-
Notifications
You must be signed in to change notification settings - Fork 95
Visual Architecture Map
This page collects the main visual references for the Azure Landing Zone Lab. Use it when explaining the lab to another engineer, reviewing a pull request, or deciding which profile to deploy.
![]()
This is the primary diagram for the current lab shape. It shows the hub-spoke deployment scope, governance layer, public entry points, shared services, workload spokes, disabled lab items, and validation outputs.
Use this map to understand how the root Terraform orchestration connects the major platform areas:
- Source and delivery through GitHub Actions.
- Governance and control plane.
- Hub VNet and shared connectivity.
- Identity, management, shared services, and workload spokes.
- Lab guardrails and optional production-like upgrades.
Use this when selecting cheap-lab, lab, dev, or prod. The diagram highlights expensive toggles, security posture, and the safest first deployment path.
This diagram is the security review map. It ties together identity, network exposure, data-plane hardening, CI policy gates, state/secrets, monitoring, cost controls, and break-glass handling.
This diagram gives the short view of the GitHub Actions workflow. The detailed workflow is documented in CI/CD Pipeline.
Use this as the validation order for local work, pull requests, and post-deployment checks.
This diagram documents how GitHub Actions authenticates to Azure, initializes the backend, and protects state through backup.
This is the operational rhythm for the lab: select a profile, plan, approve, apply, validate, and destroy safely.
These diagrams support the Network Topology and Security Model pages.
Use this map when adding new wiki pages. Architecture, scenarios, testing, modules, and reference pages should stay connected through the sidebar and cross-links.
- Architecture Overview
- Full Environment Inventory
- Network Topology
- Shared Services
- Workloads
- Module Reference
- Security Model
- Security Operations
- Identity and Access
- Governance and Policy
- Production Readiness Review
- Monitoring and Diagnostics
- Operations Runbooks
- Azure Portal Validation Evidence
- Cost Management
- Disaster Recovery and Resilience