The challenge
- A secure, reliable channel was needed between the on-premises data centre, including ERP systems, and Azure: encrypted, without exposing internal services to the public internet.
- The existing system could not handle fluctuating workloads. During peak demand, performance degradation and latency affected users. A scalable microservices architecture was needed.
- Sensitive operational and transactional data required strict access controls, with databases and storage never exposed publicly while remaining reachable by application services.
- The platform had to integrate frontend applications, backend microservices, ERP systems and multiple data sources across environments.
Four secure communication patterns
Every flow in the platform follows one of four documented patterns, so there is no ambiguity about which paths exist and which are encrypted.
External
Public users reach the frontend only. Everything behind it is private.
VPN
Encrypted IPsec/IKEv2 tunnels carry all traffic between the on-premises ERP and Azure.
Logical
Microservices communicate with each other over private networking inside Azure Container Apps.
Database
Application services reach Cosmos DB, Blob Storage and Redis through Private Endpoints only.
What Cloudlit delivered
Secure hybrid network architecture
Azure Virtual Network with segmented gateway, application and data subnets. Site-to-site VPN between Azure VPN Gateway and the on-premises gateway, with all traffic inside encrypted IPsec tunnels.
Microservices-based application layer
Containerised applications on Azure Container Apps: a public-facing frontend and backend microservices handling order processing and integration logic over private networking.
Private data layer with zero public exposure
Azure Cosmos DB for transactional data, Blob Storage for unstructured data and Azure Cache for Redis, all behind Private Endpoints with traffic staying on the Azure backbone.
Identity and access management
Azure Active Directory for authentication, authorisation and RBAC. Managed Identities give services access to each other without credentials.
Optimised communication flows
Four secure patterns designed and documented: external, VPN, logical and database.
Security and compliance enhancements
Network isolation across tiers, encryption in transit and at rest, least-privilege NSG rules and Customer Managed Keys recommended for sensitive workloads.
Results
- All backend and data services fully private with no public internet exposure, significantly reducing the attack surface.
- Reliable encrypted connectivity between on-premises systems and Azure enables smooth data exchange with ERP systems.
- Microservices with caching significantly reduced latency and improved responsiveness during peak loads.
- Pay-as-you-go scaling of resources based on demand, reducing unnecessary infrastructure cost.
- The platform is ready to scale, integrate new services and support additional workloads without major redesign.