Skip to content

Architecture and deployment model

The platform combines Elastic Stack services with Azure infrastructure managed through an Azure Managed Application.

Architecture overview

{
  "$schema": "https://vega.github.io/schema/vega/v6.json",
  "description": "High-level Azure resource-boundary architecture for the iVedha Managed Elasticsearch Platform. The managed platform runs in the customer's Azure subscription. Customer users and data sources connect through customer network and DNS to the platform endpoint and AKS-hosted Elasticsearch and Kibana. A monitoring agent forwards platform telemetry to the iVedha monitoring cluster, while lifecycle automation coordinates the Azure Marketplace managed application.",
  "width": 1600,
  "height": 850,
  "padding": 0,
  "autosize": {
    "type": "none",
    "contains": "padding"
  },
  "background": "#ffffff",
  "data": [
    {
      "name": "boundaries",
      "values": [
        {
          "x": 20,
          "y": 75,
          "w": 430,
          "h": 260,
          "label": "Customer environment",
          "fill": "#f7f4fb",
          "stroke": "#8b75a3",
          "labelColor": "#5d3f76",
          "dash": [
            1,
            0
          ]
        },
        {
          "x": 20,
          "y": 360,
          "w": 430,
          "h": 445,
          "label": "iVedha / Opsflw operations",
          "fill": "#f1f8f2",
          "stroke": "#76a67e",
          "labelColor": "#276738",
          "dash": [
            1,
            0
          ]
        },
        {
          "x": 480,
          "y": 75,
          "w": 1100,
          "h": 730,
          "label": "Customer Azure subscription",
          "fill": "#f2f7fc",
          "stroke": "#377fb4",
          "labelColor": "#0067a3",
          "dash": [
            1,
            0
          ]
        },
        {
          "x": 505,
          "y": 110,
          "w": 1050,
          "h": 510,
          "label": "Managed resource group",
          "fill": "#eaf4fc",
          "stroke": "#77a8c9",
          "labelColor": "#075f91",
          "dash": [
            7,
            6
          ]
        }
      ]
    },
    {
      "name": "nodes",
      "values": [
        {
          "x": 62,
          "y": 150,
          "w": 140,
          "h": 112,
          "label": "Users and\ndata sources",
          "icon": "asset:azure/vega-icons/users.png",
          "kind": "customer"
        },
        {
          "x": 265,
          "y": 150,
          "w": 140,
          "h": 112,
          "label": "Customer network\nand DNS",
          "icon": "asset:azure/vega-icons/network.png",
          "kind": "customer"
        },
        {
          "x": 62,
          "y": 420,
          "w": 140,
          "h": 118,
          "label": "Managed-resource\ntelemetry\nmonitoring cluster",
          "icon": "asset:azure/vega-icons/monitoring-cluster.png",
          "kind": "ops"
        },
        {
          "x": 62,
          "y": 640,
          "w": 140,
          "h": 112,
          "label": "Lifecycle\nautomation",
          "icon": "asset:azure/vega-icons/marketplace.png",
          "kind": "ops"
        },
        {
          "x": 535,
          "y": 175,
          "w": 122,
          "h": 112,
          "label": "Platform endpoint\npublic or private",
          "icon": "asset:azure/vega-icons/endpoint.png",
          "kind": "azure"
        },
        {
          "x": 700,
          "y": 175,
          "w": 122,
          "h": 112,
          "label": "AKS platform\nruntime",
          "icon": "asset:azure/vega-icons/aks.png",
          "kind": "azure"
        },
        {
          "x": 870,
          "y": 145,
          "w": 122,
          "h": 112,
          "label": "Key Vault",
          "icon": "asset:azure/vega-icons/key-vault.png",
          "kind": "azure"
        },
        {
          "x": 870,
          "y": 315,
          "w": 122,
          "h": 112,
          "label": "Kibana",
          "icon": "asset:azure/vega-icons/kibana.png",
          "kind": "elastic"
        },
        {
          "x": 1040,
          "y": 315,
          "w": 122,
          "h": 112,
          "label": "Elasticsearch",
          "icon": "asset:azure/vega-icons/elasticsearch.png",
          "kind": "elastic"
        },
        {
          "x": 1210,
          "y": 315,
          "w": 122,
          "h": 112,
          "label": "Storage",
          "icon": "asset:azure/vega-icons/storage.png",
          "kind": "azure"
        },
        {
          "x": 1040,
          "y": 480,
          "w": 122,
          "h": 112,
          "label": "Monitoring\nagent",
          "icon": "asset:azure/vega-icons/monitoring-agent.png",
          "kind": "azure"
        },
        {
          "x": 1210,
          "y": 650,
          "w": 122,
          "h": 112,
          "label": "Application\nresource group",
          "icon": "asset:azure/vega-icons/resource-group.png",
          "kind": "azure"
        },
        {
          "x": 1380,
          "y": 650,
          "w": 150,
          "h": 112,
          "label": "Azure Marketplace\nmanaged\napplication",
          "icon": "asset:azure/vega-icons/marketplace.png",
          "kind": "azure"
        }
      ]
    },
    {
      "name": "connections",
      "values": [
        {
          "path": "M 202 206 L 265 206",
          "endX": 265,
          "endY": 206,
          "angle": 90,
          "label": "HTTPS and data",
          "labelX": 233,
          "labelY": 187,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 405 206 L 535 206",
          "endX": 535,
          "endY": 206,
          "angle": 90,
          "label": "approved access",
          "labelX": 470,
          "labelY": 187,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 657 231 L 700 231",
          "endX": 700,
          "endY": 231,
          "angle": 90,
          "label": "HTTPS 443",
          "labelX": 678,
          "labelY": 212,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 822 204 L 870 201",
          "endX": 870,
          "endY": 201,
          "angle": 90,
          "label": "secrets",
          "labelX": 846,
          "labelY": 184,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 822 250 L 850 250 L 850 371 L 870 371",
          "endX": 870,
          "endY": 371,
          "angle": 90,
          "label": "hosts",
          "labelX": 852,
          "labelY": 298,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 992 371 L 1040 371",
          "endX": 1040,
          "endY": 371,
          "angle": 90,
          "label": "queries",
          "labelX": 1016,
          "labelY": 352,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 761 287 L 761 455 L 1020 455 L 1040 414",
          "endX": 1040,
          "endY": 414,
          "angle": 27,
          "label": "hosts",
          "labelX": 890,
          "labelY": 438,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 1162 371 L 1210 371",
          "endX": 1210,
          "endY": 371,
          "angle": 90,
          "label": "snapshots",
          "labelX": 1186,
          "labelY": 352,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 822 270 L 840 270 L 840 536 L 1040 536",
          "endX": 1040,
          "endY": 536,
          "angle": 90,
          "label": "runs",
          "labelX": 936,
          "labelY": 518,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 1040 560 L 470 560 L 470 479 L 202 479",
          "endX": 202,
          "endY": 479,
          "angle": -90,
          "label": "forwards platform telemetry",
          "labelX": 605,
          "labelY": 542,
          "dash": [
            8,
            6
          ]
        },
        {
          "path": "M 1380 706 L 1332 706",
          "endX": 1332,
          "endY": 706,
          "angle": -90,
          "label": "creates",
          "labelX": 1356,
          "labelY": 687,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 1210 706 L 1170 706 L 1170 635 L 760 635 L 760 287",
          "endX": 760,
          "endY": 287,
          "angle": 0,
          "label": "deploys managed platform",
          "labelX": 965,
          "labelY": 617,
          "dash": [
            1,
            0
          ]
        },
        {
          "path": "M 202 696 L 460 696 L 460 780 L 1455 780 L 1455 762",
          "endX": 1455,
          "endY": 762,
          "angle": 0,
          "label": "lifecycle coordination",
          "labelX": 970,
          "labelY": 762,
          "dash": [
            8,
            6
          ]
        }
      ]
    }
  ],
  "scales": [
    {
      "name": "nodeFill",
      "type": "ordinal",
      "domain": [
        "ops",
        "customer",
        "azure",
        "elastic"
      ],
      "range": [
        "#f7fbf7",
        "#fbf9fd",
        "#ffffff",
        "#ffffff"
      ]
    },
    {
      "name": "nodeStroke",
      "type": "ordinal",
      "domain": [
        "ops",
        "customer",
        "azure",
        "elastic"
      ],
      "range": [
        "#76a67e",
        "#8b75a3",
        "#5b9bc7",
        "#6b7280"
      ]
    }
  ],
  "marks": [
    {
      "type": "text",
      "encode": {
        "enter": {
          "x": {
            "value": 800
          },
          "y": {
            "value": 32
          },
          "text": {
            "value": "iVedha Managed Elasticsearch Platform \u2014 Azure resource boundaries"
          },
          "align": {
            "value": "center"
          },
          "baseline": {
            "value": "middle"
          },
          "font": {
            "value": "Arial, sans-serif"
          },
          "fontSize": {
            "value": 23
          },
          "fontWeight": {
            "value": 600
          },
          "fill": {
            "value": "#19324d"
          }
        }
      }
    },
    {
      "type": "rect",
      "from": {
        "data": "boundaries"
      },
      "encode": {
        "enter": {
          "x": {
            "field": "x"
          },
          "y": {
            "field": "y"
          },
          "width": {
            "field": "w"
          },
          "height": {
            "field": "h"
          },
          "fill": {
            "field": "fill"
          },
          "fillOpacity": {
            "value": 0.8
          },
          "stroke": {
            "field": "stroke"
          },
          "strokeWidth": {
            "value": 1.5
          },
          "strokeDash": {
            "field": "dash"
          },
          "cornerRadius": {
            "value": 10
          }
        }
      }
    },
    {
      "type": "text",
      "from": {
        "data": "boundaries"
      },
      "encode": {
        "enter": {
          "x": {
            "signal": "datum.x + 10"
          },
          "y": {
            "signal": "datum.y + 18"
          },
          "text": {
            "field": "label"
          },
          "font": {
            "value": "Arial, sans-serif"
          },
          "fontSize": {
            "value": 14
          },
          "fontWeight": {
            "value": 700
          },
          "fill": {
            "field": "labelColor"
          },
          "baseline": {
            "value": "middle"
          }
        }
      }
    },
    {
      "type": "path",
      "from": {
        "data": "connections"
      },
      "encode": {
        "enter": {
          "path": {
            "field": "path"
          },
          "fillOpacity": {
            "value": 0
          },
          "stroke": {
            "value": "#425d78"
          },
          "strokeWidth": {
            "value": 1.7
          },
          "strokeDash": {
            "field": "dash"
          }
        }
      }
    },
    {
      "type": "symbol",
      "from": {
        "data": "connections"
      },
      "encode": {
        "enter": {
          "x": {
            "field": "endX"
          },
          "y": {
            "field": "endY"
          },
          "shape": {
            "value": "triangle"
          },
          "size": {
            "value": 85
          },
          "angle": {
            "field": "angle"
          },
          "fill": {
            "value": "#425d78"
          }
        }
      }
    },
    {
      "type": "rect",
      "from": {
        "data": "nodes"
      },
      "encode": {
        "enter": {
          "x": {
            "field": "x"
          },
          "y": {
            "field": "y"
          },
          "width": {
            "field": "w"
          },
          "height": {
            "field": "h"
          },
          "fill": {
            "scale": "nodeFill",
            "field": "kind"
          },
          "stroke": {
            "scale": "nodeStroke",
            "field": "kind"
          },
          "strokeWidth": {
            "value": 1.25
          },
          "cornerRadius": {
            "value": 8
          },
          "shadowColor": {
            "value": "#0f2740"
          },
          "shadowBlur": {
            "value": 3
          },
          "shadowOpacity": {
            "value": 0.12
          },
          "shadowOffsetY": {
            "value": 1
          }
        }
      }
    },
    {
      "type": "image",
      "from": {
        "data": "nodes"
      },
      "encode": {
        "enter": {
          "url": {
            "field": "icon"
          },
          "x": {
            "signal": "datum.x + datum.w / 2 - 22"
          },
          "y": {
            "signal": "datum.y + 9"
          },
          "width": {
            "value": 44
          },
          "height": {
            "value": 44
          },
          "aspect": {
            "value": true
          }
        }
      }
    },
    {
      "type": "text",
      "from": {
        "data": "nodes"
      },
      "encode": {
        "enter": {
          "x": {
            "signal": "datum.x + datum.w / 2"
          },
          "y": {
            "signal": "datum.y + 64"
          },
          "text": {
            "field": "label"
          },
          "lineBreak": {
            "value": "\n"
          },
          "lineHeight": {
            "value": 14
          },
          "align": {
            "value": "center"
          },
          "baseline": {
            "value": "top"
          },
          "limit": {
            "signal": "datum.w - 10"
          },
          "font": {
            "value": "Arial, sans-serif"
          },
          "fontSize": {
            "value": 11.5
          },
          "fontWeight": {
            "value": 600
          },
          "fill": {
            "value": "#20364d"
          }
        }
      }
    },
    {
      "type": "text",
      "from": {
        "data": "connections"
      },
      "encode": {
        "enter": {
          "x": {
            "field": "labelX"
          },
          "y": {
            "field": "labelY"
          },
          "text": {
            "field": "label"
          },
          "align": {
            "value": "center"
          },
          "baseline": {
            "value": "middle"
          },
          "font": {
            "value": "Arial, sans-serif"
          },
          "fontSize": {
            "value": 12
          },
          "fontWeight": {
            "value": 500
          },
          "fill": {
            "value": "#34495e"
          },
          "stroke": {
            "value": "#ffffff"
          },
          "strokeWidth": {
            "value": 4
          },
          "strokeJoin": {
            "value": "round"
          }
        }
      }
    },
    {
      "type": "text",
      "from": {
        "data": "connections"
      },
      "encode": {
        "enter": {
          "x": {
            "field": "labelX"
          },
          "y": {
            "field": "labelY"
          },
          "text": {
            "field": "label"
          },
          "align": {
            "value": "center"
          },
          "baseline": {
            "value": "middle"
          },
          "font": {
            "value": "Arial, sans-serif"
          },
          "fontSize": {
            "value": 12
          },
          "fontWeight": {
            "value": 500
          },
          "fill": {
            "value": "#34495e"
          }
        }
      }
    },
    {
      "type": "text",
      "encode": {
        "enter": {
          "x": {
            "value": 800
          },
          "y": {
            "value": 828
          },
          "text": {
            "value": "The platform runs in the customer's Azure subscription. iVedha/Opsflw manages deployment and operations; the customer retains ownership of its Azure subscription, connectivity, identity, and data."
          },
          "align": {
            "value": "center"
          },
          "baseline": {
            "value": "middle"
          },
          "font": {
            "value": "Arial, sans-serif"
          },
          "fontSize": {
            "value": 12.5
          },
          "fontWeight": {
            "value": 600
          },
          "fill": {
            "value": "#29445d"
          }
        }
      }
    }
  ]
}

The managed platform runs in the customer's Azure subscription. Customers own the subscription, connectivity, identity, and data. A monitoring agent in the managed resource group forwards platform telemetry to the iVedha monitoring cluster so managed operations can observe platform health and respond to supported incidents.

The diagram is conceptual. The exact Azure resources depend on the approved offer, plan, region, and version. It intentionally omits subnets, node pools, node roles, and internal automation.

Service components

  • Elasticsearch stores, indexes, and searches data.
  • Kibana provides the browser interface for search, visualizations, dashboards, and supported administration.
  • Azure Kubernetes Service hosts the managed application workloads.
  • Azure Key Vault holds deployment secrets and certificate material.
  • Azure Storage supports deployment data, diagnostics, and snapshot access where configured.
  • Monitoring agent collects managed-resource platform telemetry and forwards it to the iVedha monitoring cluster.
  • Azure networking supplies virtual networks, private connectivity, DNS, and optional public access.
  • Managed identities and Azure RBAC authorize supported communication without embedding Azure credentials in documentation.

Not every underlying resource is intended for direct customer administration. Use the managed application view and documented Elasticsearch or Kibana interfaces for supported changes.

Managed monitoring flow

The monitoring agent runs in the managed resource group and forwards operational platform telemetry to the iVedha monitoring cluster outside the customer subscription. iVedha managed operations use the resulting health signals and alerts to investigate the supported platform.

This path represents platform monitoring. It does not mean that the customer's Elasticsearch indices or application data are hosted in the iVedha operations environment. Customers remain responsible for monitoring workload outcomes, data quality, ingestion behavior, and application-level service objectives.

Azure resource boundaries

Boundary Primary purpose Customer action
Application resource group Contains the managed application instance View status and perform supported lifecycle actions
Managed resource group Contains supporting infrastructure Inspect only as permitted; do not modify directly
Customer network and DNS Connects users and data sources Configure approved routing, DNS, and Private Endpoints
Elasticsearch data plane Holds customer indices and configuration Manage data, users, roles, and application-level settings

Access models

Private access keeps service endpoints on approved private network paths. Users need a Private Endpoint, working DNS, a trusted TLS certificate, and a route from their client network.

Public access uses internet-reachable endpoints. It still requires TLS, authentication, and any organization-approved network restrictions.

Choose the access model during planning. Changing it later may require DNS, certificate, firewall, and client reconfiguration.

For a focused comparison, see public and private connectivity.