Skip to content

Shared responsibility

The managed platform reduces the infrastructure and operational work required to run Elasticsearch, but the customer retains ownership of the Azure subscription, customer connectivity, identities, and data.

iVedha manages the supported platform infrastructure and lifecycle.

Responsibility swimlane showing customer ownership of subscription, network and DNS, identity, and data governance, alongside iVedha Opsflw ownership of provisioning, supported configuration, health monitoring, upgrades, and operations.

Responsibility overview

Area Customer iVedha
Azure subscription, billing, policy, and quota Own and approve Identify platform requirements and assist with deployment issues
Marketplace deployment Select, deploy, and delete the Managed Application Publish, onboard, and support the application
Managed infrastructure Do not make unsupported changes Provision, monitor, maintain, and operate supported components
Customer network and routing Configure customer-side connectivity Provide supported public and private connectivity model
Private Endpoint Create in the customer network Provide the Private Link Service information required for connection
DNS Configure company-owned or private DNS where required Provide authoritative service hostnames
TLS certificates Obtain certificate authority approval and sign the CSR Generate the private key and CSR, apply and manage the certificate
Elasticsearch data Classify, ingest, retain, and delete data Operate the Elasticsearch platform
Users and roles Define and assign application access Provide supported identity and platform configuration workflows
SSO Manage Microsoft Entra application and groups Apply supported platform OIDC configuration
Elastic Agent and Fleet Manage agent policies, integrations, and source onboarding Operate Fleet services and assist with platform-related issues
OpenTelemetry Instrument applications and validate workload telemetry Provide supported OTel ingestion architecture and platform integration
Workload monitoring Verify ingestion, search, dashboards, and application outcomes Monitor managed-platform health
Capacity Define workload growth and requirements Monitor platform capacity and perform supported capacity changes
Backups and recovery Define business RPO/RTO and validate recovered workloads Operate supported snapshot and recovery processes
Maintenance Prepare applications and users for planned changes Perform supported platform maintenance
Upgrades Validate application, client, Agent, and integration compatibility Plan and execute managed platform upgrades
Elastic licensing Define required features and commercial requirements Apply supported licenses and assist with license procurement and renewal
Support Provide business impact and safe diagnostic evidence Troubleshoot, investigate, and operate the managed platform

Azure and Marketplace

The customer owns the Azure subscription and remains responsible for:

  • subscription governance;
  • billing;
  • Azure Policy;
  • quota;
  • Marketplace purchase permissions.

Microsoft operates Azure and the Azure Marketplace platform.

iVedha provides and operates the managed application running within the customer's Azure environment.

Managed infrastructure

iVedha manages the infrastructure required to operate the platform.

This can include:

  • Azure Kubernetes Service;
  • Elasticsearch and Kibana runtime components;
  • Fleet and supporting services;
  • managed storage;
  • secrets and certificates;
  • managed identities;
  • platform monitoring components.

Customers should not modify Kubernetes resources, secrets, managed node infrastructure, or other platform resources directly unless the documentation explicitly identifies the action as customer-managed.

Networking and DNS

The customer manages connectivity from customer networks to the platform.

This includes:

  • routing;
  • peering where required;
  • firewall rules;
  • Private Endpoints;
  • corporate DNS;
  • company-owned DNS records.

iVedha provides the authoritative service information needed to establish the connection.

Do not construct endpoints or Private Link identifiers from internal Azure naming conventions.

TLS certificates

For customer-provided certificates:

iVedha:

  • generates the private key;
  • generates the CSR;
  • includes the required SANs for Kibana, Elasticsearch, Fleet, and Logstash;
  • applies the signed certificate.

Customer:

  • submits the CSR to the approved certificate authority;
  • obtains the signed certificate chain;
  • verifies that clients trust the issuing CA.

The private key remains inside the managed platform.

Observability

The platform uses an OpenTelemetry-first observability model.

The customer is responsible for:

  • application instrumentation;
  • selecting telemetry sources;
  • Fleet agent policies and integrations;
  • validating logs, metrics, and traces;
  • verifying business and application-level observability coverage.

iVedha is responsible for:

  • operating Fleet and managed observability platform components;
  • platform-level health monitoring;
  • supporting the Elastic Agent and OpenTelemetry ingestion architecture;
  • investigating managed-platform conditions.

A healthy platform does not guarantee that every customer telemetry source is producing the expected data.

Platform operations

Supported platform-level actions are performed through:

  • AI chat: https://copilot.opsflw.io
  • Support portal: https://support.ivedha.com/

Examples include:

  • administrator password reset;
  • SSO changes;
  • maintenance-window changes;
  • certificate configuration;
  • license changes;
  • supported capacity changes;
  • recovery assistance.

Customer data

Customer Elasticsearch data remains in the managed Elasticsearch deployment inside the customer's Azure subscription.

iVedha operational monitoring does not transfer ownership of customer indices, documents, or application data.

Customers remain responsible for:

  • data classification;
  • retention requirements;
  • application access;
  • data correctness;
  • legal and regulatory requirements for their data.

Safety rules

Do not:

  • modify managed infrastructure directly;
  • reconstruct internal resource names;
  • disable TLS verification to bypass errors;
  • grant broad administrator permissions simply to troubleshoot;
  • send passwords, API keys, tokens, private keys, or other secrets through normal support channels.

Use the supported workflows and contact iVedha when a platform-level change is required.

Decommissioning

Deleting the Azure Managed Application removes the managed resource group.

Customer-owned resources such as Private Endpoints, DNS records, credentials, and external integrations might require separate cleanup.

Review Delete the application before decommissioning.