A secure, enterprise-grade Azure Kubernetes Service (AKS) infrastructure managed with Terraform and automated through GitOps workflows.
SentinelFlow implements a production-ready Kubernetes infrastructure on Azure with:
- Private AKS Cluster with Azure CNI networking
- GitOps Deployment using Flux for continuous delivery
- Secure Networking with private endpoints and NSG protection
- Azure Key Vault integration for secret management
- Cloudflare Tunnel for secure ingress without exposing load balancers
- Infrastructure as Code with Terraform
- Automated CI/CD pipeline with security scanning
| Resource | Description | Configuration |
|---|---|---|
| AKS Cluster | Private Kubernetes cluster | Standard tier, auto-scaling enabled |
| Virtual Network | Isolated network (10.0.0.0/16) | AKS subnet (10.0.1.0/24) + PE subnet (10.0.2.0/24) |
| Key Vault | Premium vault with HSM keys | Private endpoint, RBAC enabled |
| Network Security Groups | Traffic filtering rules | Applied to both subnets |
| Disk Encryption Set | Customer-managed encryption | RSA-HSM 2048-bit keys |
- Infrastructure Pool (
infra): Critical system addons only, 2-3 nodes - Production Pool (
prd): User workloads, auto-scaling 2-3 nodes - VM Size: Standard_D2s_v3 (2 vCPU, 8GB RAM)
- Storage: Ephemeral OS disks with host encryption
- Flux System: GitOps controller managing deployments
- Cloudflared: Secure tunnel for ingress traffic
- HTTPBin: Sample application for testing
- Secret Store CSI: Key Vault secrets integration
- Azure Policy: Governance and compliance enforcement
SentinelFlow uses Cloudflare Tunnel (formerly Argo Tunnel) to provide secure ingress connectivity without exposing public load balancers or opening inbound firewall ports. This creates a secure, outbound-only connection from the AKS cluster to Cloudflare's edge network.
- Zero Trust Ingress: No public IPs or load balancers required
- Outbound Only: All connections initiated from inside the cluster
- Edge Security: DDoS protection and firewall at Cloudflare edge
- SSL Termination: Automatic HTTPS with Cloudflare certificates
- Global CDN: Content delivery and acceleration worldwide
Tunnel Configuration:
- Deployment: 2 replicas for high availability
- Health Checks: Built-in liveness probes on port 2000
- Tolerations: Can run on infrastructure nodes if needed
Secret Management:
- Token Storage: Cloudflare tunnel token stored in Azure Key Vault
- CSI Integration: Mounted securely via Secret Store CSI driver
- Namespace Isolation: Runs in dedicated
cloudflarednamespace
Network Flow:
Internet → Cloudflare Edge → Encrypted Tunnel → AKS Pod → Application
- Encrypted Transport: All traffic encrypted end-to-end
- Token-Based Auth: No username/password authentication required
- Network Policies: Microsegmentation within Kubernetes
- Pod Security: Runs with restricted security context
- Audit Logging: All tunnel activity logged and monitored
- Private AKS Cluster: No public API endpoint exposure
- Network Security Groups: Traffic filtering on all subnets
- Private Endpoints: Secure Key Vault access via private network
- Azure CNI: Advanced networking with network policies
- No Public IPs: All nodes use private IP addresses only
- Azure AD Integration: RBAC with managed identities
- Local Accounts Disabled: Azure AD authentication required
- Managed Identity: Pod-level authentication to Azure services
- RBAC Authorization: Fine-grained Key Vault permissions
- Service Principal: Dedicated identity for CI/CD operations
- Customer-Managed Keys: HSM-backed RSA-2048 encryption
- Disk Encryption: Host-level and disk-level encryption
- Secrets Rotation: Automatic 10-minute rotation interval
- Key Vault Premium: Hardware Security Module protection
- Purge Protection: Prevent accidental secret deletion
- Pod Security Standards: Restricted profile enforcement
- Azure Policy: Automated compliance checking
- Checkov Scanning: Infrastructure as Code security analysis
- Security Baselines: CIS and Azure security recommendations
- Audit Logging: Comprehensive activity monitoring
- Resource Limits: CPU and memory constraints on all pods
- Security Contexts: Non-root containers with restricted privileges
- Network Policies: Microsegmentation between namespaces
- Admission Controllers: Policy enforcement at deployment time
The cluster uses Flux v2 for GitOps with a three-stage deployment pipeline:
Git Repository → Flux Controller → Kubernetes Cluster
↓ ↓ ↓
Manifests Detects Changes Applies Resources
1. SecretProviderClass (./manifests/SecretProviderClass/)
- Configures Azure Key Vault CSI driver integration
- Substitutes Azure identity variables automatically:
${AZURE_CLIENT_ID}- AKS managed identity client ID${AZURE_KEYVAULT_NAME}- Key Vault name${AZURE_TENANT_ID}- Azure AD tenant ID
2. Cloudflared Tunnel (./manifests/cloudflared/)
- Deploys secure tunnel infrastructure
- Mounts secrets from Key Vault via CSI driver
- Depends on SecretProviderClass being ready
- Creates
cloudflarednamespace with security policies
3. Applications (./manifests/httpbin/)
- Sample workload deployment
- Demonstrates resource limits and security contexts
- Pod Security Standards enforcement
- Depends on tunnel infrastructure being ready
# Key settings from gitops.tf
git_repository:
url: "https://ozennouamine02@dev.azure.com/ozennouamine02/SentinelFlow/_git/SentinelFlow"
branch: "main"
sync_interval: "30s"
kustomizations:
retry_interval: "30s"
garbage_collection: enabled
dependency_chain: secretproviderclass → cloudflared → httpbinThe project uses Azure DevOps Pipelines for automated infrastructure deployment with built-in security scanning and approval workflows.
1. Infrastructure Validation
- Terraform installation and initialization
- Infrastructure validation and formatting checks
- Generate and review Terraform execution plan
- Environment variable injection for secrets
2. Security Scanning
- Checkov Analysis: Static security analysis for Terraform code
- Azure Pipelines Scanning: Pipeline configuration security review
- Infrastructure Compliance: CIS and Azure security baseline validation
- Dependency Scanning: Check for vulnerable Terraform providers
3. Manual Approval Gate
- Human review of Terraform plan output
- Email notification to designated approvers
- Infrastructure change impact assessment
- Security and compliance verification
4. Automated Deployment
- Terraform apply with state file management
- Azure resource provisioning and configuration
- GitOps configuration sync with Flux
- Post-deployment validation checks
# Key pipeline settings from azure-pipelines.yml
trigger: ["main"]
pool: "ubuntu-latest"
jobs:
- Terraform (validate & plan)
- Checkov (security scanning)
- WaitForApproval (manual gate)
- TerraformApply (deployment)
# Required variables:
# - SERVICE_CONNECTION_NAME: Azure service connection
# - TF_VAR_tunnel_token (secret): Cloudflare tunnel token
# - TF_VAR_https_key_base64 (secret): Git access token- Service Principal Authentication: Dedicated identity for pipeline execution
- Variable Groups: Secure storage of sensitive configuration
- Branch Protection: Deployment only from main branch
- Approval Required: Human verification before infrastructure changes
- Audit Trail: Complete deployment history and change tracking