Hydra 2.8.0 Hydra 2.7.0 Hydra 2.6.0 Hydra 2.5.0 Hydra 2.4.0
Auto Light Dark
Auto Light Dark
Hydra 2.8.0 Hydra 2.7.0 Hydra 2.6.0 Hydra 2.5.0 Hydra 2.4.0

Network Architecture

Overview

Hydra’s network architecture is designed to be secure, modular, and cloud-native, with support for both public and private access models. All core services can run within a dedicated Azure Resource Group and communicate over secure Azure networking channels by using private endpoints configured by the customer.

The platform is composed of the following key components:

  • Hydra App Service: The central logic layer handling API requests, automation workflows, and tenant operations.

  • SQL Server + Database: Stores configuration data, tenant metadata, and operational state.

  • Log Analytics Workspace: Collects telemetry for diagnostics, health monitoring, and platform insights.

  • Key Vault: Stores application secrets and a cryptographical key.

Connectivity and Flow

  • The Hydra App Service communicates outbound with:

  • Hydra App Service receives communication inbound with:

    • Users and Admins using the HTTPS web service

    • Hydra Agent using 443-based WebSockets (must be enabled). For more information, see the Microsoft Documentation.

Networking Models

Hydra supports two deployment options:

  1. Public Access (Default)

  • App Service and database are reachable via Azure public endpoints.

  • Simpler to deploy and manage.

  • Secured using Entra, HTTPS, and optional network-level firewall rules.

  1. Private Networking (Recommended for Production)

  • Hydra services are integrated with Azure Private Endpoints, allowing access only from within a private VNet.

  • Enhances security by eliminating public exposure of App Service, Key Vault, and SQL endpoints.

  • Ideal for enterprise environments with strict egress and segmentation requirements.

  • For a video on how to configure the various components with Private Endpoints, see Securing an App Service, a Key Vault, and a Database with Private Endpoints.