Phase 1: Prerequisites for Azure — Unique AI Documentation

Phase 1: Prerequisites for Azure

7 min read

Overview

This guide covers the Azure prerequisites that customer IT teams must complete before Unique begins deploying the application into a Customer Managed Tenant. It spans identity and access management, networking, compute, and monitoring — with the goal of ensuring a secure, compliant, and reproducible environment from day one.

Audience: IT administrators and cloud architects responsible for the customer's Azure Landing Zone.

Support Limitation — ClickOps Configurations
Unique's deployment support assumes Infrastructure as Code (IaC) or automated configurations. If ClickOps is used instead, Unique's ability to provide effective support or troubleshoot issues will be significantly limited. Customers are strongly encouraged to adopt IaC (e.g., Terraform) to fully leverage Unique's support capabilities.


General Understanding and Preparation

This section covers the foundational knowledge the customer team needs before starting environment setup.

1. Azure Resource Management

2. Networking Proficiency

3. Security and Compliance

4. Kubernetes and Container Management

5. Pre-Deployment Checks

6. Training and Documentation


Identity and Access Management

This section covers the IAM prerequisites that the customer must have in place within their Azure environment.

TODO — Diagram needed: Entity-relationship diagram showing the relationships between RBAC assignments, Certificate Management, Managed Identities, Workload Identities, and Entra ID components (App Registrations, Enterprise Applications, Conditional Access Policies). Should illustrate which identity types access which Azure resources (KeyVault, AKS, LLM endpoints).

1. RBAC Adoption

2. Certificate Management

3. Microsoft Intune and Azure Entra Integration

4. Managed and Workload Identities

5. API Access Management

6. Management Group and Subscription Rights

7. Single Sign-On (SSO)

8. Support and Debugging Access

9. Intune Licensing


Network

This section covers the network prerequisites and configuration decisions the customer must address.

TODO — Diagram needed: Network topology diagram showing the traffic flow between: internet → Application Gateway (or custom upstream gateway) → AKS ingress → pods, with NSG boundaries, DNS zone delegation, and the external Power Automate / SharePoint integration path. Should distinguish public vs. private cluster variants and show where certificates are terminated.

1. Egress Traffic — Development Phase

2. Network Security Groups (NSGs)

3. Custom Gateway Integration

4. Certificate Management for Ingress

5. Mobile App Certificate Requirements

6. DNS and Zone Configuration

7. Application Gateway URL

8. Subdomain Structure

9. Internal Network Accessibility

10. SharePoint Integration via Power Automate

11. API Gateway for Power Automate

12. Private Cluster Limitations

13. Public IP Management

14. Container Image Access

15. Certificate Management without Cert-Manager

16. Cert-Manager in Isolated Networks

17. IP Address Allocation in AKS


Compute

This section covers compute resource prerequisites for the Unique deployment.

The Kubernetes cluster must support running operators and Custom Resource Definitions (CRDs). Components such as Kong rely on CRDs — CRD installation and management is a fundamental requirement.

1. Azure VM Configuration

2. VM Tooling Requirements

3. Helm Chart Access

4. Encrypted Disk Customization

5. Shared Cluster Considerations

6. Subnet Sizing


Monitoring and Analytics

This section covers the monitoring infrastructure prerequisites.

TODO — Diagram needed: Integration diagram showing the data flow from AKS pods → Log Analytics Workspace and AKS metrics → Managed Prometheus → Managed Grafana. Should show the workspace configuration and data source connections.

1. Log Analytics Workspace

2. Grafana Integration