Lesson 24 / 25

The Azure Well-Architected Framework

Review an Azure design against the five Well-Architected pillars.

Five pillars for design reviews

Microsoft's Azure Well-Architected Framework organises design guidance into five pillars. Reliability: zones, multi-region where needed, health probes, retries, backups and tested recovery. Security: identity first, least privilege, private networking, encryption, secrets in Key Vault. Cost Optimization: right-sizing, autoscale, commitments, tags and budgets. Operational Excellence: infrastructure as code, CI/CD, observability and safe deployment practices. Performance Efficiency: choosing the right service and tier, scaling out, caching and load testing. The pillars trade off against each other: multi-region active-active improves reliability but costs more. Also understand SLAs: if a request depends on two services in series, the composite availability is roughly the product, so 99.95% × 99.99% ≈ 99.94%, lower than either one.

A reference shape for a small production web app

A common starting point that touches every pillar.

users
  -> Azure Front Door (WAF, TLS, global routing, caching)
    -> App Service or Container Apps (2+ instances, zone redundant, autoscale)
         | managed identity
         +-> Azure SQL / PostgreSQL Flexible (zone-redundant HA, PITR backups)
         +-> Storage account (ZRS, private endpoint, lifecycle rules)
         +-> Key Vault (RBAC, purge protection) via Key Vault references
         +-> Service Bus (async work, dead-letter queue) -> Functions worker
  observability: Application Insights + Log Analytics, alerts on errors/latency
  delivery:      Bicep + GitHub Actions (OIDC, what-if, approvals)
  guardrails:    Azure Policy at management group, Defender for Cloud, budgets

Write down the trade-off

In interviews and design reviews, saying why you rejected the more reliable or cheaper option matters as much as the final diagram. Name the requirement that drove the decision.

Quick check: A request flows through two services in series with SLAs of 99.95% and 99.99%. What is the approximate composite availability?

  • About 99.94%
  • 99.99%
  • 99.95%
  • 100%
Answer

About 99.94% — For dependencies in series, multiply the availabilities: 0.9995 × 0.9999 ≈ 0.9994.