Outpost
Overview
With the Outpost deployment model, Cloud Scanners are deployed and run inside your own Azure environment. Upwind provisions the scanner infrastructure (worker virtual machine scale sets, scaling components, a Key Vault, managed identities, and supporting custom roles) into the orchestrator subscription you designate, and the platform talks to those scanners through the role assignments created during onboarding.
Outpost is the long-established Upwind onboarding path and is the right fit for organizations that need scanner compute to stay inside their own tenancy. Upwind uses Terraform or Azure Resource Manager (ARM) templates to deploy all relevant roles so it can access your resources and connect to the Upwind backend. For the alternative model where Upwind hosts the scanner infrastructure, see the SaaS deployment model.
The full onboarding flow and its instructions are documented in the Azure instructions guide.
What's in This Section
- Architecture: covers the identities, role assignments, and scanner resources that make up the Outpost architecture, and what onboarding provisions in your environment.
- Prerequisites: lists the requirements that must be in place before starting the onboarding process.
- Onboarding Flow: step-by-step instructions for connecting your Azure environment to Upwind using the Outpost deployment model.
- Classic Onboarding: the earlier identity model, which creates an application registration and client secret in your own tenant.
- Migration: the path from an earlier Azure onboarding to the current onboarding experience.
- Troubleshooting: covers common issues that may occur during onboarding, with guidance on how to identify and resolve them.
- Offboarding: how to remove the Upwind identities and scanner resources from your environment.
Integration
The onboarding methods available for creating the necessary identities and role assignments for Upwind are:
Already an Upwind customer on an earlier Azure onboarding? See Migration for the path to the current onboarding experience.
Selecting Switch to classic onboarding in the first step of the flow leads to the earlier identity model, which creates an application registration and client secret in your own tenant. That flow is documented in Classic Onboarding.