Cloud services

About

A fictional company, a real platform

The brand, the boardroom, and the customer quotes are invented. The Azure stack exists, and this repository is configured to publish through it. We do not claim that a local revision is live until its public response matches the staged body.

Colleagues at a whiteboard mapping a simple publish path

We operate one region’s object storage and one global edge profile for many named sites. Account teams do not design a content delivery network; authors never receive storage keys. The catalog is small on purpose, because every option we offer is an option we have to keep correct for everyone.

We are built to sit beside an organization that already has identity and DNS operators. We do not take over your registrar, and we do not hand out a blank cloud subscription. What we ask for is a pipeline we can see, two secrets on the site repository, and permission to be opinionated about cache.

What “demo site” means here

This is a proof of concept advertising itself. The company chrome is generic so the engineering can be specific: cloud service names, protocol behavior, cache semantics, and identity constraints on this site are accurate, including the parts that are inconvenient. Where something is intended rather than already running, the blog says so.

The reviews are clearly labeled as hypothetical, and the warm company scenes and miniature platform worlds are generated for this demonstration. The numbers in the marketing panels—one repository per production hostname, two tenant secrets, thirty-day asset caching, and a hundred path expressions per Front Door purge request—are the active library contract. Deleting old fingerprinted blobs after a two-week lifecycle threshold remains a planned storage-cost feature rather than an active job.

Things we would rather disclose than bury

Neighbors share the storage account and the edge profile. Tenant blob modifications are prefix-scoped, but read/list and container operations still require a narrower custom role in the planned rebuild. The static website endpoint is publicly reachable, so prefix obscurity is not a security boundary. There is no web application firewall at this tier. Purge permission cannot be narrowed to one hostname by access control, which is precisely why tenants do not hold it.

Where to go next

Our principles if you want the reasoning. The tour if you want pictures. The blog if you want the mechanisms, one post per topic. The reviews if you want to imagine using it.