Shared responsibility
The managed platform reduces the infrastructure and operational work required to run Elasticsearch, but the customer retains ownership of the Azure subscription, customer connectivity, identities, and data.
iVedha manages the supported platform infrastructure and lifecycle.
Responsibility overview
| Area | Customer | iVedha |
|---|---|---|
| Azure subscription, billing, policy, and quota | Own and approve | Identify platform requirements and assist with deployment issues |
| Marketplace deployment | Select, deploy, and delete the Managed Application | Publish, onboard, and support the application |
| Managed infrastructure | Do not make unsupported changes | Provision, monitor, maintain, and operate supported components |
| Customer network and routing | Configure customer-side connectivity | Provide supported public and private connectivity model |
| Private Endpoint | Create in the customer network | Provide the Private Link Service information required for connection |
| DNS | Configure company-owned or private DNS where required | Provide authoritative service hostnames |
| TLS certificates | Obtain certificate authority approval and sign the CSR | Generate the private key and CSR, apply and manage the certificate |
| Elasticsearch data | Classify, ingest, retain, and delete data | Operate the Elasticsearch platform |
| Users and roles | Define and assign application access | Provide supported identity and platform configuration workflows |
| SSO | Manage Microsoft Entra application and groups | Apply supported platform OIDC configuration |
| Elastic Agent and Fleet | Manage agent policies, integrations, and source onboarding | Operate Fleet services and assist with platform-related issues |
| OpenTelemetry | Instrument applications and validate workload telemetry | Provide supported OTel ingestion architecture and platform integration |
| Workload monitoring | Verify ingestion, search, dashboards, and application outcomes | Monitor managed-platform health |
| Capacity | Define workload growth and requirements | Monitor platform capacity and perform supported capacity changes |
| Backups and recovery | Define business RPO/RTO and validate recovered workloads | Operate supported snapshot and recovery processes |
| Maintenance | Prepare applications and users for planned changes | Perform supported platform maintenance |
| Upgrades | Validate application, client, Agent, and integration compatibility | Plan and execute managed platform upgrades |
| Elastic licensing | Define required features and commercial requirements | Apply supported licenses and assist with license procurement and renewal |
| Support | Provide business impact and safe diagnostic evidence | Troubleshoot, investigate, and operate the managed platform |
Azure and Marketplace
The customer owns the Azure subscription and remains responsible for:
- subscription governance;
- billing;
- Azure Policy;
- quota;
- Marketplace purchase permissions.
Microsoft operates Azure and the Azure Marketplace platform.
iVedha provides and operates the managed application running within the customer's Azure environment.
Managed infrastructure
iVedha manages the infrastructure required to operate the platform.
This can include:
- Azure Kubernetes Service;
- Elasticsearch and Kibana runtime components;
- Fleet and supporting services;
- managed storage;
- secrets and certificates;
- managed identities;
- platform monitoring components.
Customers should not modify Kubernetes resources, secrets, managed node infrastructure, or other platform resources directly unless the documentation explicitly identifies the action as customer-managed.
Networking and DNS
The customer manages connectivity from customer networks to the platform.
This includes:
- routing;
- peering where required;
- firewall rules;
- Private Endpoints;
- corporate DNS;
- company-owned DNS records.
iVedha provides the authoritative service information needed to establish the connection.
Do not construct endpoints or Private Link identifiers from internal Azure naming conventions.
TLS certificates
For customer-provided certificates:
iVedha:
- generates the private key;
- generates the CSR;
- includes the required SANs for Kibana, Elasticsearch, Fleet, and Logstash;
- applies the signed certificate.
Customer:
- submits the CSR to the approved certificate authority;
- obtains the signed certificate chain;
- verifies that clients trust the issuing CA.
The private key remains inside the managed platform.
Observability
The platform uses an OpenTelemetry-first observability model.
The customer is responsible for:
- application instrumentation;
- selecting telemetry sources;
- Fleet agent policies and integrations;
- validating logs, metrics, and traces;
- verifying business and application-level observability coverage.
iVedha is responsible for:
- operating Fleet and managed observability platform components;
- platform-level health monitoring;
- supporting the Elastic Agent and OpenTelemetry ingestion architecture;
- investigating managed-platform conditions.
A healthy platform does not guarantee that every customer telemetry source is producing the expected data.
Platform operations
Supported platform-level actions are performed through:
- AI chat:
https://copilot.ivedha.cloud - Support portal:
https://support.ivedha.com/
Examples include:
- administrator password reset;
- SSO changes;
- maintenance-window changes;
- certificate configuration;
- license changes;
- supported capacity changes;
- recovery assistance.
Customer data
Customer Elasticsearch data remains in the managed Elasticsearch deployment inside the customer's Azure subscription.
iVedha operational monitoring does not transfer ownership of customer indices, documents, or application data.
Customers remain responsible for:
- data classification;
- retention requirements;
- application access;
- data correctness;
- legal and regulatory requirements for their data.
Safety rules
Do not:
- modify managed infrastructure directly;
- reconstruct internal resource names;
- disable TLS verification to bypass errors;
- grant broad administrator permissions simply to troubleshoot;
- send passwords, API keys, tokens, private keys, or other secrets through normal support channels.
Use the supported workflows and contact iVedha when a platform-level change is required.
Decommissioning
Deleting the Azure Managed Application removes the managed resource group.
Customer-owned resources such as Private Endpoints, DNS records, credentials, and external integrations might require separate cleanup.
Review Delete the application before decommissioning.