Azure Landing Zones & Cost Reduction
Taking over the development team meant inheriting a shared subscription where developers worked inside a single assigned resource group. They could not always see the supporting resources Azure created alongside their own deployments, and cleanup by other teams sometimes removed things that were still in use. What the team needed was subscriptions of their own, where they could deploy, experiment and tear things down freely. Cost was the live concern for the people running Azure, so the case had to be made in those terms first.
The Problem
Developers shared a subscription with other IT teams and worked from an assigned resource group, which made it hard to stand environments up and tear them down cleanly. Dedicated subscriptions would fix that, but adding subscriptions reads as adding cost, so it needed to pay for itself.
The Approach
Audited what was actually running and where the money was going. Azure Virtual Desktop was running 24/7, and several resources were sized well above what they were doing. Took the findings to my manager, who set up a session with the operations director, and presented them with an offer to help implement rather than a list to hand over. From there: designed the landing zone architecture for separate development, UAT and production subscriptions, worked with the operations team to implement VNet peering, and built auto-shutdown automation across VMs, databases and Kubernetes clusters, with development databases on the lowest workable tier. Also recommended a resource-tagging standard and consolidating Azure Virtual Desktop where it made sense.
Outcomes & Impact
Technologies Used
Interested in similar work?
I'd love to discuss how I can help with your project or organization.