Architecture Overview¶
Architecture view
AzAWSLab architecture is organised around design principles, lifecycle domains, layered controls, and the engineering decisions behind the realistic Microsoft hybrid enterprise environment and Release 2 platform build-out.
Design principles¶
Four principles shape the platform design across releases, Terraform roots, network paths, and automation workflows.
| Principle | What it means in AzAWSLab |
|---|---|
| Evidence before assertion | Platform claims are routed to screenshots, logs, source files, workflow records, and public-safe design documents. The Proof Gallery organises those routes by lifecycle domain. |
| Lifecycle boundaries | Platform components are grouped by lifecycle domain: hybrid workplace, delivery engineering, network engineering, private platform services, operations engineering, and AI governance. Those boundaries appear in Terraform root isolation, evidence routes, and Engineering Deep Dive notes. |
| Secure by default, inspectable by design | Core platform paths use controlled routing, inspection points, private access patterns, and validation evidence rather than default public exposure. |
| Automation as a governed control plane | GitHub Actions OIDC, Terraform state boundaries, Ansible, and AWX move automation from operator-local scripts into reviewable, repeatable execution paths. |
Layered architecture model¶
Security is built into the lifecycle domains rather than added after delivery. It is embedded across identity, endpoint, network, private platform services, operations, and AI governance.
+---------------------------------------------------+
| Identity and Access |
| Entra Connect, Conditional Access, MFA, |
| device compliance, Microsoft 365 access |
+---------------------------------------------------+
|
+---------------------------------------------------+
| Endpoint and Data |
| Intune, Autopilot, BitLocker, Windows LAPS, |
| Defender controls, Purview, DLP, labels |
+---------------------------------------------------+
|
+---------------------------------------------------+
| Network and Inspection |
| Hub-spoke routing, Azure Firewall, FortiGate, |
| IPSec, BGP, AWS branch, private access paths |
+---------------------------------------------------+
|
+---------------------------------------------------+
| Platform Services |
| Private AKS, Kubernetes policy context, AVD, |
| FSLogix, private platform administration |
+---------------------------------------------------+
|
+---------------------------------------------------+
| Operations and Resilience |
| Azure Monitor, Sentinel, Defender for Cloud, |
| Recovery Services Vault, backup validation, BCDR |
+---------------------------------------------------+
|
+---------------------------------------------------+
| AI Operations Governance |
| O6 evidence, policy-mediated tool use, |
| human approval boundaries, decision logs |
+---------------------------------------------------+
Each layer has an Engineering Deep Dive route and a Proof Gallery route.
Lifecycle domains¶
The platform is organised across six lifecycle domains.
| Lifecycle domain | Scope | Entry point |
|---|---|---|
| Hybrid Workplace | Identity, Exchange Hybrid, Microsoft 365 services, endpoint management, Microsoft Graph PowerShell operations, and operational visibility. | Engineering: Hybrid Workplace |
| Delivery Engineering | Terraform state boundaries, GitHub Actions OIDC, code traceability, and governed delivery workflows. | Engineering: Delivery Engineering |
| Network Engineering | Hub-spoke routing, Azure Firewall, FortiGate inspection, IPSec, BGP, AWS branch integration, and route validation. | Engineering: Network Engineering |
| Platform Services | Private AKS, AVD secure workspace, FSLogix, and private platform integration. | Engineering: Platform Services |
| Operations Engineering | Azure Monitor, Sentinel, Defender for Cloud, Recovery Services Vault, backup validation, soft-delete handling, and BCDR. | Engineering: Operations Engineering |
| AI Governance | AI Operations Enclave, evidenced through O6, policy-mediated tool use, human approval boundaries, and companion local AI lab context. | AI Operations Enclave |
Key architectural decisions¶
1. Multi-root Terraform with isolated state¶
The platform avoids one monolithic Terraform root. Separate roots divide networking, management, shared services, AKS, AVD, governance, workload, and AWS branch ownership. That separation limits blast radius and makes ownership easier to review.
2. OIDC-based delivery with GitHub Actions¶
GitHub Actions uses OpenID Connect for workflow-controlled Azure authentication without routine long-lived deployment credentials. This keeps deployment identity tied to reviewable workflow evidence and reduces reliance on stored deployment secrets.
3. Code traceability across source, workflow, and evidence¶
Delivery authentication and implementation traceability are treated as separate concerns. Code Traceability shows how source files, workflow records, documentation, and evidence routes connect platform claims to reviewable implementation evidence.
4. BGP-driven hybrid and multi-cloud transit¶
The network architecture includes on-premises routing, Azure hub-spoke design, IPSec, BGP, AWS branch routing, and inspection context. The architectural value is route control across hybrid and multi-cloud paths, not basic connectivity alone.
Hybrid BGP Multi-Cloud Transit and Hybrid Multi-Cloud Networking
5. Private platform services for AKS and AVD¶
AKS and AVD are implemented as private platform services rather than default compute deployments. The design emphasises private access, route control, compliance context, Kubernetes source, and inspected integration paths.
Private AKS Platform, AVD Secure Workspace, and Private AKS and AVD Architecture
6. Governed automation with AWX¶
Ansible and AWX provide a governed automation control plane with source-controlled runbooks, inventories, job templates, and execution records. This keeps operations reviewable and repeatable beyond local script execution.
7. Operational resilience and AI operations under policy governance¶
Operational resilience is routed through monitoring, alert validation, Defender for Cloud, Sentinel, backup controls, soft-delete handling, and BCDR planning. AI operations are represented through the AI Operations Enclave, evidenced through O6, with policy-mediated tool use, bounded tool access, structured decision records, namespace lifecycle evidence, and cleanup checks.
Monitoring, Backup and Resilience, AI Operations Enclave, and Companion Local AI Lab
Platform evolution¶
Release 3 carries the existing multi-cloud routing, private platform services, and operational governance work toward cross-cloud Kubernetes, GitOps, DevSecOps scanning, observability, and resilience.
Where to see the evidence¶
- Proof Gallery - curated evidence dashboard for the major platform capabilities.
- Skills Matrix - skills map with links to engineering notes and proof routes.
- Engineering Deep Dive - engineering notes with design rationale, implementation context, and evidence maps.
- GitHub Repository - public-safe screenshots, logs, Terraform code, documentation, workflows, and evidence folders.