diff --git a/_partials/_azure-features.md b/_partials/_azure-features.md index 5023a4b8eb..1c8fcc239e 100644 --- a/_partials/_azure-features.md +++ b/_partials/_azure-features.md @@ -6,52 +6,53 @@ The available $PRICING_PLANs are: The features included in each [$PRICING_PLAN][pricing-plans] are: -| Feature | $PERFORMANCE | $SCALE | $ENTERPRISE | -|---------------------------------------------------------------|----------------------------------------|------------------------------------------------|--------------------------------------------------| -| **Compute and storage** | | | | -| Number of $SERVICE_SHORTs | Up to 2 free and 4 standard services | Up to 2 free and and unlimited standard services | Up to 2 free and and unlimited standard services | -| CPU limit per $SERVICE_SHORT | Up to 8 CPU | Up to 32 CPU | Up to 64 CPU | -| Memory limit per $SERVICE_SHORT | Up to 32 GB | Up to 128 GB | Up to 256 GB | -| Storage limit per $SERVICE_SHORT | Up to 16 TB | Up to 16 TB | Up to 16 TB | -| Bottomless blob storage | | Unlimited | Unlimited | -| Independently scale compute and storage | Standard services only | Standard services only | Standard services only | -| **Data services and workloads** | | | | -| Relational | ✓ | ✓ | ✓ | -| Time-series | ✓ | ✓ | ✓ | -| Vector search | ✓ | ✓ | ✓ | -| AI workflows (coming soon) | ✓ | ✓ | ✓ | -| Cloud SQL editor | 3 seats | 10 seats | 20 seats | -| Charts | ✓ | ✓ | ✓ | -| Dashboards | 2 | Unlimited | Unlimited | -| **Storage and performance** | | | | -| IOPS | 3,000 - 5,000 | 5,000 - 8,000 | 5,000 - 8,000 | -| Bandwidth (autoscales) | 125 - 250 Mbps | 250 - 500 Mbps | Up to 500 mbps | -| I/O boost | | Add-on:
Up to 16K IOPS, 1000 Mbps BW | Add-on:
Up to 16K IOPS, 1000 Mbps BW | -| **Availability and monitoring** | | | | -| High-availability replicas
(Automated multi-AZ failover) | ✓ | ✓ | ✓ | -| Read replicas | | ✓ | ✓ | -| Backup reports | | 14 days | 14 days | -| Point-in-time recovery and forking | 3 days | 14 days | 14 days | -| Performance insights | ✓ | ✓ | ✓ | -| Metrics and log exporters | | ✓ | ✓ | -| **Security and compliance** | | | | -| Role-based access | ✓ | ✓ | ✓ | -| End-to-end encryption | ✓ | ✓ | ✓ | -| [HIPAA compliance][hipaa-compliance] | | | ✓ | +| Feature | $PERFORMANCE | $SCALE | $ENTERPRISE | +|---------------------------------------------------------------|----------------------------------------|----------------------------------------------|--------------------------------------------------| +| **Compute and storage** | | | | +| Number of $SERVICE_SHORTs | Up to 2 free and 4 standard services | Up to 2 free and and unlimited standard services | Up to 2 free and and unlimited standard services | +| CPU limit per $SERVICE_SHORT | Up to 8 CPU | Up to 32 CPU | Up to 64 CPU | +| Memory limit per $SERVICE_SHORT | Up to 32 GB | Up to 128 GB | Up to 256 GB | +| Storage limit per $SERVICE_SHORT | Up to 16 TB | Up to 16 TB | Up to 16 TB | +| Bottomless blob storage | | Unlimited | Unlimited | +| Independently scale compute and storage | Standard services only | Standard services only | Standard services only | +| **Data services and workloads** | | | | +| Relational | ✓ | ✓ | ✓ | +| Time-series | ✓ | ✓ | ✓ | +| Vector search | ✓ | ✓ | ✓ | +| AI workflows (coming soon) | ✓ | ✓ | ✓ | +| Cloud SQL editor | 3 seats | 10 seats | 20 seats | +| Charts | ✓ | ✓ | ✓ | +| Dashboards | 2 | Unlimited | Unlimited | +| **Storage and performance** | | | | +| IOPS | 3,000 - 5,000 | 5,000 - 8,000 | 5,000 - 8,000 | +| Bandwidth (autoscales) | 125 - 250 Mbps | 250 - 500 Mbps | Up to 500 mbps | +| I/O boost | | Add-on:
Up to 16K IOPS, 1000 Mbps BW | Add-on:
Up to 16K IOPS, 1000 Mbps BW | +| **Availability and monitoring** | | | | +| High-availability replicas
(Automated multi-AZ failover) | ✓ | ✓ | ✓ | +| Read replicas | | ✓ | ✓ | +| Backup reports | | 14 days | 14 days | +| Point-in-time recovery and forking | 3 days | 14 days | 14 days | +| Performance insights | ✓ | ✓ | ✓ | +| Metrics and log exporters | | ✓ | ✓ | +| **Security and compliance** | | | | +| Role-based access | ✓ | ✓ | ✓ | +| Azure Private Link | ✓ |✓|✓| +| End-to-end encryption | ✓ | ✓ | ✓ | +| [HIPAA compliance][hipaa-compliance] | | | ✓ | | IP address allow list | 1 list with up to 10 IP addresses | Up to 10 lists with up to 10 IP addresses each | Up to 10 lists with up to 100 IP addresses each | -| Multi-factor authentication | ✓ | ✓ | ✓ | -| Federated authentication (SAML) | | | ✓ | -| SOC 2 Type 2 report | | ✓ | ✓ | -| Penetration testing report | | | ✓ | -| Security questionnaire and review | | | ✓ | -| Pay by invoice | Available at minimum spend | Available at minimum spend | ✓ | -| [Uptime SLAs][commercial-sla] | Standard | Standard | Enterprise | -| **Support and technical services** | | | | -| Community support | ✓ | ✓ | ✓ | -| Email support | ✓ | ✓ | ✓ | -| Production support | Add-on | Add-on | ✓ | -| Named account manager | | | ✓ | -| JOIN services (Jumpstart Onboarding and INtegration) | | Available at minimum spend | ✓ | +| Multi-factor authentication | ✓ | ✓ | ✓ | +| Federated authentication (SAML) | | | ✓ | +| SOC 2 Type 2 report | | ✓ | ✓ | +| Penetration testing report | | | ✓ | +| Security questionnaire and review | | | ✓ | +| Pay by invoice | Available at minimum spend | Available at minimum spend | ✓ | +| [Uptime SLAs][commercial-sla] | Standard | Standard | Enterprise | +| **Support and technical services** | | | | +| Community support | ✓ | ✓ | ✓ | +| Email support | ✓ | ✓ | ✓ | +| Production support | Add-on | Add-on | ✓ | +| Named account manager | | | ✓ | +| JOIN services (Jumpstart Onboarding and INtegration) | | Available at minimum spend | ✓ | For a personalized quote, [get in touch with $COMPANY][contact-company]. diff --git a/_partials/_azure-privatelink.md b/_partials/_azure-privatelink.md new file mode 100644 index 0000000000..d7dc1231da --- /dev/null +++ b/_partials/_azure-privatelink.md @@ -0,0 +1,95 @@ +import IntegrationPrereqsNoConnection from "versionContent/_partials/_prereqs-cloud-no-connection.mdx"; + +## Prerequisites + + + +* Create an [Azure account](https://azure.microsoft.com/en-gb/pricing/purchase-options/azure-account) with an active subscription. +* Configure [permissions](https://learn.microsoft.com/en-us/azure/private-link/rbac-permissions) to create private endpoints and manage network resources. +* Create an [Azure Virtual Network](https://learn.microsoft.com/en-us/azure/virtual-network/quickstart-create-virtual-network?tabs=portal) with a subnet for the resources you will connect to $CLOUD_LONG. + +## Set up Azure Private Link connection + + + +Azure Private Link is currently in private preview. To request access in $CONSOLE_LONG, go to `Security` > `Private Endpoints` and click `Request access`. Then refresh the page and follow the steps below. + + + +Take the following steps to connect $CLOUD_LONG to Azure with Private Link: + + + +1. **Create a Private Link subscription authorization** + + 1. In [$CONSOLE_LONG][console-azure-privatelink], select `Security` > `Private Endpoints` > `Configure Private Endpoint Connection`. + + 1. Enter your [Azure subscription ID](https://learn.microsoft.com/en-us/azure/azure-portal/get-subscription-tenant-id#find-your-azure-subscription) and specify a name for the Private Link authorization, then click a checkmark next to it. + + ![Azure Private Link authorization][azure-privatelink-authorization] + + 1. Under `Alias`, copy the alias for the region in which you need to create the connection. + + Choose the region closest to your Azure resources for optimal performance. + + 1. Click `Done`. + + $CLOUD_LONG confirms your authorization. Once it is confirmed, you can create multiple private endpoints from the same authorized subscription. + + ![Azure Private Link authorization complete][azure-privatelink-authorization-complete] + +1. **Create a private endpoint** + + 1. In [Azure Portal](https://azure.microsoft.com/en-us/get-started/azure-portal), go to `Private endpoints` and click `Create`. + + ![Create Azure Private Endpoint][create-azure-endpoint] + + 1. Configure the endpoint: + 1. In `Subscription`, select the subscription you have previously authorized in $CLOUD_LONG. + 1. In `Resource group`, select an existing resource group or create a new one for your private endpoint. + 1. Provide a name for your endpoint. + 1. Select the region where your Virtual Network is deployed, then click `Next: Resource`. + 1. In `Connection method`, select `Connect to an Azure resource by resource ID or alias`. + 1. In `Resource ID or alias`, paste the alias you have copied from $CONSOLE_LONG. + 1. In `Request message`, enter your [$PROJECT_LONG ID][find-connection-details], then click `Next: Virtual Network`. + 1. Select the Virtual Network and subnet for your endpoint, optionally select an application security group, then click `Next: DNS`. + 1. Optionally configure private DNS integration and tags for your endpoint, then click `Next: Review + create`. + 1. Review your config and click `Create`. + Azure creates your private endpoint. Wait for the deployment to succeed. + 1. Go to `Private endpoints` and copy the private endpoint IP from the `Private IP` column. + +1. **Sync the connection** + + 1. In [$CONSOLE_LONG][console-azure-privatelink] > `Security` > `Private Link`, click `Refresh`. $CLOUD_LONG automatically approves connections from authorized subscriptions. Your connection appears in the list. + + ![Azure Private Endpoint IP][azure-private-endpoint-ip] + + 1. Click `Add IP` and paste the IP address you have copied from Azure Portal. + + 1. Click the three dots next to your connection and select `+ Attach service`. Select your $SERVICE_SHORT from the dropdown and click `Attach`. You can attach a $SERVICE_SHORT to one Private Endpoint connection. + + + + After attaching a $SERVICE_SHORT to a Private Endpoint, it is no longer accessible from the public internet. Make sure all your applications are configured to connect through the Private Endpoint before attaching your $SERVICE_SHORT. + + + + 1. From a VM inside your Azure VNet, connect to your $SERVICE_SHORT using a connection string with your [connection details][find-connection-details]. You should be able to connect successfully. + + + + +## Manage connections + +- To detach a $SERVICE_SHORT from a Private Endpoint connection, go to `Security` > `Private Endpoints` and expand the details of the corresponding connection. Click the trash bin icon and confirm detaching your $SERVICE_SHORT. +- To edit or remove a connection, click the three dots next to the connection in the list and select `Edit` or `Disconnect`, respectively. Detach $SERVICE_SHORTs from the connection before deleting it. +- To remove an authorization, click `Manage Authorizations` > trash bin icon. Disconnect all relevant connections before removing an authorization. + + +[console-azure-privatelink]: https://console.cloud.timescale.com/dashboard/azure-privatelink +[find-connection-details]: /integrations/:currentVersion:/find-connection-details/ +[regions]: /about/:currentVersion:/supported-platforms/#available-regions +[azure-privatelink-authorization]: https://assets.timescale.com/docs/images/tiger-cloud-console/configure-private-link-authorization.png +[azure-privatelink-authorization-complete]: https://assets.timescale.com/docs/images/tiger-cloud-console/private-link-authorization-complete.png +[azure-private-endpoint-ip]: https://assets.timescale.com/docs/images/tiger-cloud-console/private-link-add-ip.png +[create-azure-endpoint]: https://assets.timescale.com/docs/images/tiger-cloud-console/create-private-endpoint-azure.png \ No newline at end of file diff --git a/_partials/_integration-prereqs-cloud-only.md b/_partials/_integration-prereqs-cloud-only.md index ab90078704..2bacc07933 100644 --- a/_partials/_integration-prereqs-cloud-only.md +++ b/_partials/_integration-prereqs-cloud-only.md @@ -1,9 +1,7 @@ To follow the steps on this page: -* Create a target [$SERVICE_LONG][create-service] with the Real-time analytics capability. - - You need your [connection details][connection-info]. +* Create a target [$SERVICE_LONG][create-service] with the Real-time analytics capability. You need your [connection details][connection-info]. [connection-info]: /integrations/:currentVersion:/find-connection-details/ [create-service]: /getting-started/:currentVersion:/services/ diff --git a/about/feature-comparison.md b/about/feature-comparison.md index 4e198d771c..4a7e6a5e80 100644 --- a/about/feature-comparison.md +++ b/about/feature-comparison.md @@ -9,93 +9,94 @@ keywords: [TimescaleDB, Tiger Cloud] The following table compares the features available in $CLOUD_LONG and self-hosted $TDB_COMMUNITY. -| Feature | $CLOUD_LONG on AWS | $CLOUD_LONG on Azure | self-hosted $TIMESCALE_DB | -|---------------------------------------------------------------------------------------------------------------|-----------------------------------|------------------------------------|---------------------------------------------| -| **Best-in-сlass $PG performance** | | | | -| Automatic partitioning via hypertables for efficient indexes and faster ingest | | | | -| Continuous aggregates | | | | -| Time/partition-oriented constraint exclusion for faster queries | | | | -| Skip scans, ordered appends, custom optimizations for faster `LIMIT` and `DISTINCT` queries | | | | -| Columnar storage for accelerated scans | | | | -| Vectorized query execution (SIMD) | | | | -| Specialized vector indexes for AI applications | | | | -| $PG_CONNECTOR_CAP | | | Manual | -| $S3_CONNECTOR_CAP | | | | -| Source Apache Kafka connector | | | | -| $LAKE_LONG destination connector from $CLOUD_LONG to Iceberg-backed S3 Tables | | | | -| In-Console CSV, Parquet, and text file imports | | | | -| **Flexible analysis with full SQL** | | | | -| Complete $PG ecosystem including all $PG features, connectors, and third-party drivers | | | | -| Cross-table JOINs for time-series and events tables with relational tables | | | | -| Rich timestamp and timezone support | | | | -| Flexible time-bucketing for time-oriented analysis | | | | -| Advanced hyperfunctions including interpolation, approximation, and visualization functions | | | | -| Geospatial and vector data types | | | | -| **Automated data management** | | | | -| Native compression (up to 98% storage savings) | | | | -| Columnar storage format with fast scans | | | | -| Data retention policies | | | | -| Data tiering with automated policies | | | | -| Data reordering for efficient disk scans | | | | -| Data downsampling for efficient historical analysis | | | | -| Background job scheduler and user-defined jobs | | | | -| **Enterprise scalability** | | | | -| Disaggregated compute and storage | | | Manual | -| Dynamic compute resizing | | | | -| Dynamic disk storage with usage-based pricing | | | | -| Dynamic I/O provisioning for high-read/ high-write performance | | | Manual | +| Feature | $CLOUD_LONG on AWS | $CLOUD_LONG on Azure | self-hosted $TIMESCALE_DB | +|---------------------------------------------------------------------------------------------------------------|-----------------------------------|-------------------------------------|---------------------------------------------| +| **Best-in-сlass $PG performance** | | | | +| Automatic partitioning via hypertables for efficient indexes and faster ingest | | | | +| Continuous aggregates | | | | +| Time/partition-oriented constraint exclusion for faster queries | | | | +| Skip scans, ordered appends, custom optimizations for faster `LIMIT` and `DISTINCT` queries | | | | +| Columnar storage for accelerated scans | | | | +| Vectorized query execution (SIMD) | | | | +| Specialized vector indexes for AI applications | | | | +| $PG_CONNECTOR_CAP | | | Manual | +| $S3_CONNECTOR_CAP | | | | +| Source Apache Kafka connector | | | | +| $LAKE_LONG destination connector from $CLOUD_LONG to Iceberg-backed S3 Tables | | | | +| In-Console CSV, Parquet, and text file imports | | | | +| **Flexible analysis with full SQL** | | | | +| Complete $PG ecosystem including all $PG features, connectors, and third-party drivers | | | | +| Cross-table JOINs for time-series and events tables with relational tables | | | | +| Rich timestamp and timezone support | | | | +| Flexible time-bucketing for time-oriented analysis | | | | +| Advanced hyperfunctions including interpolation, approximation, and visualization functions | | | | +| Geospatial and vector data types | | | | +| **Automated data management** | | | | +| Native compression (up to 98% storage savings) | | | | +| Columnar storage format with fast scans | | | | +| Data retention policies | | | | +| Data tiering with automated policies | | | | +| Data reordering for efficient disk scans | | | | +| Data downsampling for efficient historical analysis | | | | +| Background job scheduler and user-defined jobs | | | | +| **Enterprise scalability** | | | | +| Disaggregated compute and storage | | | Manual | +| Dynamic compute resizing | | | | +| Dynamic disk storage with usage-based pricing | | | | +| Dynamic I/O provisioning for high-read/ high-write performance | | | Manual | | Low-cost storage with infinite capacity | | | | -| Transparent queries across high-performance and low-cost tiers | | | | -| Read replicas with load balancing for seamless read scaling | | | Manual | -| Connection pooling for connection scaling | | | Manual | -| Automated resource-aware parameter tuning | | | | -| Terraform for infrastructure-as-code control | | | | -| **High availability and reliability** | | | | -| Multi-AZ deployments for high availability | | | Manual | -| Continuous incremental backup and automated restore | | | Manual | +| Transparent queries across high-performance and low-cost tiers | | | | +| Read replicas with load balancing for seamless read scaling | | | Manual | +| Connection pooling for connection scaling | | | Manual | +| Automated resource-aware parameter tuning | | | | +| Terraform for infrastructure-as-code control | | | | +| **High availability and reliability** | | | | +| Multi-AZ deployments for high availability | | | Manual | +| Continuous incremental backup and automated restore | | | Manual | | Cross-region backup | | 🔜 | | -| Point-in-time recovery and branching | | | Manual | -| Regular database and disk snapshots to enable fast restore | | | | -| Rapid recovery for all services by fast database restart and remote disk remount | | | | -| Memory guard protections to avoid database out-of-memory crashes | | | | -| Decoupled control/data planes for greater resilience | | | | -| Commercial SLAs | | | | -| **Automated upgrades and software patching** | | | | -| Automated upgrades during maintenance windows | | | | -| Phased, zero-downtime $TIMESCALE_DB and $PG minor upgrades | | | | -| $PG major version upgrades with forking workflow and disk snapshots to minimize downtime | | | | -| HA-replica-aware coordinated upgrades | | | | -| Fleet-wide version and stability monitoring with staged roll-out/roll-back upgrades | | | | -| **Security and compliance** | | | | -| SOC 2 Type 2, GDPR, HIPAA certified compliance | | | | -| Data encryption at rest (both disk and backup) | | | Manual | -| Data encryption in transit | | | Manual | -| Database SSL with fully verifiable certificate chains | | | | -| Control plane role-based access control | | | | -| Database role-based access control | | | | -| Multi-factor authentication | | | | -| Corporate SSO and SAML | | | | -| VPC peering | | | | -| AWS Transit Gateway | | | | -| Layered database "privilege escalation" protections | | | | -| Secure SDLC practices and vulnerability scanning, third-party pen testing | | | | -| **Deep observability** | | | | -| Operational database visibility to understand performance, uncover regressions, optimize performance | | | | -| Automated query analysis and statistics | | | | -| Per-query drill-downs into execution times, row results, plans, memory buffer management, cache performance | | | | -| In-Console metric visualization and system logs | | | | -| AWS CloudWatch exporter | | | | -| Prometheus exporter | | | | -| Datadog exporter | | | | -| Azure Monitor exporter | | | | -| Connection monitoring | | | Manual | -| Connection management | | | Manual | -| **Production-grade support and operations** | | | | -| 24/7 follow-the-sun support with global support team across APAC, EMEA, and Americas | | | [Contact sales][contact-sales] | -| Production support (severity 1) | | | [Contact sales][contact-sales] | -| Architectural reviews, data modeling, and query optimization and assistance, feature testing, and migration support | | | [Contact sales][contact-sales] | -| 24/7 operational monitoring and control | | | [Contact sales][contact-sales] | -| 98%+ customer satisfaction (CSAT scores) | | | [Contact sales][contact-sales] | +| Point-in-time recovery and branching | | | Manual | +| Regular database and disk snapshots to enable fast restore | | | | +| Rapid recovery for all services by fast database restart and remote disk remount | | | | +| Memory guard protections to avoid database out-of-memory crashes | | | | +| Decoupled control/data planes for greater resilience | | | | +| Commercial SLAs | | | | +| **Automated upgrades and software patching** | | | | +| Automated upgrades during maintenance windows | | | | +| Phased, zero-downtime $TIMESCALE_DB and $PG minor upgrades | | | | +| $PG major version upgrades with forking workflow and disk snapshots to minimize downtime | | | | +| HA-replica-aware coordinated upgrades | | | | +| Fleet-wide version and stability monitoring with staged roll-out/roll-back upgrades | | | | +| **Security and compliance** | | | | +| SOC 2 Type 2, GDPR, HIPAA certified compliance | | | | +| Data encryption at rest (both disk and backup) | | | Manual | +| Data encryption in transit | | | Manual | +| Database SSL with fully verifiable certificate chains | | | | +| Control plane role-based access control | | | | +| Database role-based access control | | | | +| Multi-factor authentication | | | | +| Corporate SSO and SAML | | | | +| VPC peering | | | | +| AWS Transit Gateway | | | | +| Azure Private Link | | | | +| Layered database "privilege escalation" protections | | | | +| Secure SDLC practices and vulnerability scanning, third-party pen testing | | | | +| **Deep observability** | | | | +| Operational database visibility to understand performance, uncover regressions, optimize performance | | | | +| Automated query analysis and statistics | | | | +| Per-query drill-downs into execution times, row results, plans, memory buffer management, cache performance | | | | +| In-Console metric visualization and system logs | | | | +| AWS CloudWatch exporter | | | | +| Prometheus exporter | | | | +| Datadog exporter | | | | +| Azure Monitor exporter | | | | +| Connection monitoring | | | Manual | +| Connection management | | | Manual | +| **Production-grade support and operations** | | | | +| 24/7 follow-the-sun support with global support team across APAC, EMEA, and Americas | | | [Contact sales][contact-sales] | +| Production support (severity 1) | | | [Contact sales][contact-sales] | +| Architectural reviews, data modeling, and query optimization and assistance, feature testing, and migration support | | | [Contact sales][contact-sales] | +| 24/7 operational monitoring and control | | | [Contact sales][contact-sales] | +| 98%+ customer satisfaction (CSAT scores) | | | [Contact sales][contact-sales] | [contact-sales]: mailto:sales@tigerdata.com diff --git a/integrations/microsoft-azure.md b/integrations/microsoft-azure.md index 9c05fb69ff..adcf1c25a9 100644 --- a/integrations/microsoft-azure.md +++ b/integrations/microsoft-azure.md @@ -8,39 +8,18 @@ keywords: [Azure, integrations] import IntegrationPrereqsCloud from "versionContent/_partials/_integration-prereqs-cloud-only.mdx"; import TransitGateway from "versionContent/_partials/_transit-gateway.mdx"; -import NotSupportedAzure from "versionContent/_partials/_not-supported-for-azure.mdx"; +import AzurePrivateLink from "versionContent/_partials/_azure-privatelink.mdx"; +import NotSupportedAws from "versionContent/_partials/_not-supported-for-aws.mdx"; # Integrate Microsoft Azure with $CLOUD_LONG - [Microsoft Azure][azure] is a cloud computing platform and services suite, offering infrastructure, AI, analytics, security, and developer tools to help businesses build, deploy, and manage applications. -This page explains how to integrate your Microsoft Azure infrastructure with $CLOUD_LONG using [AWS Transit Gateway][aws-transit-gateway]. - -## Prerequisites - - - -- Set up [AWS Transit Gateway][gtw-setup]. - - -## Connect your Microsoft Azure infrastructure to your $SERVICE_LONGs - -To connect to $CLOUD_LONG: - - - -1. **Connect your infrastructure to AWS Transit Gateway** - - Establish connectivity between Azure and AWS. See the [AWS architectural documentation][azure-aws] for details. - - +This page explains how to integrate your Microsoft Azure infrastructure with $CLOUD_LONG on Azure using [Azure Private Link][azure-private-link]. - + -You have successfully integrated your Microsoft Azure infrastructure with $CLOUD_LONG. + -[aws-transit-gateway]: https://aws.amazon.com/transit-gateway/ -[azure-aws]: https://aws.amazon.com/blogs/modernizing-with-aws/designing-private-network-connectivity-aws-azure/ +[azure-private-link]: https://learn.microsoft.com/en-us/azure/private-link/private-link-overview [azure]: https://azure.microsoft.com/en-gb/ -[gtw-setup]: https://docs.aws.amazon.com/vpc/latest/tgw/tgw-getting-started.html diff --git a/use-timescale/page-index/page-index.js b/use-timescale/page-index/page-index.js index ba7ea97492..2760337ddd 100644 --- a/use-timescale/page-index/page-index.js +++ b/use-timescale/page-index/page-index.js @@ -699,6 +699,12 @@ module.exports = [ excerpt: "Secure your Tiger Cloud services with VPC peering and AWS PrivateLink", }, + { + title: "Azure Private Link", + href: "azure-privatelink", + excerpt: + "Secure your Tiger Cloud services with Azure Private Link", + }, { title: "IP allow list", href: "ip-allow-list", diff --git a/use-timescale/security/azure-privatelink.md b/use-timescale/security/azure-privatelink.md new file mode 100644 index 0000000000..9a497396e0 --- /dev/null +++ b/use-timescale/security/azure-privatelink.md @@ -0,0 +1,24 @@ +--- +title: Azure Private Link +excerpt: Azure Private Link ensures that your Tiger Cloud services are only accessible through your secured Azure infrastructure. Set up Private Link connections in Tiger Cloud Console +products: [cloud] +price_plans: [performance, scale, enterprise] +keywords: [PrivateLink, Azure, private endpoint, services, operations, security] +tags: [azure, security] +cloud_ui: + path: + - [services, :serviceId, operations, azure-privatelink] +--- + +import AzurePrivateLink from "versionContent/_partials/_azure-privatelink.mdx"; +import NotSupportedAws from "versionContent/_partials/_not-supported-for-aws.mdx"; + +# Secure your $CLOUD_LONG services with Azure Private Link + +Azure Private Link creates a private connection between your Azure Virtual Network and $SERVICE_LONGs hosted on Azure, eliminating exposure to the public internet. Applications in your Azure VNet connect to a Private Endpoint with a private IP address, which links to $CLOUD_LONG. Once connected, your $SERVICE_SHORTs become accessible only through the Private Endpoint, providing enhanced security, reduced attack surface, and compliance with data isolation requirements. + + + + + +[azure-privatelink-architecture]: https://assets.timescale.com/docs/images/tiger-cloud-console/azure-privatelink-architecture.svg \ No newline at end of file diff --git a/use-timescale/security/index.md b/use-timescale/security/index.md index 13b4135c64..653e951b79 100644 --- a/use-timescale/security/index.md +++ b/use-timescale/security/index.md @@ -17,9 +17,11 @@ Learn how $CLOUD_LONG protects your data and privacy. * Connect with a [stricter SSL mode][ssl-mode] * Secure your $SERVICE_SHORTs with [VPC peering][vpc-peering] * Connect to your $SERVICE_SHORTs from any cloud with [AWS Transit Gateway][transit-gateway] +* Secure your $SERVICE_SHORTs with [Azure Private Link][azure-privatelink] * Restrict access with an [IP address allow list][ip-allowlist] [2fa]: /use-timescale/:currentVersion:/security/multi-factor-authentication/ +[azure-privatelink]: /use-timescale/:currentVersion:/security/azure-privatelink/ [client-credentials]: /use-timescale/:currentVersion:/security/client-credentials/ [database-rbac]: /use-timescale/:currentVersion:/security/read-only-role/ [ip-allowlist]: /use-timescale/:currentVersion:/security/ip-allow-list/ diff --git a/use-timescale/security/transit-gateway.md b/use-timescale/security/transit-gateway.md index 90afc283b8..8e2256fe64 100644 --- a/use-timescale/security/transit-gateway.md +++ b/use-timescale/security/transit-gateway.md @@ -15,7 +15,7 @@ import NotSupportedAzure from "versionContent/_partials/_not-supported-for-azure # Securely connect to $CLOUD_LONG using AWS Transit Gateway -[AWS Transit Gateway][aws-transit-gateway] enables you to securely connect to your $CLOUD_LONG from AWS, Google Cloud, Microsoft Azure, or any other cloud or on-premise environment. +[AWS Transit Gateway][aws-transit-gateway] enables you to securely connect to your **$CLOUD_LONG on AWS** from Google Cloud, Microsoft Azure, AWS, or any other cloud or on-premise environment. @@ -48,6 +48,12 @@ AWS Transit Gateway enables you to connect from almost any environment, this pag + + +These steps describe connecting **$CLOUD_LONG on AWS** to Microsoft Azure using AWS Transit Gateway. To connect **$CLOUD_LONG on Azure**, follow the steps in [Azure Private Link][azure-private-link]. + + + 1. **Connect your infrastructure to AWS Transit Gateway** @@ -92,6 +98,7 @@ AWS Transit Gateway enables you to connect from almost any environment, this pag You can now securely access your $SERVICE_SHORTs in $CLOUD_LONG. +[azure-private-link]: /use-timescale/:currentVersion:/security/azure-privatelink/ [aws-onprem]: https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/centralize-network-connectivity-using-aws-transit-gateway.html [aws-transit-gateway]: https://aws.amazon.com/transit-gateway/ [azure-aws]: https://aws.amazon.com/blogs/modernizing-with-aws/designing-private-network-connectivity-aws-azure/