About This Architecture
Ani Platform demonstrates a production-grade Azure landing zone architecture spanning identity, platform, hub networking, and workload subscriptions with strict network segmentation. External traffic flows through Azure Front Door and WAF into an Application Gateway, routing requests to Next.js and FastAPI services running on Container Apps across isolated spoke virtual networks. The design enforces least-privilege access via Microsoft Entra ID, Managed Identities, and RBAC, while segregating data tier resources—PostgreSQL, Redis, Neo4j, and Blob Storage—into a dedicated data network spoke with private endpoints and key vault integration. Fork this diagram on Diagrams.so to customize subnets, add additional workload spokes, or integrate your own CI/CD and monitoring tooling.