Design proposal
The environment design and application architecture for moving AuraShop to Microsoft Azure New Zealand North.
1.Summary
One Microsoft Entra tenant, one management group and two subscriptions, production and non-production, in Azure New Zealand North. Production and non-production share the same shape, so the same Bicep templates deploy both, and only production changes need the owner’s approval.
2.Environment layout

3.Application architecture

4.Resource groups
| Resource group | Holds |
|---|---|
| Platform | Log Analytics, Application Insights, budget and alerts |
| App | Container Apps environment and AuraShop, managed identity, Key Vault, Container Registry, and Azure OpenAI for AI product search (if confirmed in Stage 0) |
| Data | PostgreSQL Flexible Server, kept separate so it can carry a delete lock |
5.Naming and tagging
Names follow type-workload-environment-region, such as ca-aurashop-prod-nzn. Every resource is tagged with project, environment, owner, cost centre and “managed by Bicep”.
6.Guardrails
Azure Policy limits resources to New Zealand North (with Australia East only for recorded exceptions), requires tags, and blocks public access to storage and databases.
7.Access and security
Only the owner holds standing admin rights, with multi-factor authentication. Deployments run through GitHub Actions using federated sign-in, so no passwords or keys are stored. The app uses a managed identity, and secrets live only in Key Vault. Shoppers keep signing in as they do today (email and password, Google or Apple).
8.Cost
We’ll publish the Azure Pricing Calculator estimate in Stage 0, with the monthly budget and alerts already in place.
9.Kept outside Azure for now
Stripe payments, the WedgewoodAI account sync, email, Google and Apple sign-in, and advertising stay as external services for this migration, each recorded in the decision log.
