Microsoft Azure
tsdevstack on Azure uses Container Apps for backend services, App Service for Kong and Next.js, PostgreSQL Flexible Server for databases, and Azure Managed Redis. Azure Front Door provides a unified edge service combining CDN, WAF, SSL, and load balancing in one.
Azure has the simplest architecture overall (~25-30 Terraform resources vs AWS's ~45). Front Door replaces three separate AWS services (CloudFront + ALB + ACM) with one unified service. There are two security tiers: Standard and Premium (adding Private Link origins and managed WAF rulesets).
Cost
tsdevstack is free and open source — there are no license fees. You only pay Microsoft directly for the cloud resources. See Azure Cost Estimation for a full breakdown by scenario.
Key Characteristics
- Compute: Container Apps (ILB) for backends, App Service for Kong + Next.js
- Data: PostgreSQL Flexible Server + Azure Managed Redis
- Edge: Front Door (unified CDN + WAF + SSL + LB)
- Scale-to-zero: Container Apps KEDA HTTP scaling (automatic, 2-5s cold start)
- Networking: VNet with ILB-enabled Container Apps Environment
- Secrets: Key Vault with RBAC mode + Managed Identity (zero-credential runtime)
Standard vs Premium Tier
Getting Started
- Account Setup — Create App Registration and configure credentials
- Architecture — Understand what gets deployed
- Cost Estimation — What you'll pay Microsoft (development, production, scaled)
- DNS & Domains — Configure Azure DNS and custom domains
- CI/CD — Set up OIDC federation for GitHub Actions