Zum Hauptinhalt springen

CCA-Hosting Infrastructure

🤖 Generated with Claude Code

Co-Authored-By: Claude (noreply@anthropic.com)

Azure Resources​

KomponenteResourceZweck
Application GatewayTIS-PROD-CCA_Weblight-AppGwWAF, HTTPS Termination
WebserverTIS-PROD-CCAWeblight-WE-VM-POCIIS (CCA-Online, OMDSmanager)
SQL Server 1CCA-Hosting-SQL01Cloud Edition Datenbanken
SQL Server 2CCA-Hosting-SQL02Host-It Datenbanken
VPN ServerTIS-PROD-CCAWebLight-WE-VM-AccessServerOpenVPN Access Server
Backup StorageStorage Accounts (Cold Tier)SQL Backups

Region: West Europe (alle Ressourcen)

Network Topology​

Network Topology

Subnets​

SubnetAdressbereichKomponenten
DMZ10.42.1.0/24Application Gateway
VPN10.42.0.0/24OpenVPN Access Server
APP10.42.2.0/24Webserver
DB10.42.3.0/24SQL01, SQL02

Public Endpoints​

EndpointIPZweck
Application Gateway40.114.151.227HTTPS Zugang (CCA-Online)
OpenVPN4.180.1.41VPN Zugang (CCA9)

Network Security​

  • NSGs pro Subnet konfiguriert
  • WAF v2 auf Application Gateway
  • SQL01 nicht via VPN erreichbar (bewusste Isolation)
  • SQL02 via VPN Port-Forwarding (MSSQL 1433)
DokumentInhalt
ARCHITECTURE.mdSystem Context, Applications, Integrationen
DECISIONS.mdArchitecture Decision Records
Betriebskonzept Kap. 1VM-Sizing, Disk-Konfiguration, Kosten
Betriebskonzept Kap. 3NSG-Regeln, Security Details