-
Notifications
You must be signed in to change notification settings - Fork 795
Mx Azure draft #8901
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Mx Azure draft #8901
Changes from all commits
Commits
Show all changes
19 commits
Select commit
Hold shift + click to select a range
647154f
Mx Azure beta
katarzyna-koltun-mx ec6a84c
updates
katarzyna-koltun-mx f04ad1b
mx azure beta
katarzyna-koltun-mx 2f1d991
mx azure
katarzyna-koltun-mx 4647964
Merge branch 'development' into kk-azu-beta
katarzyna-koltun-mx e678176
draft
katarzyna-koltun-mx ba3f185
draft
katarzyna-koltun-mx 26f2745
Mx Azure intro
katarzyna-koltun-mx 95b80fa
Update _index.md
katarzyna-koltun-mx 5b047b0
Update _index.md
katarzyna-koltun-mx fd84a3e
Merge branch 'development' into kk-azu-beta
katarzyna-koltun-mx e993ac2
updates
katarzyna-koltun-mx 44eca6a
sme review
katarzyna-koltun-mx 19332ac
updates
katarzyna-koltun-mx f7c0f8e
Azure SME
katarzyna-koltun-mx 8fb3b53
Merge branch 'development' into kk-azu-beta
katarzyna-koltun-mx 386a70e
Merge branch 'development' into kk-azu-beta
katarzyna-koltun-mx dfe6551
sme updates
katarzyna-koltun-mx 5ac351a
updated date
katarzyna-koltun-mx File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,93 @@ | ||
| --- | ||
| title: "Mendix on Azure" | ||
| url: /developerportal/deploy/mendix-on-azure/ | ||
| description: "Presents documentation on deploying your Mendix app on Microsoft Azure." | ||
| weight: 42 | ||
| no_list: false | ||
| description_list: true | ||
| --- | ||
|
|
||
| {{% alert color="info" %}} This feature is currently available to participating customers. For more information, contact your Customer Success Manager. {{% /alert %}} | ||
|
|
||
| ## Introduction | ||
|
|
||
| Mendix on Azure provides a simplified, integrated way to deploy Mendix applications to a Microsoft Azure environment. With this solution, users are empowered to deploy their Mendix applications in Azure environments without the need for intricate infrastructure setup in cloud services. They can also seamlessly manage infrastructure services through an intuitive user interface. No matter their IT skills, users can realize their project value quickly and securely with Azure. | ||
|
|
||
| ## Benefits of Mendix on Azure | ||
|
|
||
| By eliminating manual setup and maintenance, Mendix on Azure allows your teams to: | ||
|
|
||
| * Focus on developing business value instead of configuring infrastructure. | ||
| * Avoid delays caused by cross-team dependencies or architectural discussions. | ||
| * Accelerate time-to-market for critical applications. | ||
| * Address deployment and operational bottlenecks by automating the setup and management of Mendix applications on Azure. | ||
| * Eliminate the need for specialized cloud engineers and reduce setup time to under 30 minutes. | ||
| * Focus on innovation and deliver value faster, reduces labor costs, and ensure consistency, security, and compliance. | ||
|
|
||
| ## Mendix on Azure and Mendix for Private Cloud | ||
|
|
||
| Mendix on Azure is a new deployment option that makes use of some of the features of Mendix for Private Cloud, but does so in an opinionated way. | ||
|
|
||
| Mendix for Private Cloud offers its users flexibility coupled with the ability to keep their deployment within their enterprise firewall, but requires more effort to configure and more time to value than deployments on Mendix Cloud. | ||
|
|
||
| Mendix on Azure builds on that by providing an automated, preconfigured solution with access to private customer networks, which can be deployed in 30 minutes by a user without IT skills at no extra operational costs. The architecture, its maintenance, updates, and security hardening are all fully managed by Mendix. This helps prevent issues with setting up the infrastructure, which can sometimes be very technical and complicated for citizen developers. | ||
|
|
||
| ## Architecture | ||
|
|
||
| Mendix on Azure provides a managed service to host Mendix apps in an Azure subscription you own. The Mendix on Azure service is composed of several underlying Azure services combined with the following Mendix-specific components: | ||
|
|
||
| * [Mendix Runtime](/refguide/runtime/) | ||
| * [Mendix Operator](/developerportal/deploy/private-cloud-cluster/) | ||
| * [Mendix Agent](/developerportal/deploy/private-cloud-cluster/) | ||
|
|
||
| Mendix operates all services and components within the scope of the Mendix on Azure service for you. The service leverages several underlying Azure services that are preconfigured to optimally host your Mendix apps. | ||
|
|
||
| ### Components | ||
|
|
||
| Mendix deploys, operates and is responsible for overall service functionality of the following components as part of Mendix on Azure: | ||
|
|
||
| * Azure Kubernetes Service with Managed NGINX Ingress Controller (app routing add-on) | ||
| * Azure PostgreSQL Flexible Server | ||
| * Azure Container Registry | ||
| * Azure Blob Storage | ||
| * Azure Managed Grafana | ||
| * Azure Managed Prometheus | ||
| * Azure Virtual Network with private endpoints and private DNS zones | ||
| * Mendix Runtime | ||
| * Mendix Operator | ||
| * Mendix Agent | ||
|
|
||
| You cannot alter these managed components yourself beyond what is offered in the Mendix on Azure and Mendix Private Cloud self-service portals. Mendix limits customization to ensure a consistent, predictable, and scalable customer experience. | ||
|
|
||
| ### Diagram | ||
|
|
||
| The diagram in this section presents the high-level architecture of the Mendix for Azure solution. | ||
|
|
||
| {{< figure src="/attachments/deployment/mx-azure/architecture.png" class="no-border" >}} | ||
|
|
||
| The architecture is assessed against the [Azure well-architected framework](https://learn.microsoft.com/en-us/azure/well-architected/) to ensure its reliability, accessibility, and performance. | ||
|
|
||
| ## Security | ||
|
|
||
| Mendix accesses customer environments in a secure, auditable way: | ||
|
|
||
| * We use [cross-tenant access](https://learn.microsoft.com/en-us/entra/external-id/cross-tenant-access-overview), which is native to Azure and complies with Microsoft best practices. | ||
| * Most access is performed programmatically, that is, by the system rather than manually by normal users. There is usually no human intervention into the customer environments. | ||
| * In rare cases where human intervention is required, for example, because of a support request that requires access to the customer environment to resolve, the access is automated, auditable, and governed by Mendix support processes. The Mendix employee working on the support request receives temporary access which is then revoked. | ||
| * The network connectivity is done using a private Azure link service, not through the public internet. | ||
|
|
||
| ### SOC 2 Type 2 Compliance Exceptions | ||
|
|
||
| The Azure Policy add-on is not enabled inside Mendix Azure clusters, because Mendix can control which workloads can access the cluster. Because of that, the following exceptions to the SOC 2 Type 2 policy are considered acceptable: | ||
|
katarzyna-koltun-mx marked this conversation as resolved.
|
||
|
|
||
| * Azure Container Registry: | ||
| * [Container registries should be encrypted with a customer-managed key](https://www.azadvertizer.net/azpolicyadvertizer/5b9159ae-1701-4a6f-9a7a-aa9c8ddd0580.html) - The standard Microsoft key is used instead. | ||
| * AKS - cluster resource: | ||
| * [Azure Policy Add-on for Kubernetes service (AKS) should be installed and enabled on your clusters](https://www.azadvertizer.net/azpolicyadvertizer/0a15ec92-a229-4763-bb14-0ea34a568f8d.html) - The cluster is deployed and managed by Mendix, so the policy is not needed. | ||
| * [Azure Kubernetes Service clusters should have Defender profile enabled](https://www.azadvertizer.net/azpolicyadvertizer/a1840de2-8088-4ea8-b153-b4c723e9cb01.html) - This is not automated for cost-saving reasons. | ||
| * AKS - cluster VNET: | ||
| * [All Internet traffic should be routed via your deployed Azure Firewall](https://www.azadvertizer.net/azpolicyadvertizer/fc5e4038-4584-4632-8c85-c0448d374b2c.html) - This is not automated, but the customer can deploy their own Firewall if required. | ||
| * Storage Account: | ||
| * [Storage accounts should use customer-managed key for encryption](https://www.azadvertizer.net/azpolicyadvertizer/6fac406b-40ca-413b-bf8e-0bf964659c25.html) - The cluster is deployed and managed by Mendix, so this is not needed. | ||
|
|
||
| ## Read More | ||
60 changes: 60 additions & 0 deletions
60
content/en/docs/deployment/mx-azure/mx-azure-getting-started.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,60 @@ | ||
| --- | ||
| title: "Getting Started with Mendix on Azure" | ||
| url: /developerportal/deploy/mendix-on-azure/quickstart/ | ||
| description: "Documents the pre-implementation tasks for Mendix on Azure." | ||
| weight: 10 | ||
| --- | ||
|
|
||
| {{% alert color="info" %}} This feature is currently available to participating customers. For more information, contact your Customer Success Manager. {{% /alert %}} | ||
|
|
||
| ## Introduction | ||
|
|
||
| Before you can deploy your Mendix app on Azure, you must plan and complete a number of pre-implementation tasks. | ||
|
|
||
|
katarzyna-koltun-mx marked this conversation as resolved.
|
||
| ## Prerequisites | ||
|
katarzyna-koltun-mx marked this conversation as resolved.
|
||
|
|
||
| To adopt Mendix on Azure, you need to have the following: | ||
|
|
||
| * A Mendix account; Mendix Studio Pro 10.10 or newer is required | ||
| * As an optional best practice, add multiple cluster manager to your clusters | ||
| * An Azure account with the following permissions: | ||
| * Permission to grant admin consent on the Mendix on Azure portal app registration | ||
| * Owner or Contributor role assigned on the target subscription level | ||
|
|
||
| {{% alert color="info" %}} To comply with the principle of least privilege, you can also create a custom role for the Mendix Operator instead of assigning the Owner or Contributor role. For the required permissions, see below: | ||
|
|
||
| ```text | ||
| { | ||
| "properties": { | ||
| "roleName": "Mendix on Azure Operator", | ||
| "description": "", | ||
| "assignableScopes": [ | ||
| "/subscriptions/<yoursubscriptionid>" | ||
| ], | ||
| "permissions": [ | ||
| { | ||
| "actions": [ | ||
| "*/register/action", | ||
| "Microsoft.Solutions/applications/*", | ||
| "Microsoft.Solutions/locations/operationstatuses/*", | ||
| "Microsoft.Resources/subscriptions/resourceGroups/*", | ||
| "Microsoft.Resources/deployments/*", | ||
| "Microsoft.Monitor/accounts/*", | ||
| "Microsoft.Authorization/roleAssignments/write", | ||
| "Microsoft.Authorization/roleAssignments/read" | ||
| ], | ||
| "notActions": [], | ||
| "dataActions": [], | ||
| "notDataActions": [] | ||
| } | ||
| ] | ||
| } | ||
| } | ||
| ``` | ||
| {{% /alert %}} | ||
|
|
||
| ## Licensing | ||
|
katarzyna-koltun-mx marked this conversation as resolved.
|
||
|
|
||
| Mendix on Azure is available for purchase from the the [Azure Marketplace](https://azuremarketplace.microsoft.com/). Connecting to Azure services may also include additional cost. For more information, refer to Azure documentation. | ||
|
|
||
| For production environments, you also need a license for your Mendix app. For more information, refer to [Licensing Apps](/developerportal/deploy/licensing-apps-outside-mxcloud/). | ||
79 changes: 79 additions & 0 deletions
79
content/en/docs/deployment/mx-azure/mx-azure-installation.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,79 @@ | ||
| --- | ||
| title: "Installing and Configuring Mendix on Azure" | ||
| url: /developerportal/deploy/mendix-on-azure/installation/ | ||
| description: "Documents the initial configuration tasks for Mendix on Azure." | ||
| weight: 20 | ||
| --- | ||
|
|
||
| {{% alert color="info" %}} This feature is currently available to participating customers. For more information, contact your Customer Success Manager. {{% /alert %}} | ||
|
|
||
| ## Introduction | ||
|
|
||
| To get started with your Mendix on Azure deployment, you must first register your Microsoft Azure cloud cluster in the Mendix Portal. This will provide you with the resources required to deploy the Mendix Operator and host your Mendix app in an Azure deployment. | ||
|
|
||
| ### Prerequisites | ||
|
|
||
| Before starting the installation and implementation process, make sure that you have all the necessary prerequisites: | ||
|
|
||
| * Obtain and configure a Microsoft Azure account. For more information, refer to the the Microsoft Azure documentation. | ||
| * Purchase the Mendix on Azure offering in the [Azure Marketplace](https://azuremarketplace.microsoft.com/). | ||
| * Familiarize yourself with the [Private Cloud](https://docs.mendix.com/developerportal/deploy/private-cloud/) concepts. | ||
| * Ensure that your Mendix Studio Pro is in version 10.10 or newer. | ||
| * As an optional best practice, add multiple cluster manager to your clusters. | ||
|
|
||
| ## Creating an Azure Cluster | ||
|
|
||
| To create a cluster for your Mendix on Azure app, perform the following steps: | ||
|
|
||
| 1. In the Mendix Portal, in Private Cloud Cluster Manager, click **Mendix on Azure**. | ||
| 2. Connect to your Azure account by clicking **Connect and Initialize**, and then logging in with the same account that you used to purchase the Mendix on Azure offering. | ||
|
|
||
| After you successfully connect the accounts, the Mendix Portal shows a list of available clusters (that is, any Azure clusters that you have already linked with Mendix) and initializable clusters (that is, any clusters that you have not yet linked with Mendix). For initialized clusters, means that the all the required resources are provisioned on the cluster. For uninitialized clusters, no resources are provisioned yet. | ||
|
|
||
| {{< figure src="/attachments/deployment/mx-azure/available-clusters.png" class="no-border" >}} | ||
|
|
||
| 3. In the Microsoft Azure portal, add a new managed Mendix on Azure application with **Standard** as the plan. | ||
|
|
||
| {{< figure src="/attachments/deployment/mx-azure/create-managed-app.png" class="no-border" >}} | ||
|
|
||
| 4. Provide a name for the resource group. The resource group contains all the resources that must be initialized for your Mendix deployment. | ||
|
|
||
| {{< figure src="/attachments/deployment/mx-azure/resource-group-name.png" class="no-border" >}} | ||
|
|
||
| 5. Follow the **Create** wizard to create the managed application. | ||
|
|
||
| 6. After the resource deployment finishes, click **Go to resource**, and then click **Mendix on Azure Portal**. | ||
|
|
||
| The managed app that you created is now visible as a new initializable cluster. | ||
|
|
||
| {{< figure src="/attachments/deployment/mx-azure/initializable-clusters.png" class="no-border" >}} | ||
|
|
||
| 7. Click **Initialize**. | ||
|
|
||
| The preflight check launches to verify that the required resources can be registered in the cluster. Mendix apps are hosted with virtual images, so the preflight check determines whether the cluster contains the required type of virtual image. To view a list of the required resource providers, hover your cursor over the **Information** icon. If required, you can register any missing providers in the **Resource providers** section of the Microsoft Azure portal. | ||
|
|
||
| 8. After the preflight check completes, click **Next**. | ||
|
|
||
| 9. Select the **AKS Service Tier**. | ||
|
|
||
| You can choose any tier that suits your requirements. Higher tiers will incur higher costs. | ||
|
|
||
| 10. Click **Initialize**. | ||
|
|
||
| The initialization process takes ca. 15 minutes. It creates a resource group in the managed app that you created in step 3 above. Once the cluster is initialized successfully, a corresponding cluster and namespace are created in the the Private Cloud portal. The namespace is also configured automatically, as described in [Standard Operator: Running the Tool](https://docs.mendix.com/developerportal/deploy/standard-operator/#running-the-tool). The cluster cannot be deleted from the Private Cloud portal. If you want to remove it, you must delete it in the Microsoft Azure portal. | ||
|
|
||
| ## Deploying an App to an Azure Cluster | ||
|
|
||
| After creating your cluster in Microsoft Azure, you can deploy now deploy your applications to the cluster. The deployment process is the same as with Mendix for Private Cloud. For more information, see [Deploying a Mendix App to a Private Cloud Cluster](/developerportal/deploy/private-cloud-deploy/). | ||
|
|
||
| ## Editing the Cluster in the Mendix on Azure Portal | ||
|
|
||
| If required, you can change the following options for your cluster: | ||
|
|
||
| * AKS service tier | ||
| * AKS node size | ||
| * VM type | ||
| * Load balancer type | ||
| * Postgres compute SKU | ||
| * Postgres performance tier for storage IOPS | ||
| * Custom tags |
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.