Azure
Azure Mental Model
Practice transferring the AWS job-based cloud map into Azure resources, scopes, callers, and first service choices.
Tenants, Subscriptions, and Regions
Practice choosing Azure tenant, subscription, resource group, region, and availability-zone placement before resources drift.
Resources, IDs, and Tags
Practice using Azure names, resource IDs, resource types, tags, locks, and evidence before changing resources.
Azure Core Services Map
Practice mapping Azure service choices to traffic, compute, state, access, signals, operations, cost, and recovery jobs.
What Is Azure RBAC
Practice reading Azure RBAC through caller identity, object IDs, scope, role assignments, least privilege, and one focused evidence check.
Managed Identities
Practice using managed identities for workload access, inspecting runtime identity evidence, and separating identity from permission.
Key Vault
Practice deciding what belongs in Key Vault, inspecting secret metadata and access, and reasoning about rotation, deletion protection, and evidence.
What Is a VNet
Practice placing an Azure workload in a VNet, reading subnet and route evidence, and choosing safe route fixes.
Network Security Groups
Practice reading Azure packet rules, priority order, default rules, ASG targets, and effective rule evidence before changing access.
Public Entry Points
Practice choosing Azure public entry services, reading DNS and TLS evidence, and checking backend health before blaming the app.
Private Connectivity
Practice reading private endpoint, private DNS, service endpoint, resource firewall, and authorization evidence separately.
What Is Compute
Practice matching Azure compute choices to workload shape, then inspect runtime evidence before changing production.
App Service
Practice reading the App Service plan, web app settings, identity, slots, health, and runtime evidence before changing a backend.
Container Apps
Practice reading Container Apps environments, images, revisions, ingress, scale rules, secrets, identity, and runtime failure evidence.
Virtual Machines
Practice deciding when VM control is honest, then inspecting image, size, disk, network, startup, patching, and runtime evidence.
Functions
Practice recognizing event-shaped jobs, triggers, function app evidence, retries, and failure modes in Azure Functions.
AKS
Practice deciding when Kubernetes is the right Azure operating model, then place node pools, pods, services, ingress, and identity in the cluster story.
What Is Data Storage
Practice choosing Azure data services by data shape, access pattern, operating evidence, and recovery promise.
Blob Storage
Practice Blob Storage choices for durable generated files, private access, blob names, tiers, and lifecycle rules.
Azure SQL Database
Practice SQL database evidence for order records, private access, retention, and schema-sensitive releases.
Cosmos DB
Practice Cosmos DB decisions around item shape, access patterns, partition keys, request units, TTL, and NoSQL fit.
Disks and File Shares
Practice attached disk and shared file path decisions for VM-shaped workloads and legacy migration paths.
Backups and Retention
Practice separating backup from restore, choosing retention windows, protecting blobs from deletion or overwrite, and reviewing safe deletion.
What Is Observability
Practice matching Azure logs, metrics, traces, and alerts to real checkout questions.
Logs and Workspaces
Practice diagnostic settings, workspaces, tables, KQL, retention, and access choices for Azure logs.
Application Insights
Practice following requests, dependencies, exceptions, traces, and correlation through one backend failure.
Metrics and Alerts
Practice metric selection, dashboard judgment, alert rules, action groups, and alert noise control.
What Is a Release
Practice separating artifact, runtime, configuration, traffic, health, and rollback evidence during an Azure release.
Safe Rollouts
Practice using slots, revisions, traffic splitting, direct testing, and rollback targets during Azure releases.
Configuration and Secrets
Practice runtime configuration, app settings, secrets, Key Vault references, managed identity, and config rollback decisions.
Release Verification and Rollback Decisions
Practice post-release verification and rollback judgment for Azure by reading production evidence, choosing safe first checks, and avoiding broad changes.
Verification and Rollback
Practice watch windows, health checks, real-traffic evidence, rollback, fix-forward choices, and release records.
What Is Cost and Resilience
Practice pairing Azure cost shapes with failure promises before changing resources.
Cost Visibility
Practice using Azure Cost Management, Cost Analysis, tags, budgets, Advisor, and workload context before tuning spend.
Recovery Planning
Practice RTO, RPO, backup versus recovery, data protection, redundancy, recovery strategy, and restore drill judgment.