Election application — Azure architecture on one page
Born Between 2 Generals LLC · for Luke and Mark · 27 August 2026
Controlled Not for distribution
3isolation tiers to provision
62regional vCPUs requested
11components, one source each
23days to the overseas ballot wall
The four things that block everything else
01
One dedicated subscription, named for the election application, in a US region with availability zones. Not shared with other workloads.
02
vCPU quota: 62 total regional — 42 in the Ddsv5 family, 20 in the DCadsv5 confidential family. Azure enforces quota regionally and per VM family, so both numbers must be requested or the confidential machines will not deploy.
03
Confirmation that DCadsv5 or ECadsv5 confidential VMs are available in that region. If they are not, the custody tier is redesigned — and we need to know now, not at deployment.
04
A written answer on intellectual-property separation between Born Between 2 Generals' code and the host organisation's data. Not a verbal assurance.
Three tiers, assigned by what a workload can touch
Tier
Azure service, and what runs there
Tier 3 Edge
Azure Container Apps behind Front Door with the web application firewall. Public verification portal, static assets, TLS, rate limiting. Holds no keys and has no route to the chain. Consumption-billed, so it draws no VM quota.
Tier 2 Processing
AKS with Pod Sandboxing — per-pod kernel isolation using Kata Containers. Event validation, poison checks, chain append, Merkle construction, read replicas. The correct default for anything that processes election data.
Tier 1 Custody
Confidential VM, DCadsv5 or ECadsv5 — AMD SEV-SNP with guest attestation — plus Key Vault Managed HSM. Signing, sealing, anchor publication, key rotation. No public IP. No inbound path from Tier 3. No interactive login, ever.
Production custody 2 × DC8ads_v5 (16) · staging custody 1 × DC4ads_v5 (4). Staging is required — an attestation gate that has never been tested is not a gate.
Data layer
Production
PostgreSQL Flexible Server, General Purpose D4ds_v5, 4 vCores / 16 GiB, zone-redundant standby, 35-day restore, 512 GiB. Private access only — no public endpoint at any point in its life.
Discipline
Append-only enforced by grant: the app role gets INSERT and SELECT; UPDATE and DELETE are never granted. Identity and ballot domains never share a server, credential or backup.
The workflow, eleven stages, local to live
1 Devcontainer, synthetic data2 Signed commit, short branch3 PR, required checks4 Build image once, sign, SBOM5 Scan gate6 Infrastructure as code7 Dev → test → prod8 Attestation gate9 Post-deploy verify or roll back10 Anchors, retention, rotation11 Release record
Promote by digest, never by tag — the artifact that ships is the artifact that was tested. Deployment authenticates by federated OpenID Connect, so no Azure secret is stored in GitHub. Every release emits one record: commit, digest, bill-of-materials hash, test counts, attestation measurements, approver, timestamp. That record is the reason the pipeline exists.
The one cost that will surprise you
Managed HSM · flat hourly, independent of use
A dedicated pool runs roughly $2,300–2,400 a month before transactions. Independent estimate; confirm in the portal.
Mitigation: Key Vault Premium — HSM-backed, billed per active key — for development and test. Dedicated pool only from the first real pilot. Identical code path.
The date that actually governs
19 September 2026 · overseas and military ballots
Twenty-three days, not the sixty-eight to Election Day. Anything meant to touch a real 2026 ballot lives inside that window.
Which is why mail-ballot custody goes first and verifiable voting does not: custody can be stood up and audited in twenty-three days, a cryptographic tally argument cannot.
Stated plainly, before anyone else finds it
Authorisation on the operations platform is client-side today, so it is advisory until a server enforces it. Supersession is a mutable flag the hash chain does not cover — half a day to fix, and it is first in the queue. Key setup assumes a trusted dealer and produces no ceremony record; that needs a written procedure more than it needs code. Two live hosts still serve without a crawler exclusion, one recoverable and one not. Nothing in this programme is certified, independently audited, or piloted, and no claim of the form "N of N complete" should be believed — including from us.
Born Between 2 Generals LLC
Companion to the election application brief and the full engineering specification. Azure quota enforcement, confidential VM capability and PostgreSQL tier limits were read from Microsoft's documentation on 27 August 2026; cost figures are independent estimates to be confirmed in the portal. Controlled — contains unregistered intellectual property and pre-filing subject matter.