What is subscription vending?
A process that helps organizations achieve subscription democratization design principles critical for scaling, security, and governance of Azure environments.
What do subscription vending product lines cater to?
The diverse needs of various application teams.
Why is a standardized approach to subscription vending important?
It prevents confusion, delay, and inefficiency.
What are the benefits of offering various product lines in subscription vending?
They provide flexibility, align with platform engineering principles, and cater to different application team requirements.
What is meant by ‘one size fits all’ in subscription vending?
An approach that limits internal customers’ flexibility and can compromise application teams’ architecture design choices.
What are management groups in Azure environments?
Organizational units that help manage subscriptions and resources effectively.
What should platform teams consider when designing subscription vending?
Questions about resources, subscription deployment, network connectivity, RBAC, and governance.
What is the purpose of having multiple types and styles of subscriptions?
To provide application teams with flexibility and meet their unique requirements.
What is a common product line for subscription vending?
Corp connected, Online, Tech platform, Shared application portfolio, Sandbox.
What does the corp connected product line provide?
Connectivity via traditional Layer-3 IP methods between resources.
When should you use the corp connected product line?
For Rehost and Refactor migrations, familiar on-premises architecture, ‘lift and shift’ applications, and enhancing security.
What is the online product line used for?
It doesn’t use traditional Layer-3 IP methods and provides connectivity via public interfaces.
When should the online product line be utilized?
For refactoring, rebuilding applications, enhancing zero-trust alignment, and when private IP address space is limited.
What is the tech platform product line designed for?
Hosting and managing large, complex workloads for multiple application teams.
What types of products might be included in a tech platform product line?
What is the shared application portfolio product line?
For workloads that don’t require multiple separate application landing zone subscriptions.
What considerations should be made for resource group delegation in a single subscription?
True or False: Subscription vending can follow a ‘one size fits all’ design.
False
Fill in the blank: The _______ product line is for workloads requiring traditional Layer-3 IP routing connectivity.
corp connected
What is the purpose of the Sandbox product line?
To allow application teams to build a proof of concept (PoC) or minimum viable product (MVP) with fewer controls.
What is Azure Private Link used for?
To enable private connectivity between applications and expose services securely.
What is the goal of subscription democratization?
To provide flexibility and control to internal customers in Azure environments.
What management overhead increases when adding new resource groups to subscriptions?
Increases management overhead to create Azure Policy assignments
When new resource groups are added, it complicates the management of policy assignments.
What happens to security and governance gaps when policies are not immediately assigned to resource groups?
Increases security and governance gaps
Immediate assignment of policies is crucial for maintaining security and governance.