Declared resources
- Virtual network and AppSubnet.
- Key Vault for protected configuration.
- Cosmos DB account for structured audit information.
- Azure OpenAI account with public network access disabled.
Recommended build-out order
Complete private connectivity and DNS, add managed identities and least-privilege roles, configure data and model resources, deploy application workloads, then add monitoring, retention, recovery and policy validation.
Integrated system view
Infrastructure sequence: parameterized Bicep → VNet and subnet → Key Vault → Cosmos DB → Azure OpenAI boundary → private integration and validation.
Infrastructure sequence: parameterized Bicep → VNet and subnet → Key Vault → Cosmos DB → Azure OpenAI boundary → private integration and validation.
Scope
The document explains intended architecture and code. It is not certification or evidence that the environment has been deployed or tested.