> For the complete documentation index, see [llms.txt](https://docs.e6data.com/query-engine/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.e6data.com/query-engine/guides/deployment/azure-serverless/architecture.md).

# Architecture

How a Serverless e6data deployment on Azure works - managed compute in e6data's subscription, your ADLS Gen2 data read keylessly via Workload Identity.

In a **Serverless** deployment on Azure, e6data runs and manages the compute. You grant e6data read-only, keyless access to your data; everything else is handled by the platform.

![Azure Serverless deployment architecture](https://256648299-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2Fz2BYVXehgdnk8dbeZoW5%2Fuploads%2Fgit-blob-a6e8b960a49df3b93364dc81e5978e2c8d521c2d%2FAzure%20Serverless%20PLT-V2.png?alt=media)

## Where things run

Compute runs in the **e6data-managed Azure subscription** (AKS across three availability zones). A public load balancer fronts ingress (HTTPS / gRPC, with SSO and JWT), and engine egress leaves through a NAT gateway. Your **ADLS Gen2** storage is reached **read-only** via Workload Identity / OIDC federation - no keys are stored. The platform syncs releases and status with the Control Plane at `app.e6.run`.

## Where your data lives

Your data stays in **your Azure account**. e6data does not copy or move it - the engine reads directly from your ADLS Gen2 storage using a federated identity you grant, with only the **Storage Blob Data Reader** role. You can revoke access at any time by removing the role assignment.

## The two planes

| Plane         | What it does in a Serverless deployment                                                                                                        |
| ------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- |
| Control Plane | The shared e6data Console where you manage your organization, workspaces, account, and billing.                                                |
| Compute Plane | The per-workspace environment (opened with **Open**) where you manage catalogs and clusters and run queries. The compute is managed by e6data. |

## See also

* [Configure Azure access](/query-engine/guides/deployment/azure-serverless/configure-azure-access.md)
* [Deployment models](/query-engine/get-started/deployment-models.md)
* [FAQs](/query-engine/guides/deployment/azure-serverless/faqs.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.e6data.com/query-engine/guides/deployment/azure-serverless/architecture.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
