> For the complete documentation index, see [llms.txt](https://docs.e6data.com/query-engine/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.e6data.com/query-engine/guides/deployment/azure-in-vpc/architecture.md).

# Architecture

How an In-VPC (CloudPrem) e6data deployment on Azure runs inside your own VNet on AKS, with engine pods on your node pools and data in your subscription.

An In-VPC deployment runs the entire e6data Compute Plane inside your own Azure VNet on AKS. Compute and data stay in your subscription; the e6data Control Plane handles only admin operations.

![Azure In-VPC deployment architecture](https://256648299-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fz2BYVXehgdnk8dbeZoW5%2Fuploads%2Fgit-blob-7c5ae052319a060d0ca65b99c86702b03928eed3%2FAzure%20IN-VPC%20PLT-V2.png?alt=media)

## Key design points

* **Your data stays in your subscription.** All access to ADLS and your catalog happens through a Managed Identity within your environment - no keys are stored in the cluster.
* **Engine pods run on your node pools.** Any provisioner is supported - static node pools, AKS Node Auto-Provisioning (NAP), or self-hosted Karpenter for scale-to-zero.
* **Azure CNI overlay with Cilium.** Pods get IPs from a virtual pod CIDR, so node pools scale without exhausting subnet IPs.
* **Workload Identity, no stored credentials.** AKS service accounts are federated to an Azure Managed Identity.
* **Public endpoint by default, protected by JWT.** The workspace query endpoint is exposed through an L4 Azure Load Balancer with a public IP; Envoy enforces JWT auth on every request. You can make the endpoint private (internal load balancer) so it is reachable only inside your VNet - see the QueryRouter step in [Deploy workspace and e6data](/query-engine/guides/deployment/azure-in-vpc/deploy-workspace-and-e6data.md).
* **Automatic provisioning.** The e6data operator provisions the workspace's metadata services automatically once the NamespaceConfig is applied.

## What the Control Plane does

The e6data Control Plane (hosted by e6data) handles workspace management, access control, releases, and observability, communicating with your cluster over HTTPS on port 443. Your data stays within your subscription.

## Components

The deployment installs cluster-wide platform components (the e6data operator, cert-manager, and Karpenter) once per cluster, and per-workspace components (console, query routing, and a metadata compaction job). These are enumerated in [Component versions and operations](/query-engine/guides/deployment/azure-in-vpc/component-versions-and-operations.md).

## See also

* [Prerequisites](/query-engine/guides/deployment/azure-in-vpc/prerequisites.md)
* [Configure registry, Kubernetes, and networking](/query-engine/guides/deployment/azure-in-vpc/configure-registry-kubernetes-networking.md)
* [Deployment models](/query-engine/get-started/deployment-models.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.e6data.com/query-engine/guides/deployment/azure-in-vpc/architecture.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
