Shared responsibility
The managed application reduces infrastructure work, but it does not transfer ownership of your Azure subscription, identities, network, or data to iVedha.
The customer owns Azure and data decisions. iVedha and Opsflw manage the supported platform lifecycle without owning the customer's infrastructure.
Responsibility overview
| Area | Customer | iVedha |
|---|---|---|
| Azure subscription, billing, policy, and quota | Own and approve | Identify deployment requirements |
| Marketplace purchase and managed application | Select, create, and delete | Package and support the application |
| Managed infrastructure | Avoid unsupported changes | Provision and operate supported components |
| Network routes, peering, and client DNS | Configure customer-side connectivity | Provide authoritative deployment endpoints |
| Private Endpoint | Create in the client network | Expose the deployment Private Link Service |
| TLS | Approve names and trust chain | Apply supported certificate material |
| Elasticsearch data and retention | Classify, ingest, retain, and delete data | Operate the managed platform |
| Elasticsearch users and roles | Assign least-privilege access | Provide supported access mechanisms |
| Snapshots and recovery objectives | Define and test requirements | Provide verified platform workflows |
| Monitoring and support evidence | Monitor workload outcomes and report symptoms | Operate the managed-resource monitoring agent, receive its telemetry in the iVedha monitoring cluster, and investigate platform health |
Microsoft operates Azure and enforces the Azure Managed Application and Marketplace contracts. Elastic defines Elasticsearch and Kibana product behavior, APIs, security features, and version compatibility.
The monitoring agent in the managed resource group forwards operational platform telemetry to the iVedha monitoring cluster for health monitoring and incident response. This monitoring flow does not transfer ownership of the customer's Azure resources, Elasticsearch indices, or application data to iVedha.
Customer safety rules
- Do not edit, move, or delete resources in the managed resource group.
- Do not reconstruct internal resource names from naming conventions.
- Do not share passwords, private keys, access tokens, or unredacted diagnostics in tickets.
- Obtain endpoint names and resource IDs from deployment details.
- Test backups, access changes, and client configuration in a non-production environment when one is available.
Deleting the Azure managed application also deletes its managed resource group. Review delete the application before decommissioning.