Search
Explore digital transformation resources.
Uncover insights, best practises and case studies.
Search
Explore digital transformation resources.
Uncover insights, best practises and case studies.
Azure Front Door serves as an entry point for web applications, providing load balancing, routing, and security features. It's designed to be powerful and flexible, but that doesn't mean you need a separate instance for every application.
DevOps Team Lead
Nortal-built DevOps Team
This fragmented approach created several significant challenges:
"If you want to update the certificate, you need to update this on every single Azure Front Door instance which is using it. This makes it a very tedious and time-consuming process." notes our DevOps Team Lead.
Each Front Door instance is approximately $300 per month in base fees for Premium SKU, while Classic SKU (about $150/month) and Standard SKU (around $50/month) are less expensive. With approximately 80% of their instances using Classic SKU multiplied by 150+ instances, these costs still added significantly. Regardless of traffic volume, these cumulative base fees created death by a thousand cuts for the IT budget.
Microsoft was deprecating the older classic SKU of Azure Front Door, meaning migration would eventually be necessary anyway.
With so many instances deployed by different teams at different times, security settings, routing rules, and other configurations varied widely, creating potential vulnerabilities and management complexity.
Before jumping into such a significant architectural change, the team needed buy-in from stakeholders across the organization. They constructed a clear business case highlighting:
DevOps Team Lead
Nortal-built DevOps Team
Rather than attempting to migrate all 150+ instances at once – a recipe for disaster – the team adopted a methodical approach:
They established just two Front Door instances for each major environment:
"We scoped custom domains and Azure Front Doors which were under our business unit responsibility," explains the Team Lead. "We have all the access, all the permissions, and that was quick and easy."
The team wisely started with non-production environments to identify and resolve issues before touching production systems.
Each migration was carefully documented, including any challenges encountered, creating a knowledge base for subsequent migrations.
Manual migration of 150+ instances would be both tedious and error-prone. Instead, the team built a robust automation framework:
During migration, the team applied:
With hundreds of domains and services relying on Front Door, even a minor misconfiguration could cause significant disruption. The team implemented several risk mitigation strategies:
DevOps Team Lead
Nortal-built DevOps Team
When dealing with critical infrastructure changes, especially those that impact dozens of teams and hundreds of services, having a solid risk mitigation plan is non-negotiable. Below, we break down the most critical risks, the strategies used to manage them, and the impact those precautions had.
| Risk | Mitigation strategy | Impact achieved |
|---|
| Downtime during migrations | Extensive pre-migration testing, rollback scripts | Near-zero downtime |
| Misconfigurations discovered post-migration | Automated validation tests, emergency rollback plan | Rapid identification & fix |
| Certificate expiration | Unified managed TLS certificates | Eliminated downtime risks |
| Poor stakeholder communication | Pre-scheduled communication & feedback loops | Smooth stakeholder buy-in |
Within a remarkably short timeframe, the team successfully consolidated over 150 Azure Front Door instances down to just 10, with impressive outcomes:
Non-production environments (dev & test) were migrated in just two weeks, with approximately 100 custom domains spanning 20-30 products moved to the new consolidated architecture. Their business unit's production environment was then migrated in the following three weeks, with remarkably little disruption.
The complete migration of all non-production environments (dev, test, and pre-prod) across all business units took approximately three months, demonstrating the importance of a phased, methodical approach to large-scale architectural changes.
DevOps Team Lead
Nortal-built DevOps Team
Whether you're dealing with Azure Front Door specifically or any other proliferation of cloud services, the principles from this successful consolidation can guide your approach:
Start with a thorough inventory
Understanding exactly what you have is essential before planning any consolidation.
Automate wherever possible
Scripting and automation not only save time but also significantly reduce human error. The team created export and import scripts to streamline the migration process and ensure consistency.
Test in non-production first
The team wisely started with non-production environments to identify and resolve issues before touching production systems.
Communicate relentlessly
"We sent communications to the product, custom domain owners, and service owners in advance – one month, two weeks, one week," explains the Team Lead. This proactive approach ensured all stakeholders were prepared for the changes.
Document edge cases
Unique configurations and special requirements will emerge – document them thoroughly to prevent future issues.
Create a feedback loop
"Every edge case or issue was analyzed and action items created to avoid having such in the future," the DevOps Team Lead notes – a practice that led to continuous improvement throughout the project.
Cloud architecture simplification projects like this one demonstrate that technical debt can be systematically addressed with the right approach. By reducing complexity, standardizing configurations, and improving manageability, organizations can achieve both cost savings and operational benefits.
If your cloud infrastructure has grown organically over time, it may be worth examining opportunities for similar consolidation. The initial investment in planning and implementation can pay significant dividends in reduced costs and simplified operations going forward.
Before launching a large-scale project like Front Door consolidation, it's critical to ensure your organization is set up for success. The checklist below highlights the foundational elements you should have in place, from stakeholder buy-in to automation tooling.
| Readiness criteria | Why it matters |
|---|---|
| Inventory of existing Front Door instances | Knowing what you have is essential for planning consolidation |
| Stakeholder alignment across business units | Ensures smooth migration and prevents silos from resisting |
| Automation capability for export/import | Minimizes manual errors and speeds up rollout |
| CI/CD pipelines for deployment | Enables repeatable, scalable migration processes |
| Security baseline defined | Prevents introducing vulnerabilities during migration |
| Budget for short-term migration work | Even with long-term savings, initial work may need resources |
| Change management process | Necessary to avoid downtime and maintain trust |
Whether you're managing a handful of Azure resources or overseeing enterprise-scale cloud architecture, the consolidation principles demonstrated in this project can help you identify sprawl and implement effective streamlining. And if your organization needs expert assistance tackling your complex cloud infrastructure, Nortal-built DevOps teams can achieve similar results.
Looking for more insights on cloud optimization? Check this article detailing how the same team saved $1M in Azure costs through targeted resource optimization. Stay tuned!
While you wait for our next article, our DevOps specialists are ready to bring order to your fragmented infrastructure. Do you really need 150+ Azure services when 10 would suffice? Is your cloud environment so complex that it makes the Azure portal look like a maze?
We specialize in building engineering teams who look at your architectural spaghetti and think, "Finally, a worthy challenge!" Where others see an insurmountable mess of technical debt, our teams see a satisfying before-and-after story waiting to happen. Let's tame your Azure chaos together!
Nortal is a strategic innovation and technology company with an unparalleled track-record of delivering successful transformation projects over 20 years.