Real-Time Analytics Platform  ·  View 16 of 21  ·  Operations

Deployment and Infrastructure

What runs where, which failure domains it spans, and what is actually standing by in the secondary region.

Editable source SVG draw.io All views
Azure · Sweden Central (primary)
Azure · Sweden Central (primary)
Hub VNet · shared services
Hub VNet · shared services
Azure Firewall
egress control
Azure Firewall...
Private DNS Zones
privatelink.*
Private DNS Zones...
Azure Bastion
no public RDP/SSH
Azure Bastion...
ExpressRoute Gateway
on-premises CDC
ExpressRoute Gateway...
Zone-redundant compute and messaging
Zone-redundant compute and messaging
Availability Zone 1
Availability Zone 1
Event Hubs CU
Event Hubs CU
Databricks Workers
Databricks Workers
ADX Nodes x4
ADX Nodes x4
Availability Zone 2
Availability Zone 2
Event Hubs CU
Event Hubs CU
Databricks Workers
Databricks Workers
ADX Nodes x4
ADX Nodes x4
Availability Zone 3
Availability Zone 3
Event Hubs CU
Event Hubs CU
Databricks Workers
Databricks Workers
ADX Nodes x4
ADX Nodes x4
Zone-redundant state
Zone-redundant state
ADLS Gen2
ZRS · hierarchical
ADLS Gen2...
Checkpoint Container
per streaming job
Checkpoint Container...
Azure Key Vault
HSM · CMK
Azure Key Vault...
Azure Cache for Redis
zone-redundant premium
Azure Cache for Redis...
Azure · Germany West Central (DR)
Azure · Germany West Central (DR)
Warm standby
Warm standby
Event Hubs Geo-DR Alias
metadata replication
Event Hubs Geo-DR Alias...
ADX Follower Cluster
read-only standby
ADX Follower Cluster...
ADLS GRS Replica
bronze archive
ADLS GRS Replica...
Terraform Standby Stack
apply on declare
Terraform Standby Stack...
Azure Monitor
cross-region workspace
Azure Monitor...
Microsoft Entra ID
global
Microsoft Entra ID...
Azure DevOps
self-hosted agents
Azure DevOps...
geo-DR pair
geo-DR pair
GRS replication
GRS replication
attach
attach
Deployment and Infrastructure
Deployment and Infrastructure
Security / platform
Security / platform
Interface / broker
Interface / broker
Queue / topic
Queue / topic
Application we own
Application we own
Data store
Data store
event / async
event / async
batch
batch
RTO 60 min, RPO 5 min. DR is warm: capacity is provisioned on declare, not held idle.
RTO 60 min, RPO 5 min. DR is warm: capacity is provisioned on declare, not held idle.
v 1.0 · owner Cloud Platform · date 2026-08
v 1.0 · owner Cloud Platform · date 2026-08
Text is not SVG - cannot display

Availability target

  • 99.9% monthly, allowing roughly 43 minutes of downtime — met by zone redundancy, not by DR
  • Event Hubs, ADX, ADLS and Redis are all zone-redundant within the primary region
  • A single zone loss is a capacity event, not an outage; the pipeline continues degraded

Disaster recovery

  • RTO 60 minutes, RPO 5 minutes — warm standby, capacity provisioned on declare
  • Event Hubs geo-DR replicates metadata only; in-flight events within RPO can be lost
  • Bronze is geo-replicated, so a regional failure costs a replay window and not the data

Honest gap

  • A regional failover has not been rehearsed end to end; the RTO figure is a design estimate
  • Quarterly game-day exercise is a prerequisite for production sign-off
  • Cross-region egress cost during failover is not yet modelled