Skip to content

Architecture details

The managed platform combines the Elastic Stack with Azure infrastructure and iVedha-managed operations.

The platform runs in the customer's Azure subscription while iVedha provides supported monitoring, configuration, lifecycle management, and operational assistance.

Architecture overview

Managed platform architecture

The diagram is conceptual. The exact Azure resources depend on the Marketplace plan, deployment configuration, region, and platform version.

Major platform components

Elasticsearch

Elasticsearch provides the core data platform for:

  • search;
  • indexing;
  • analytics;
  • observability data;
  • vector and semantic search.

Customer data remains in the Elasticsearch deployment running in the customer's Azure subscription.

Kibana

Kibana provides the primary user interface for:

  • search and analytics;
  • dashboards and visualization;
  • observability;
  • Fleet;
  • users and roles;
  • supported Elasticsearch administration.

Elastic Agent

Elastic Agent is the standard collection layer for observability workloads.

It can:

  • collect host and infrastructure telemetry;
  • collect Kubernetes telemetry;
  • receive application OpenTelemetry data;
  • run supported Elastic integrations;
  • forward logs, metrics, and traces into Elasticsearch.

Fleet

Fleet centrally manages Elastic Agents.

Fleet controls:

  • agent enrollment;
  • agent policies;
  • integrations;
  • configuration distribution;
  • health;
  • agent lifecycle.

OpenTelemetry

The managed observability architecture is OpenTelemetry-first.

OpenTelemetry provides the common telemetry model for:

  • logs;
  • metrics;
  • traces.

Elastic Agent and supported integrations collect or receive telemetry and align new observability workloads with OpenTelemetry semantic conventions and OTel-native data streams.

Existing ECS-compatible integrations can continue to operate where required.

Logstash

Logstash can be used when existing or specialized ingestion pipelines require transformation, routing, or protocol handling not covered by the standard Elastic Agent integration model.

For new observability onboarding, prefer Elastic Agent and OpenTelemetry unless there is a specific requirement for Logstash.

Azure infrastructure

The platform uses Azure services to provide the required compute, networking, security, and storage.

Typical components include:

  • Azure Kubernetes Service;
  • Azure Key Vault;
  • Azure Storage;
  • Azure networking;
  • managed identities;
  • Azure RBAC;
  • Private Link where private connectivity is used.

The exact resource layout can change between platform versions.

Customers should not depend on internal resource names or modify managed infrastructure directly.

Customer and managed boundaries

Boundary Responsibility
Azure subscription Customer
Managed platform infrastructure iVedha-managed
Customer networking and DNS Customer
Elasticsearch application data Customer
Elasticsearch platform operations iVedha
Application users and data access Customer
Platform health monitoring iVedha
Application and workload monitoring Customer
Elastic Agent policies and integrations Customer, with iVedha assistance
Managed lifecycle actions iVedha-supported workflow

For detailed ownership, see Shared responsibility.

Operational control

Supported platform-level configuration and lifecycle actions are performed through the iVedha AI chat application:

https://copilot.ivedha.cloud

Examples include:

  • administrator password reset;
  • maintenance-window changes;
  • SSO configuration;
  • TLS certificate configuration;
  • license changes;
  • supported capacity changes.

The support portal is available for tracked cases and engineering investigation:

https://support.ivedha.com/

Do not modify Kubernetes resources, secrets, Elasticsearch infrastructure, or other managed platform components directly unless the documentation explicitly identifies the action as customer-managed.

Platform monitoring

The managed platform forwards operational health telemetry to the iVedha operations environment.

This telemetry is used to monitor supported platform components and investigate platform conditions.

Managed monitoring does not mean that customer Elasticsearch data is moved into the iVedha operations environment.

Customer application data remains in the customer's managed Elasticsearch deployment.

Observability data flow

The preferred observability architecture is:

Applications / Hosts / Kubernetes / Azure Services
                         ↓
                    Elastic Agent
                         ↓
               Fleet-managed policy
                         ↓
             OpenTelemetry telemetry
                         ↓
                    Elasticsearch
                         ↓
                       Kibana

OpenTelemetry provides the common logs, metrics, and traces model while Fleet and Elastic Agent provide centralized collection and management.

Search data flow

Application search data typically follows a simpler path:

Application / Data Pipeline
          ↓
     Elasticsearch API
          ↓
      Elasticsearch
          ↓
   Application / Kibana

Search documents do not need to use the OpenTelemetry telemetry model.

Public access

When public access is enabled, supported platform services can be reached through public HTTPS endpoints.

TLS and authentication are still required.

Company security controls can further restrict which clients are permitted to use the endpoints.

Private access

When public access is disabled, customers establish private connectivity using Azure Private Link.

The customer creates a Private Endpoint using the Private Link Service information provided for the deployment.

Private access requires:

  • an approved Private Endpoint;
  • network routing;
  • private DNS;
  • trusted TLS certificates.

DNS and service hostnames

The deployment provides the authoritative service hostnames.

Depending on enabled components, these can include:

  • Elasticsearch;
  • Kibana;
  • Fleet;
  • Logstash.

Do not construct hostnames from internal Azure resource names.

The platform-generated CSR contains the SANs required for the deployment services.

Data remains in the customer environment

The core design principle is that Elasticsearch data remains in the customer's Azure subscription.

iVedha operates and monitors the platform without requiring customer application data to be hosted in a separate iVedha Elasticsearch environment.

This provides a managed operating model while preserving customer control of the Azure subscription and data location.

See: