Vulnerability scanning. Content trust. |
| **Log Analytics** | Per-GB (Analytics Logs) | swedencentral | $2.99/GB. 1-year retention for PCI-DSS § 10.7. |
| **DDoS Protection** | Network Protection (Standard) | swedencentral | Full VNet coverage for CDE network. $2,944/mo fixed. |

### Service Maturity Assessment

| Service | GA Status | AVM Module | Notes |
| --- | --- | --- | --- |
| AKS | GA | `br/public:avm/res/container-service/managed-cluster` | Production-ready, well-documented PCI guidance |
| PostgreSQL Flexible Server | GA | Available | Zone-redundant HA, read replicas GA |
| Cosmos DB NoSQL | GA | `br/public:avm/res/document-db/database-account` | Autoscale GA, PITR GA |
| Azure Firewall Premium | GA | Available | IDPS GA, TLS inspection GA |
| Azure Front Door Premium | GA | `br/public:avm/res/cdn/profile` | WAF policies GA |
| API Management Premium | GA | Available | VNet integration GA |
| Key Vault Premium | GA | `br/public:avm/res/key-vault/vault` | HSM-backed keys GA |
| Service Bus Premium | GA | `br/public:avm/res/service-bus/namespace` | Zone-redundant GA |
| DDoS Network Protection | GA | Available | Standard tier GA |
| Container Registry Premium | GA | `br/public:avm/res/container-registry/registry` | Geo-replication GA |

> [!TIP]
> All recommended services are Generally Available (GA) with Azure Verified Modules where available. No preview or deprecated services in this architecture.

---

## Architecture Decision Summary

| # | Decision | Options Considered | Choice | Rationale |
| --- | --- | --- | --- | --- |
| ADR-001 | Compute Platform | AKS vs. ACA | **AKS** | PCI CDE requires dedicated node pools, Kubernetes network policies, OPA Gatekeeper. ACA lacks node-level isolation. |
| ADR-002 | Database Strategy | PostgreSQL-only vs. PostgreSQL + Cosmos DB | **Dual DB** | Offloads session/cache reads from PostgreSQL. Reduces connection pressure at 10k TPS. Sub-10ms cache reads. |
| ADR-003 | Network Topology | Flat VNet vs. Hub-Spoke | **Hub-Spoke** | PCI-DSS Req 1 requires network segmentation. Azure Firewall Premium provides IDPS + east-west inspection. |
| ADR-004 | API Gateway | Front Door only vs. Front Door + APIM | **Front Door + APIM** | Front Door for WAF/DDoS at edge. APIM Premium for VNet-integrated API management inside CDE. |
| ADR-005 | Cosmos DB Consistency | Strong vs. Session vs. Eventual | **Session** | Read-your-writes for session state. Avoids Strong consistency latency penalty. Sufficient for cache/session use case. |
| ADR-006 | Multi-Region | Active-Active vs. Active-Passive | **Active-Passive** | Lower cost and complexity. RPO ≤ 5 min achievable with geo-redundant PostgreSQL backup. Active-Active adds Cosmos DB multi-region write cost. |
| ADR-007 | DDoS Protection | IP Protection vs. Network Protection | **Network Protection** | Full VNet coverage for CDE. Higher cost ($2,944/mo) but covers all public IPs and provides advanced telemetry. |
| ADR-008 | Connection Pooling | PgBouncer vs. Azure-native | **PgBouncer sidecar** | Required at 10k TPS to prevent PostgreSQL connection exhaustion. Transaction mode with pool_size=200/pod. |

---

## Implementation Handoff

### For Bicep Plan Agent

1. **Network**: Hub VNet (firewall, bastion) + Spoke VNet (AKS, PostgreSQL, Cosmos DB, APIM). Private endpoints for all data services.
2. **Compute**: AKS with system node pool (D4s_v5 × 3) + user CDE node pool (D8s_v5 × 3-20). KEDA add-on. Workload Identity.
3. **Data**: PostgreSQL Flexible Server E16s v5 zone-redundant HA. Cosmos DB NoSQL autoscale 10K-50K RU/s.
4. **Security**: Key Vault Premium. Azure Firewall Premium. NSGs on all subnets. AKS network policies (Calico).
5. **Edge**: Front Door Premium + WAF policy. APIM Premium VNet-integrated.
6. **Messaging**: Service Bus Premium 1 MU.
7. **Monitoring**: Log Analytics workspace (1-year retention) + Application Insights + Defender for Cloud + Defender for Containers.
8. **DDoS**: Network Protection on hub VNet.
9. **Identity**: Managed identities for all service-to-service. Workload Identity for AKS pods. PIM for admin access.

### AVM Modules to Use

| Resource | AVM Module | Min Version |
| --- | --- | --- |
| AKS | `br/public:avm/res/container-service/managed-cluster` | Latest |
| Key Vault | `br/public:avm/res/key-vault/vault` | `0.11.0` |
| Cosmos DB | `br/public:avm/res/document-db/database-account` | `0.10.0` |
| Service Bus | `br/public:avm/res/service-bus/namespace` | `0.10.0` |
| Container Registry | `br/public:avm/res/container-registry/registry` | `0.6.0` |
| Virtual Network | `br/public:avm/res/network/virtual-network` | `0.5.0` |
| NSG | `br/public:avm/res/network/network-security-group` | `0.5.0` |
| Log Analytics | `br/public:avm/res/operational-insights/workspace` | `0.9.0` |
| Front Door | `br/public:avm/res/cdn/profile` | `0.7.0` |

### Required Tags

```bicep
tags: {
  Environment: environment    // 'dev' | 'staging' | 'prod'
  ManagedBy: 'Bicep'
  Project: 'pci-dss-gw'
  Owner: '<to-be-confirmed>'
}
```

---

## Approval Gate

| Pillar | Score | Confidence |
| --- | --- | --- |
| 🔒 Security | 9/10 | High |
| 🔄 Reliability | 8/10 | High |
| ⚡ Performance | 8/10 | Medium |
| 💰 Cost | 7/10 | Medium |
| 🔧 Operations | 8/10 | High |
| **Composite WAF Score** | **8.0/10** | |

**Estimated Monthly Cost**: $13,328 – $19,032 (typical prod), up to ~$27,800 at peak scale

> [!IMPORTANT]
> ⚠️ Composite SLA (99.93%) is slightly below 99.99% target. Mitigation: implement automated DR runbook to achieve operational SLA ≥ 99.99% with rapid failover. Alternatively, accept 99.95%+ with strong DR automation.

**Top Risks**:
1. Composite SLA gap — mitigate with multi-region or accept 99.95%
2. DDoS + APIM Premium are large fixed costs ($5,739/mo combined) — validate necessity with QSA
3. Load testing not yet conducted — 15k TPS peak is untested assumption

Reply **"approve"** to proceed to bicep-plan, or provide feedback.

---

## References

> [!NOTE]
> 📚 The following Microsoft Learn resources provide additional guidance.

| Topic | Link |
| --- | --- |
| AKS PCI-DSS Baseline | [AKS regulated cluster](https://learn.microsoft.com/azure/aks/operator-best-practices-cluster-security) |
| AKS Well-Architected Review | [AKS WAF review](https://learn.microsoft.com/azure/well-architected/service-guides/azure-kubernetes-service) |
| PostgreSQL Flexible Server HA | [HA concepts](https://learn.microsoft.com/azure/postgresql/flexible-server/concepts-high-availability) |
| Cosmos DB Consistency Levels | [Consistency levels](https://learn.microsoft.com/azure/cosmos-db/consistency-levels) |
| Azure Firewall Premium Features | [Firewall Premium](https://learn.microsoft.com/azure/firewall/premium-features) |
| Azure Front Door WAF | [WAF on Front Door](https://learn.microsoft.com/azure/web-application-firewall/afds/afds-overview) |
| API Management VNet Integration | [APIM VNet](https://learn.microsoft.com/azure/api-management/api-management-using-with-vnet) |
| PCI-DSS on Azure | [PCI compliance blueprint](https://learn.microsoft.com/azure/compliance/offerings/offering-pci-dss) |
| DDoS Protection Overview | [DDoS Protection](https://learn.microsoft.com/azure/ddos-protection/ddos-protection-overview) |
| Azure Well-Architected Framework | [WAF overview](https://learn.microsoft.com/azure/well-architected/) |
| Azure Pricing Calculator | [Pricing calculator](https://azure.microsoft.com/pricing/calculator/) |

