Every resource the Azure template creates, and what each one is for.
This is the actual shape of the Azure Resource Manager template — one App Service running everything, a PostgreSQL Flexible Server and a Redis Enterprise cache reached privately, and a Key Vault for the credentials it starts with.
It's a leaner shape than the AWS template, and deliberately not padded out to look symmetric: one App Service plays the role AWS splits across three ECS services, and there's no CDN layer or template-hosting bucket in front of it. Both differences are called out below rather than glossed over.
This is the hub's own account. Adding another Azure subscription, or AWS or Google Cloud, deploys a much smaller collector into it instead — covered by the permission model and the scan cycle pages.
Need this against your own security review checklist? Email support@cloud-vex.com.
Join the waitlist