Cloud & Infrastructure Architecture Glossary
A single reference for the terms introduced across this section — link here instead of re-deriving a definition from an earlier page.
| Term | Meaning | Defined in |
|---|---|---|
| IaaS | Rent raw compute/storage/network, manage the OS and above yourself | Cloud Service & Deployment Models |
| PaaS | Rent a managed platform; provider manages OS/runtime | Cloud Service & Deployment Models |
| SaaS | Rent the entire finished application | Cloud Service & Deployment Models |
| Hybrid cloud | A mix of on-premises and public cloud, connected together | Cloud Service & Deployment Models |
| Multi-cloud | Using more than one public cloud provider | Cloud Service & Deployment Models |
| Management group | Container for grouping subscriptions to apply policy/RBAC at scale | Landing Zone Design |
| Subscription | Billing and access boundary within a cloud tenant | Landing Zone Design |
| Policy | An enforced rule (region, tags, SKU, etc.) applied across a scope | Landing Zone Design |
| Blast radius | The scope of impact if a resource or subscription is compromised | Landing Zone Design |
| Cloud Adoption Framework (CAF) | Microsoft’s reference methodology defining landing zones and cloud adoption practice | Landing Zone Design |
| VNet / VPC | Isolated virtual network within a cloud account | Network Architecture & Connectivity |
| Hub-and-spoke | Topology centralizing shared services in a hub, workloads in spokes | Network Architecture & Connectivity |
| NSG | Network security group — layer 3/4 allow/deny rules on a subnet or NIC | Network Architecture & Connectivity |
| Private endpoint | A private IP for a PaaS service, removing public exposure | Network Architecture & Connectivity |
| Container | A packaged, portable unit of an app and its dependencies | Compute & Container Platforms |
| Kubernetes | An orchestration platform for scheduling, scaling, and healing containers | Compute & Container Platforms |
| Serverless / FaaS | Event-triggered compute with no server management, billed per execution | Compute & Container Platforms |
| Cold start | Latency incurred when serverless infrastructure spins up an idle function | Compute & Container Platforms |
| IaC | Defining infrastructure in version-controlled, machine-readable files | Infrastructure as Code & Provisioning |
| Drift | When actual infrastructure no longer matches the code that should define it | Infrastructure as Code & Provisioning |
| State file | Terraform’s record of what it believes is currently deployed | Infrastructure as Code & Provisioning |
| Autoscaling | Automatically adding/removing capacity based on demand | Capacity & Scalability Planning |
| Quota | A subscription/region-level cap on how many resources can be provisioned | Capacity & Scalability Planning |
| Load balancer | Distributes incoming traffic across a pool of instances | Capacity & Scalability Planning |
| Saturation | How “full” a resource is relative to its capacity | Infrastructure Observability & Monitoring |
| Golden signals | Latency, traffic, errors, saturation — the four core signal categories | Infrastructure Observability & Monitoring |
| Health probe | An automated check of whether an instance/node is healthy | Infrastructure Observability & Monitoring |
| Well-Architected Framework | The cloud provider pillars (e.g. Performance Efficiency, Cost Optimization, Reliability) this section’s guidance maps to | Capacity & Scalability Planning |
| RTO | Recovery Time Objective — target time to restore service after an outage | Business Continuity & Disaster Recovery |
| RPO | Recovery Point Objective — maximum acceptable data loss, measured in time | Business Continuity & Disaster Recovery |
| Active-active / Active-passive | Both regions serving traffic simultaneously vs. secondary on standby | Business Continuity & Disaster Recovery |
| DR drill | A scheduled, real exercise of the failover process | Business Continuity & Disaster Recovery |
| Pilot Light / Warm Standby | Well-Architected’s two named active-passive DR strategies, between Backup & Restore and Multi-Site Active/Active | Business Continuity & Disaster Recovery |
| Bicep | Azure-native declarative IaC language, compiles to ARM templates | Infrastructure as Code & Provisioning |
| Scale-out / Scale-up | Adding more instances vs. moving to a bigger SKU/tier | Capacity & Scalability Planning |
| Failover group | Azure SQL construct automating failover of read-write/read-only endpoints to a paired secondary | Business Continuity & Disaster Recovery |
| Paired region | Azure’s predefined region pairing with sequenced updates and physical isolation | Business Continuity & Disaster Recovery |
| Application Insights | Azure Monitor’s application performance monitoring (APM) service | Infrastructure Observability & Monitoring |
| KQL | Kusto Query Language, used to query Log Analytics/Application Insights telemetry | Infrastructure Observability & Monitoring |
Related pages
Section titled “Related pages”Part of Introduction to Cloud & Infrastructure Architecture.