Crucible Docs

Azure deployment checklist

Give Crucible the Azure boundaries once, then let it provision and operate the full deployment end to end.

Azure deployment support

Crucible supports Azure full deployments end to end. Once the customer approves the tenant, billing, security, and network boundaries, Crucible connects its Enterprise Application, creates or verifies the subscription, provisions the runtime and supporting infrastructure, deploys the project, and keeps the resulting status and URLs in Crucible.

The running Azure environment remains customer-owned. Revoking Crucible's permissions stops future management access without requiring the workload to move out of Azure.

Azure setup path

Connect the Crucible Azure App

In Organization Settings > Azure App, an Entra administrator grants Microsoft admin consent, which creates the Enterprise Application in the tenant.

Choose the billing boundary

Microsoft Customer Agreement (MCA) tenants choose an invoice section where Crucible can create subscriptions, and assign the Enterprise Application the Subscription creator role on it. Enterprise Agreement (EA) and CSP tenants supply an existing subscription for Crucible to verify instead.

Approve deployment access

Grant the Enterprise Application the approved subscription and role-assignment scope it needs to create the environment resources and identities.

Settle the runtime decisions

Agree on region, recovery, network, egress, DNS, data residency, quotas, resource policy, support access, and release approvals using the table below before creating the full deployment.

Decisions before provisioning

Name an owner and approved outcome for each decision. If an answer is not ready, record the approval path instead of treating the item as optional.

DecisionOwnerOutcome
Billing and subscription modelAzure billing ownerAgreement type (MCA or EA/CSP), the invoice section for MCA, or existing subscription IDs for EA/CSP, plus a lifecycle owner.
Enterprise Application accessEntra administratorAdmin consent, service-principal review, approved RBAC scope, and any time-bound controls.
Region and recoveryPlatform leadPrimary and recovery regions, data-residency constraints, quotas, and global-service restrictions.
Network and egressNetwork or security leadVNet topology, private access, outbound IPs, firewall controls, and external allowlists.
Secrets and workload identitySecurity or identity leadKey Vault ownership, workload identity, secret rotation, support access, and audit requirements.
DNS and release approvalDelivery ownerDomain owner, certificate path, release gates, acceptance tests, and named approvers.

Network requirements

  • Private cluster access: Define how deployment automation and support users reach the private AKS API.
  • Controlled outbound egress: Choose the NAT Gateway or firewall path and the fixed source IPs required by dependent services.
  • Secrets and identity: Approve workload identity, support access, secret rotation, and Key Vault RBAC.
  • DNS ownership: Name the domain owner and confirm Azure DNS delegation, certificate, and validation requirements.

Customer IT checklist

  • Confirm the Azure billing owner and agreement model. For MCA, name the invoice section. For EA/CSP, supply subscription IDs Crucible can verify.
  • Confirm who approves the Crucible Enterprise Application and which security review applies.
  • State the approved RBAC scope and any time-bound or approval-gated access rules.
  • Provide region, recovery, VNet, private-access, firewall, egress, and allowlist requirements.
  • Name the DNS, certificate, secrets, telemetry, logging, and support-access owners.

On this page