diff --git a/_partials/_azure-features.md b/_partials/_azure-features.md
index 5023a4b8eb..1c8fcc239e 100644
--- a/_partials/_azure-features.md
+++ b/_partials/_azure-features.md
@@ -6,52 +6,53 @@ The available $PRICING_PLANs are:
The features included in each [$PRICING_PLAN][pricing-plans] are:
-| Feature | $PERFORMANCE | $SCALE | $ENTERPRISE |
-|---------------------------------------------------------------|----------------------------------------|------------------------------------------------|--------------------------------------------------|
-| **Compute and storage** | | | |
-| Number of $SERVICE_SHORTs | Up to 2 free and 4 standard services | Up to 2 free and and unlimited standard services | Up to 2 free and and unlimited standard services |
-| CPU limit per $SERVICE_SHORT | Up to 8 CPU | Up to 32 CPU | Up to 64 CPU |
-| Memory limit per $SERVICE_SHORT | Up to 32 GB | Up to 128 GB | Up to 256 GB |
-| Storage limit per $SERVICE_SHORT | Up to 16 TB | Up to 16 TB | Up to 16 TB |
-| Bottomless blob storage | | Unlimited | Unlimited |
-| Independently scale compute and storage | Standard services only | Standard services only | Standard services only |
-| **Data services and workloads** | | | |
-| Relational | ✓ | ✓ | ✓ |
-| Time-series | ✓ | ✓ | ✓ |
-| Vector search | ✓ | ✓ | ✓ |
-| AI workflows (coming soon) | ✓ | ✓ | ✓ |
-| Cloud SQL editor | 3 seats | 10 seats | 20 seats |
-| Charts | ✓ | ✓ | ✓ |
-| Dashboards | 2 | Unlimited | Unlimited |
-| **Storage and performance** | | | |
-| IOPS | 3,000 - 5,000 | 5,000 - 8,000 | 5,000 - 8,000 |
-| Bandwidth (autoscales) | 125 - 250 Mbps | 250 - 500 Mbps | Up to 500 mbps |
-| I/O boost | | Add-on:
Up to 16K IOPS, 1000 Mbps BW | Add-on:
Up to 16K IOPS, 1000 Mbps BW |
-| **Availability and monitoring** | | | |
-| High-availability replicas
(Automated multi-AZ failover) | ✓ | ✓ | ✓ |
-| Read replicas | | ✓ | ✓ |
-| Backup reports | | 14 days | 14 days |
-| Point-in-time recovery and forking | 3 days | 14 days | 14 days |
-| Performance insights | ✓ | ✓ | ✓ |
-| Metrics and log exporters | | ✓ | ✓ |
-| **Security and compliance** | | | |
-| Role-based access | ✓ | ✓ | ✓ |
-| End-to-end encryption | ✓ | ✓ | ✓ |
-| [HIPAA compliance][hipaa-compliance] | | | ✓ |
+| Feature | $PERFORMANCE | $SCALE | $ENTERPRISE |
+|---------------------------------------------------------------|----------------------------------------|----------------------------------------------|--------------------------------------------------|
+| **Compute and storage** | | | |
+| Number of $SERVICE_SHORTs | Up to 2 free and 4 standard services | Up to 2 free and and unlimited standard services | Up to 2 free and and unlimited standard services |
+| CPU limit per $SERVICE_SHORT | Up to 8 CPU | Up to 32 CPU | Up to 64 CPU |
+| Memory limit per $SERVICE_SHORT | Up to 32 GB | Up to 128 GB | Up to 256 GB |
+| Storage limit per $SERVICE_SHORT | Up to 16 TB | Up to 16 TB | Up to 16 TB |
+| Bottomless blob storage | | Unlimited | Unlimited |
+| Independently scale compute and storage | Standard services only | Standard services only | Standard services only |
+| **Data services and workloads** | | | |
+| Relational | ✓ | ✓ | ✓ |
+| Time-series | ✓ | ✓ | ✓ |
+| Vector search | ✓ | ✓ | ✓ |
+| AI workflows (coming soon) | ✓ | ✓ | ✓ |
+| Cloud SQL editor | 3 seats | 10 seats | 20 seats |
+| Charts | ✓ | ✓ | ✓ |
+| Dashboards | 2 | Unlimited | Unlimited |
+| **Storage and performance** | | | |
+| IOPS | 3,000 - 5,000 | 5,000 - 8,000 | 5,000 - 8,000 |
+| Bandwidth (autoscales) | 125 - 250 Mbps | 250 - 500 Mbps | Up to 500 mbps |
+| I/O boost | | Add-on:
Up to 16K IOPS, 1000 Mbps BW | Add-on:
Up to 16K IOPS, 1000 Mbps BW |
+| **Availability and monitoring** | | | |
+| High-availability replicas
(Automated multi-AZ failover) | ✓ | ✓ | ✓ |
+| Read replicas | | ✓ | ✓ |
+| Backup reports | | 14 days | 14 days |
+| Point-in-time recovery and forking | 3 days | 14 days | 14 days |
+| Performance insights | ✓ | ✓ | ✓ |
+| Metrics and log exporters | | ✓ | ✓ |
+| **Security and compliance** | | | |
+| Role-based access | ✓ | ✓ | ✓ |
+| Azure Private Link | ✓ |✓|✓|
+| End-to-end encryption | ✓ | ✓ | ✓ |
+| [HIPAA compliance][hipaa-compliance] | | | ✓ |
| IP address allow list | 1 list with up to 10 IP addresses | Up to 10 lists with up to 10 IP addresses each | Up to 10 lists with up to 100 IP addresses each |
-| Multi-factor authentication | ✓ | ✓ | ✓ |
-| Federated authentication (SAML) | | | ✓ |
-| SOC 2 Type 2 report | | ✓ | ✓ |
-| Penetration testing report | | | ✓ |
-| Security questionnaire and review | | | ✓ |
-| Pay by invoice | Available at minimum spend | Available at minimum spend | ✓ |
-| [Uptime SLAs][commercial-sla] | Standard | Standard | Enterprise |
-| **Support and technical services** | | | |
-| Community support | ✓ | ✓ | ✓ |
-| Email support | ✓ | ✓ | ✓ |
-| Production support | Add-on | Add-on | ✓ |
-| Named account manager | | | ✓ |
-| JOIN services (Jumpstart Onboarding and INtegration) | | Available at minimum spend | ✓ |
+| Multi-factor authentication | ✓ | ✓ | ✓ |
+| Federated authentication (SAML) | | | ✓ |
+| SOC 2 Type 2 report | | ✓ | ✓ |
+| Penetration testing report | | | ✓ |
+| Security questionnaire and review | | | ✓ |
+| Pay by invoice | Available at minimum spend | Available at minimum spend | ✓ |
+| [Uptime SLAs][commercial-sla] | Standard | Standard | Enterprise |
+| **Support and technical services** | | | |
+| Community support | ✓ | ✓ | ✓ |
+| Email support | ✓ | ✓ | ✓ |
+| Production support | Add-on | Add-on | ✓ |
+| Named account manager | | | ✓ |
+| JOIN services (Jumpstart Onboarding and INtegration) | | Available at minimum spend | ✓ |
For a personalized quote, [get in touch with $COMPANY][contact-company].
diff --git a/_partials/_azure-privatelink.md b/_partials/_azure-privatelink.md
new file mode 100644
index 0000000000..d7dc1231da
--- /dev/null
+++ b/_partials/_azure-privatelink.md
@@ -0,0 +1,95 @@
+import IntegrationPrereqsNoConnection from "versionContent/_partials/_prereqs-cloud-no-connection.mdx";
+
+## Prerequisites
+
+
+
+* Create an [Azure account](https://azure.microsoft.com/en-gb/pricing/purchase-options/azure-account) with an active subscription.
+* Configure [permissions](https://learn.microsoft.com/en-us/azure/private-link/rbac-permissions) to create private endpoints and manage network resources.
+* Create an [Azure Virtual Network](https://learn.microsoft.com/en-us/azure/virtual-network/quickstart-create-virtual-network?tabs=portal) with a subnet for the resources you will connect to $CLOUD_LONG.
+
+## Set up Azure Private Link connection
+
+
+
+Azure Private Link is currently in private preview. To request access in $CONSOLE_LONG, go to `Security` > `Private Endpoints` and click `Request access`. Then refresh the page and follow the steps below.
+
+
+
+Take the following steps to connect $CLOUD_LONG to Azure with Private Link:
+
+
+
+1. **Create a Private Link subscription authorization**
+
+ 1. In [$CONSOLE_LONG][console-azure-privatelink], select `Security` > `Private Endpoints` > `Configure Private Endpoint Connection`.
+
+ 1. Enter your [Azure subscription ID](https://learn.microsoft.com/en-us/azure/azure-portal/get-subscription-tenant-id#find-your-azure-subscription) and specify a name for the Private Link authorization, then click a checkmark next to it.
+
+ ![Azure Private Link authorization][azure-privatelink-authorization]
+
+ 1. Under `Alias`, copy the alias for the region in which you need to create the connection.
+
+ Choose the region closest to your Azure resources for optimal performance.
+
+ 1. Click `Done`.
+
+ $CLOUD_LONG confirms your authorization. Once it is confirmed, you can create multiple private endpoints from the same authorized subscription.
+
+ ![Azure Private Link authorization complete][azure-privatelink-authorization-complete]
+
+1. **Create a private endpoint**
+
+ 1. In [Azure Portal](https://azure.microsoft.com/en-us/get-started/azure-portal), go to `Private endpoints` and click `Create`.
+
+ ![Create Azure Private Endpoint][create-azure-endpoint]
+
+ 1. Configure the endpoint:
+ 1. In `Subscription`, select the subscription you have previously authorized in $CLOUD_LONG.
+ 1. In `Resource group`, select an existing resource group or create a new one for your private endpoint.
+ 1. Provide a name for your endpoint.
+ 1. Select the region where your Virtual Network is deployed, then click `Next: Resource`.
+ 1. In `Connection method`, select `Connect to an Azure resource by resource ID or alias`.
+ 1. In `Resource ID or alias`, paste the alias you have copied from $CONSOLE_LONG.
+ 1. In `Request message`, enter your [$PROJECT_LONG ID][find-connection-details], then click `Next: Virtual Network`.
+ 1. Select the Virtual Network and subnet for your endpoint, optionally select an application security group, then click `Next: DNS`.
+ 1. Optionally configure private DNS integration and tags for your endpoint, then click `Next: Review + create`.
+ 1. Review your config and click `Create`.
+ Azure creates your private endpoint. Wait for the deployment to succeed.
+ 1. Go to `Private endpoints` and copy the private endpoint IP from the `Private IP` column.
+
+1. **Sync the connection**
+
+ 1. In [$CONSOLE_LONG][console-azure-privatelink] > `Security` > `Private Link`, click `Refresh`. $CLOUD_LONG automatically approves connections from authorized subscriptions. Your connection appears in the list.
+
+ ![Azure Private Endpoint IP][azure-private-endpoint-ip]
+
+ 1. Click `Add IP` and paste the IP address you have copied from Azure Portal.
+
+ 1. Click the three dots next to your connection and select `+ Attach service`. Select your $SERVICE_SHORT from the dropdown and click `Attach`. You can attach a $SERVICE_SHORT to one Private Endpoint connection.
+
+
+
+ After attaching a $SERVICE_SHORT to a Private Endpoint, it is no longer accessible from the public internet. Make sure all your applications are configured to connect through the Private Endpoint before attaching your $SERVICE_SHORT.
+
+
+
+ 1. From a VM inside your Azure VNet, connect to your $SERVICE_SHORT using a connection string with your [connection details][find-connection-details]. You should be able to connect successfully.
+
+
+
+
+## Manage connections
+
+- To detach a $SERVICE_SHORT from a Private Endpoint connection, go to `Security` > `Private Endpoints` and expand the details of the corresponding connection. Click the trash bin icon and confirm detaching your $SERVICE_SHORT.
+- To edit or remove a connection, click the three dots next to the connection in the list and select `Edit` or `Disconnect`, respectively. Detach $SERVICE_SHORTs from the connection before deleting it.
+- To remove an authorization, click `Manage Authorizations` > trash bin icon. Disconnect all relevant connections before removing an authorization.
+
+
+[console-azure-privatelink]: https://console.cloud.timescale.com/dashboard/azure-privatelink
+[find-connection-details]: /integrations/:currentVersion:/find-connection-details/
+[regions]: /about/:currentVersion:/supported-platforms/#available-regions
+[azure-privatelink-authorization]: https://assets.timescale.com/docs/images/tiger-cloud-console/configure-private-link-authorization.png
+[azure-privatelink-authorization-complete]: https://assets.timescale.com/docs/images/tiger-cloud-console/private-link-authorization-complete.png
+[azure-private-endpoint-ip]: https://assets.timescale.com/docs/images/tiger-cloud-console/private-link-add-ip.png
+[create-azure-endpoint]: https://assets.timescale.com/docs/images/tiger-cloud-console/create-private-endpoint-azure.png
\ No newline at end of file
diff --git a/_partials/_integration-prereqs-cloud-only.md b/_partials/_integration-prereqs-cloud-only.md
index ab90078704..2bacc07933 100644
--- a/_partials/_integration-prereqs-cloud-only.md
+++ b/_partials/_integration-prereqs-cloud-only.md
@@ -1,9 +1,7 @@
To follow the steps on this page:
-* Create a target [$SERVICE_LONG][create-service] with the Real-time analytics capability.
-
- You need your [connection details][connection-info].
+* Create a target [$SERVICE_LONG][create-service] with the Real-time analytics capability. You need your [connection details][connection-info].
[connection-info]: /integrations/:currentVersion:/find-connection-details/
[create-service]: /getting-started/:currentVersion:/services/
diff --git a/about/feature-comparison.md b/about/feature-comparison.md
index 4e198d771c..4a7e6a5e80 100644
--- a/about/feature-comparison.md
+++ b/about/feature-comparison.md
@@ -9,93 +9,94 @@ keywords: [TimescaleDB, Tiger Cloud]
The following table compares the features available in $CLOUD_LONG and self-hosted $TDB_COMMUNITY.
-| Feature | $CLOUD_LONG on AWS | $CLOUD_LONG on Azure | self-hosted $TIMESCALE_DB |
-|---------------------------------------------------------------------------------------------------------------|-----------------------------------|------------------------------------|---------------------------------------------|
-| **Best-in-сlass $PG performance** | | | |
-| Automatic partitioning via hypertables for efficient indexes and faster ingest | ✓ | ✓ | ✓ |
-| Continuous aggregates | ✓ | ✓ | ✓ |
-| Time/partition-oriented constraint exclusion for faster queries | ✓ | ✓ | ✓ |
-| Skip scans, ordered appends, custom optimizations for faster `LIMIT` and `DISTINCT` queries | ✓ | ✓ | ✓ |
-| Columnar storage for accelerated scans | ✓ | ✓ | ✓ |
-| Vectorized query execution (SIMD) | ✓ | ✓ | ✓ |
-| Specialized vector indexes for AI applications | ✓ | ✓ | ✓ |
-| $PG_CONNECTOR_CAP | ✓ | ✓ | Manual |
-| $S3_CONNECTOR_CAP | ✓ | ✗ | ✗ |
-| Source Apache Kafka connector | ✓ | ✗ | ✗ |
-| $LAKE_LONG destination connector from $CLOUD_LONG to Iceberg-backed S3 Tables | ✓ | ✗ | ✗ |
-| In-Console CSV, Parquet, and text file imports | ✓ | ✗ | ✗ |
-| **Flexible analysis with full SQL** | | | |
-| Complete $PG ecosystem including all $PG features, connectors, and third-party drivers | ✓ | ✓ | ✓ |
-| Cross-table JOINs for time-series and events tables with relational tables | ✓ | ✓ | ✓ |
-| Rich timestamp and timezone support | ✓ | ✓ | ✓ |
-| Flexible time-bucketing for time-oriented analysis | ✓ | ✓ | ✓ |
-| Advanced hyperfunctions including interpolation, approximation, and visualization functions | ✓ | ✓ | ✓ |
-| Geospatial and vector data types | ✓ | ✓ | ✓ |
-| **Automated data management** | | | |
-| Native compression (up to 98% storage savings) | ✓ | ✓ | ✓ |
-| Columnar storage format with fast scans | ✓ | ✓ | ✓ |
-| Data retention policies | ✓ | ✓ | ✓ |
-| Data tiering with automated policies | ✓ | ✓ | ✗ |
-| Data reordering for efficient disk scans | ✓ | ✓ | ✓ |
-| Data downsampling for efficient historical analysis | ✓ | ✓ | ✓ |
-| Background job scheduler and user-defined jobs | ✓ | ✓ | ✓ |
-| **Enterprise scalability** | | | |
-| Disaggregated compute and storage | ✓ | ✓ | Manual |
-| Dynamic compute resizing | ✓ | ✓ | ✗ |
-| Dynamic disk storage with usage-based pricing | ✓ | ✓ | ✗ |
-| Dynamic I/O provisioning for high-read/ high-write performance | ✓ | ✓ | Manual |
+| Feature | $CLOUD_LONG on AWS | $CLOUD_LONG on Azure | self-hosted $TIMESCALE_DB |
+|---------------------------------------------------------------------------------------------------------------|-----------------------------------|-------------------------------------|---------------------------------------------|
+| **Best-in-сlass $PG performance** | | | |
+| Automatic partitioning via hypertables for efficient indexes and faster ingest | ✓ | ✓ | ✓ |
+| Continuous aggregates | ✓ | ✓ | ✓ |
+| Time/partition-oriented constraint exclusion for faster queries | ✓ | ✓ | ✓ |
+| Skip scans, ordered appends, custom optimizations for faster `LIMIT` and `DISTINCT` queries | ✓ | ✓ | ✓ |
+| Columnar storage for accelerated scans | ✓ | ✓ | ✓ |
+| Vectorized query execution (SIMD) | ✓ | ✓ | ✓ |
+| Specialized vector indexes for AI applications | ✓ | ✓ | ✓ |
+| $PG_CONNECTOR_CAP | ✓ | ✓ | Manual |
+| $S3_CONNECTOR_CAP | ✓ | ✗ | ✗ |
+| Source Apache Kafka connector | ✓ | ✗ | ✗ |
+| $LAKE_LONG destination connector from $CLOUD_LONG to Iceberg-backed S3 Tables | ✓ | ✗ | ✗ |
+| In-Console CSV, Parquet, and text file imports | ✓ | ✗ | ✗ |
+| **Flexible analysis with full SQL** | | | |
+| Complete $PG ecosystem including all $PG features, connectors, and third-party drivers | ✓ | ✓ | ✓ |
+| Cross-table JOINs for time-series and events tables with relational tables | ✓ | ✓ | ✓ |
+| Rich timestamp and timezone support | ✓ | ✓ | ✓ |
+| Flexible time-bucketing for time-oriented analysis | ✓ | ✓ | ✓ |
+| Advanced hyperfunctions including interpolation, approximation, and visualization functions | ✓ | ✓ | ✓ |
+| Geospatial and vector data types | ✓ | ✓ | ✓ |
+| **Automated data management** | | | |
+| Native compression (up to 98% storage savings) | ✓ | ✓ | ✓ |
+| Columnar storage format with fast scans | ✓ | ✓ | ✓ |
+| Data retention policies | ✓ | ✓ | ✓ |
+| Data tiering with automated policies | ✓ | ✓ | ✗ |
+| Data reordering for efficient disk scans | ✓ | ✓ | ✓ |
+| Data downsampling for efficient historical analysis | ✓ | ✓ | ✓ |
+| Background job scheduler and user-defined jobs | ✓ | ✓ | ✓ |
+| **Enterprise scalability** | | | |
+| Disaggregated compute and storage | ✓ | ✓ | Manual |
+| Dynamic compute resizing | ✓ | ✓ | ✗ |
+| Dynamic disk storage with usage-based pricing | ✓ | ✓ | ✗ |
+| Dynamic I/O provisioning for high-read/ high-write performance | ✓ | ✓ | Manual |
| Low-cost storage with infinite capacity | ✓ | ✓ | ✗ |
-| Transparent queries across high-performance and low-cost tiers | ✓ | ✓ | ✗ |
-| Read replicas with load balancing for seamless read scaling | ✓ | ✓ | Manual |
-| Connection pooling for connection scaling | ✓ | ✓ | Manual |
-| Automated resource-aware parameter tuning | ✓ | ✓ | ✗ |
-| Terraform for infrastructure-as-code control | ✓ | ✓ | ✗ |
-| **High availability and reliability** | | | |
-| Multi-AZ deployments for high availability | ✓ | ✓ | Manual |
-| Continuous incremental backup and automated restore | ✓ | ✓ | Manual |
+| Transparent queries across high-performance and low-cost tiers | ✓ | ✓ | ✗ |
+| Read replicas with load balancing for seamless read scaling | ✓ | ✓ | Manual |
+| Connection pooling for connection scaling | ✓ | ✓ | Manual |
+| Automated resource-aware parameter tuning | ✓ | ✓ | ✗ |
+| Terraform for infrastructure-as-code control | ✓ | ✓ | ✗ |
+| **High availability and reliability** | | | |
+| Multi-AZ deployments for high availability | ✓ | ✓ | Manual |
+| Continuous incremental backup and automated restore | ✓ | ✓ | Manual |
| Cross-region backup | ✓ | 🔜 | ✗ |
-| Point-in-time recovery and branching | ✓ | ✓ | Manual |
-| Regular database and disk snapshots to enable fast restore | ✓ | ✓ | ✗ |
-| Rapid recovery for all services by fast database restart and remote disk remount | ✓ | ✓ | ✗ |
-| Memory guard protections to avoid database out-of-memory crashes | ✓ | ✓ | ✗ |
-| Decoupled control/data planes for greater resilience | ✓ | ✓ | ✗ |
-| Commercial SLAs | ✓ | ✓ | ✗ |
-| **Automated upgrades and software patching** | | | |
-| Automated upgrades during maintenance windows | ✓ | ✓ | ✗ |
-| Phased, zero-downtime $TIMESCALE_DB and $PG minor upgrades | ✓ | ✓ | ✗ |
-| $PG major version upgrades with forking workflow and disk snapshots to minimize downtime | ✓ | ✓ | ✗ |
-| HA-replica-aware coordinated upgrades | ✓ | ✓ | ✗ |
-| Fleet-wide version and stability monitoring with staged roll-out/roll-back upgrades | ✓ | ✓ | ✗ |
-| **Security and compliance** | | | |
-| SOC 2 Type 2, GDPR, HIPAA certified compliance | ✓ | ✓ | ✗ |
-| Data encryption at rest (both disk and backup) | ✓ | ✓ | Manual |
-| Data encryption in transit | ✓ | ✓ | Manual |
-| Database SSL with fully verifiable certificate chains | ✓ | ✓ | ✗ |
-| Control plane role-based access control | ✓ | ✓ | ✗ |
-| Database role-based access control | ✓ | ✓ | ✓ |
-| Multi-factor authentication | ✓ | ✓ | ✗ |
-| Corporate SSO and SAML | ✓ | ✓ | ✗ |
-| VPC peering | ✓ | ✗ | ✗ |
-| AWS Transit Gateway | ✓ | ✗ | ✗ |
-| Layered database "privilege escalation" protections | ✓ | ✓ | ✗ |
-| Secure SDLC practices and vulnerability scanning, third-party pen testing | ✓ | ✓ | ✗ |
-| **Deep observability** | | | |
-| Operational database visibility to understand performance, uncover regressions, optimize performance | ✓ | ✓ | ✗ |
-| Automated query analysis and statistics | ✓ | ✓ | ✗ |
-| Per-query drill-downs into execution times, row results, plans, memory buffer management, cache performance | ✓ | ✓ | ✗ |
-| In-Console metric visualization and system logs | ✓ | ✓ | ✗ |
-| AWS CloudWatch exporter | ✓ | ✗ | ✗ |
-| Prometheus exporter | ✓ | ✓ | ✗ |
-| Datadog exporter | ✓ | ✓ | ✗ |
-| Azure Monitor exporter | ✗ | ✓ | ✗ |
-| Connection monitoring | ✓ | ✓ | Manual |
-| Connection management | ✓ | ✓ | Manual |
-| **Production-grade support and operations** | | | |
-| 24/7 follow-the-sun support with global support team across APAC, EMEA, and Americas | ✓ | ✓ | [Contact sales][contact-sales] |
-| Production support (severity 1) | ✓ | ✓ | [Contact sales][contact-sales] |
-| Architectural reviews, data modeling, and query optimization and assistance, feature testing, and migration support | ✓ | ✓ | [Contact sales][contact-sales] |
-| 24/7 operational monitoring and control | ✓ | ✓ | [Contact sales][contact-sales] |
-| 98%+ customer satisfaction (CSAT scores) | ✓ | ✓ | [Contact sales][contact-sales] |
+| Point-in-time recovery and branching | ✓ | ✓ | Manual |
+| Regular database and disk snapshots to enable fast restore | ✓ | ✓ | ✗ |
+| Rapid recovery for all services by fast database restart and remote disk remount | ✓ | ✓ | ✗ |
+| Memory guard protections to avoid database out-of-memory crashes | ✓ | ✓ | ✗ |
+| Decoupled control/data planes for greater resilience | ✓ | ✓ | ✗ |
+| Commercial SLAs | ✓ | ✓ | ✗ |
+| **Automated upgrades and software patching** | | | |
+| Automated upgrades during maintenance windows | ✓ | ✓ | ✗ |
+| Phased, zero-downtime $TIMESCALE_DB and $PG minor upgrades | ✓ | ✓ | ✗ |
+| $PG major version upgrades with forking workflow and disk snapshots to minimize downtime | ✓ | ✓ | ✗ |
+| HA-replica-aware coordinated upgrades | ✓ | ✓ | ✗ |
+| Fleet-wide version and stability monitoring with staged roll-out/roll-back upgrades | ✓ | ✓ | ✗ |
+| **Security and compliance** | | | |
+| SOC 2 Type 2, GDPR, HIPAA certified compliance | ✓ | ✓ | ✗ |
+| Data encryption at rest (both disk and backup) | ✓ | ✓ | Manual |
+| Data encryption in transit | ✓ | ✓ | Manual |
+| Database SSL with fully verifiable certificate chains | ✓ | ✓ | ✗ |
+| Control plane role-based access control | ✓ | ✓ | ✗ |
+| Database role-based access control | ✓ | ✓ | ✓ |
+| Multi-factor authentication | ✓ | ✓ | ✗ |
+| Corporate SSO and SAML | ✓ | ✓ | ✗ |
+| VPC peering | ✓ | ✗ | ✗ |
+| AWS Transit Gateway | ✓ | ✗ | ✗ |
+| Azure Private Link | ✗ | ✓ | ✗ |
+| Layered database "privilege escalation" protections | ✓ | ✓ | ✗ |
+| Secure SDLC practices and vulnerability scanning, third-party pen testing | ✓ | ✓ | ✗ |
+| **Deep observability** | | | |
+| Operational database visibility to understand performance, uncover regressions, optimize performance | ✓ | ✓ | ✗ |
+| Automated query analysis and statistics | ✓ | ✓ | ✗ |
+| Per-query drill-downs into execution times, row results, plans, memory buffer management, cache performance | ✓ | ✓ | ✗ |
+| In-Console metric visualization and system logs | ✓ | ✓ | ✗ |
+| AWS CloudWatch exporter | ✓ | ✗ | ✗ |
+| Prometheus exporter | ✓ | ✓ | ✗ |
+| Datadog exporter | ✓ | ✓ | ✗ |
+| Azure Monitor exporter | ✗ | ✓ | ✗ |
+| Connection monitoring | ✓ | ✓ | Manual |
+| Connection management | ✓ | ✓ | Manual |
+| **Production-grade support and operations** | | | |
+| 24/7 follow-the-sun support with global support team across APAC, EMEA, and Americas | ✓ | ✓ | [Contact sales][contact-sales] |
+| Production support (severity 1) | ✓ | ✓ | [Contact sales][contact-sales] |
+| Architectural reviews, data modeling, and query optimization and assistance, feature testing, and migration support | ✓ | ✓ | [Contact sales][contact-sales] |
+| 24/7 operational monitoring and control | ✓ | ✓ | [Contact sales][contact-sales] |
+| 98%+ customer satisfaction (CSAT scores) | ✓ | ✓ | [Contact sales][contact-sales] |
[contact-sales]: mailto:sales@tigerdata.com
diff --git a/integrations/microsoft-azure.md b/integrations/microsoft-azure.md
index 9c05fb69ff..adcf1c25a9 100644
--- a/integrations/microsoft-azure.md
+++ b/integrations/microsoft-azure.md
@@ -8,39 +8,18 @@ keywords: [Azure, integrations]
import IntegrationPrereqsCloud from "versionContent/_partials/_integration-prereqs-cloud-only.mdx";
import TransitGateway from "versionContent/_partials/_transit-gateway.mdx";
-import NotSupportedAzure from "versionContent/_partials/_not-supported-for-azure.mdx";
+import AzurePrivateLink from "versionContent/_partials/_azure-privatelink.mdx";
+import NotSupportedAws from "versionContent/_partials/_not-supported-for-aws.mdx";
# Integrate Microsoft Azure with $CLOUD_LONG
-
[Microsoft Azure][azure] is a cloud computing platform and services suite, offering infrastructure, AI, analytics, security, and developer tools to help businesses build, deploy, and manage applications.
-This page explains how to integrate your Microsoft Azure infrastructure with $CLOUD_LONG using [AWS Transit Gateway][aws-transit-gateway].
-
-## Prerequisites
-
-
-
-- Set up [AWS Transit Gateway][gtw-setup].
-
-
-## Connect your Microsoft Azure infrastructure to your $SERVICE_LONGs
-
-To connect to $CLOUD_LONG:
-
-
-
-1. **Connect your infrastructure to AWS Transit Gateway**
-
- Establish connectivity between Azure and AWS. See the [AWS architectural documentation][azure-aws] for details.
-
-
+This page explains how to integrate your Microsoft Azure infrastructure with $CLOUD_LONG on Azure using [Azure Private Link][azure-private-link].
-
+
-You have successfully integrated your Microsoft Azure infrastructure with $CLOUD_LONG.
+
-[aws-transit-gateway]: https://aws.amazon.com/transit-gateway/
-[azure-aws]: https://aws.amazon.com/blogs/modernizing-with-aws/designing-private-network-connectivity-aws-azure/
+[azure-private-link]: https://learn.microsoft.com/en-us/azure/private-link/private-link-overview
[azure]: https://azure.microsoft.com/en-gb/
-[gtw-setup]: https://docs.aws.amazon.com/vpc/latest/tgw/tgw-getting-started.html
diff --git a/use-timescale/page-index/page-index.js b/use-timescale/page-index/page-index.js
index ba7ea97492..2760337ddd 100644
--- a/use-timescale/page-index/page-index.js
+++ b/use-timescale/page-index/page-index.js
@@ -699,6 +699,12 @@ module.exports = [
excerpt:
"Secure your Tiger Cloud services with VPC peering and AWS PrivateLink",
},
+ {
+ title: "Azure Private Link",
+ href: "azure-privatelink",
+ excerpt:
+ "Secure your Tiger Cloud services with Azure Private Link",
+ },
{
title: "IP allow list",
href: "ip-allow-list",
diff --git a/use-timescale/security/azure-privatelink.md b/use-timescale/security/azure-privatelink.md
new file mode 100644
index 0000000000..9a497396e0
--- /dev/null
+++ b/use-timescale/security/azure-privatelink.md
@@ -0,0 +1,24 @@
+---
+title: Azure Private Link
+excerpt: Azure Private Link ensures that your Tiger Cloud services are only accessible through your secured Azure infrastructure. Set up Private Link connections in Tiger Cloud Console
+products: [cloud]
+price_plans: [performance, scale, enterprise]
+keywords: [PrivateLink, Azure, private endpoint, services, operations, security]
+tags: [azure, security]
+cloud_ui:
+ path:
+ - [services, :serviceId, operations, azure-privatelink]
+---
+
+import AzurePrivateLink from "versionContent/_partials/_azure-privatelink.mdx";
+import NotSupportedAws from "versionContent/_partials/_not-supported-for-aws.mdx";
+
+# Secure your $CLOUD_LONG services with Azure Private Link
+
+Azure Private Link creates a private connection between your Azure Virtual Network and $SERVICE_LONGs hosted on Azure, eliminating exposure to the public internet. Applications in your Azure VNet connect to a Private Endpoint with a private IP address, which links to $CLOUD_LONG. Once connected, your $SERVICE_SHORTs become accessible only through the Private Endpoint, providing enhanced security, reduced attack surface, and compliance with data isolation requirements.
+
+
+
+
+
+[azure-privatelink-architecture]: https://assets.timescale.com/docs/images/tiger-cloud-console/azure-privatelink-architecture.svg
\ No newline at end of file
diff --git a/use-timescale/security/index.md b/use-timescale/security/index.md
index 13b4135c64..653e951b79 100644
--- a/use-timescale/security/index.md
+++ b/use-timescale/security/index.md
@@ -17,9 +17,11 @@ Learn how $CLOUD_LONG protects your data and privacy.
* Connect with a [stricter SSL mode][ssl-mode]
* Secure your $SERVICE_SHORTs with [VPC peering][vpc-peering]
* Connect to your $SERVICE_SHORTs from any cloud with [AWS Transit Gateway][transit-gateway]
+* Secure your $SERVICE_SHORTs with [Azure Private Link][azure-privatelink]
* Restrict access with an [IP address allow list][ip-allowlist]
[2fa]: /use-timescale/:currentVersion:/security/multi-factor-authentication/
+[azure-privatelink]: /use-timescale/:currentVersion:/security/azure-privatelink/
[client-credentials]: /use-timescale/:currentVersion:/security/client-credentials/
[database-rbac]: /use-timescale/:currentVersion:/security/read-only-role/
[ip-allowlist]: /use-timescale/:currentVersion:/security/ip-allow-list/
diff --git a/use-timescale/security/transit-gateway.md b/use-timescale/security/transit-gateway.md
index 90afc283b8..8e2256fe64 100644
--- a/use-timescale/security/transit-gateway.md
+++ b/use-timescale/security/transit-gateway.md
@@ -15,7 +15,7 @@ import NotSupportedAzure from "versionContent/_partials/_not-supported-for-azure
# Securely connect to $CLOUD_LONG using AWS Transit Gateway
-[AWS Transit Gateway][aws-transit-gateway] enables you to securely connect to your $CLOUD_LONG from AWS, Google Cloud, Microsoft Azure, or any other cloud or on-premise environment.
+[AWS Transit Gateway][aws-transit-gateway] enables you to securely connect to your **$CLOUD_LONG on AWS** from Google Cloud, Microsoft Azure, AWS, or any other cloud or on-premise environment.
@@ -48,6 +48,12 @@ AWS Transit Gateway enables you to connect from almost any environment, this pag
+
+
+These steps describe connecting **$CLOUD_LONG on AWS** to Microsoft Azure using AWS Transit Gateway. To connect **$CLOUD_LONG on Azure**, follow the steps in [Azure Private Link][azure-private-link].
+
+
+
1. **Connect your infrastructure to AWS Transit Gateway**
@@ -92,6 +98,7 @@ AWS Transit Gateway enables you to connect from almost any environment, this pag
You can now securely access your $SERVICE_SHORTs in $CLOUD_LONG.
+[azure-private-link]: /use-timescale/:currentVersion:/security/azure-privatelink/
[aws-onprem]: https://docs.aws.amazon.com/prescriptive-guidance/latest/patterns/centralize-network-connectivity-using-aws-transit-gateway.html
[aws-transit-gateway]: https://aws.amazon.com/transit-gateway/
[azure-aws]: https://aws.amazon.com/blogs/modernizing-with-aws/designing-private-network-connectivity-aws-azure/