Election application environment · 50 items in 8 groups · 27 August 2026
Controlled Not for distribution
How to read this. Group A blocks every other group — nothing else can start until those five items are done. Every item is stated so it can be actioned without a follow-up conversation: where a number or a setting is required, the number or setting is given. Items marked WRITTEN require a written answer rather than a configuration change.
A · Subscription and access — blocks everything else
✓
Item
Owner
Date
One dedicated Azure subscriptionNamed for the election application. Not shared with other workloads. This is the boundary that makes cost, access and audit answerable in one place.
Primary region named, US, with availability zonesElection material carries residency expectations that vary by jurisdiction. The region must be recorded, not assumed.
Contributor on the subscription for the build accountPlus User Access Administrator scoped to the resource groups, so managed identities can be assigned without a ticket per step. Owner is not required and should not be granted.
Access list documented, with a review cadenceWho holds administrator, owner and contributor, and how often that list is reviewed.
Three resource groups: development, test, productionSeparate identities, no shared data path. Production data never appears in the other two.
B · Compute and quota
✓
Item
Owner
Date
Regional vCPU quota raised to 62 in the primary regionAzure enforces quota at two levels — total regional and per VM family — so both of the next two items are required. A regional grant alone is not sufficient.
Confidential VM availability confirmed in regionDCadsv5 or ECadsv5 — the AMD SEV-SNP families. If unavailable in region, say so now: the custody tier design changes.
AKS Pod Sandboxing support status confirmedMicrosoft's documentation calls it preview; the Kata Containers project reports general availability. Tier 2 depends on it, so this needs resolving by someone with a support contract. Also confirm which node sizes support nested virtualisation in region.
Azure Container Apps environment for the public tierConsumption billing, scales to zero outside an election period, draws no VM quota.
C · Data and storage
✓
Item
Owner
Date
PostgreSQL Flexible Server, productionGeneral Purpose Standard_D4ds_v5, 4 vCores / 16 GiB, 512 GiB storage, zone-redundant high availability with the standby in a different zone.
Private access mode, delegated subnet, no public endpointNot at any point in the server's life, including initial setup. A database that was briefly public was public.
Private DNS zone created and linkedPlus the permission for the build account to link it.
Read replica, D2ds_v5, 2 vCoresFor analytics and disclosure-control queries. Nothing that computes a published figure touches the primary.
Test server, General Purpose D2ds_v5General Purpose rather than Burstable — Burstable throttling makes load results meaningless.
Point-in-time restore set to 35 daysThe maximum. Plus long-term retention where the statute requires it.
Customer-managed key for encryption at restDatabase and storage both, held with the custody keys.
Storage account per environment, immutable blob with time-based retentionFor sealed archives, anchor publications and release records. Legal hold available. Private endpoints only, infrastructure encryption on.
D · Keys and custody
✓
Item
Owner
Date
Managed HSM pool approved for production, with a budget lineFlat hourly fee independent of use — roughly $2,300–2,400 per month by independent estimate, to be confirmed in the portal. This is the largest recurring cost in the environment.
Key Vault Premium for development and test instead of a second poolHSM-backed, billed per actively used key. Identical application code path, so nothing is left untested except the pool boundary itself.
All signing keys created non-exportableCannot be retrofitted — a key created exportable is exportable for life.
Confidential OS disk encryption enabled at VM creation, customer-managed keyCannot be changed after deployment. Getting it wrong means rebuilding the machine.
HSM backup to a customer-controlled location, encryptedAnd the restore path documented.
E · Network
✓
Item
Owner
Date
Virtual network with four subnets: edge, processing, custody, dataPlus the right to define network security groups and route tables on them. Tier separation is enforced in the network, not in application code.
Deny rule: edge cannot reach custody or the databaseAn explicit deny, not an absent route.
Custody has no inbound path from edge or processingCustody pulls from a queue that processing writes to. The direction of the connection is the control.
Private endpoints for registry, key vault, storage and databaseNo service traffic on the public internet, including between Azure services.
Front Door with the web application firewall as the only public ingressOne door.
No public IP on any virtual machine; Azure Bastion for break-glassWith a recorded approval per use, never a standing SSH port.
Outbound egress controlled and logged"What is transmitted outside this environment, and who can read it" must have a documented answer. Default-open egress means it does not.
F · Pipeline and environments
✓
Item
Owner
Date
Azure Container Registry, Premium tierPremium is required for private endpoints and geo-replication. Standard does not support private endpoints.
Federated identity credential for GitHub Actions, one per environmentOpenID Connect workload identity federation. No service-principal password should ever be issued — the development credential must not be able to deploy to production.
Self-hosted runner capacity inside the network2 × D4ds_v5, ephemeral, destroyed and recreated per job. Needed so integration tests can reach private endpoints.
Production deployment approval gate, with a named approverRecorded per release.
Registry vulnerability scanning, with a policy that blocks on critical findingsPlus scheduled base-image rebuilds rather than rebuilds when someone remembers.
Infrastructure-as-code permissions, and agreement that nothing is created in the portalA resource created by hand is unreviewable and unreproducible, which in an election context is a finding waiting to be written up.
G · Operations, backup and recovery
✓
Item
Owner
Date
Log Analytics workspace per environment, retention matched to the statutory scheduleNot the platform default.
Microsoft Defender for Cloud enabled, container and database plans on
Azure Policy denying public IPs, public blob access and unencrypted storage
Alerts wired for the five failures that indicate a broken guaranteeA missed anchor publication · a chain continuity failure · a failed attestation · a retention clock that did not advance · an anonymity set below threshold. These matter more than CPU alerts.
Witnessed restore exercise before the first real record enters the systemThen quarterly. A backup that has never been restored is not a backup.
Recovery time and recovery point objectives written down and measured against the testMeasured, not estimated.
Rollback path exercised on a scheduleA rollback first attempted during an incident is a hope, not a procedure.
Budget created with alerts at 50, 80 and 100 per cent, and a named recipient
H · Written answers required — not configuration
✓
Item
Owner
Date
Is Born Between 2 Generals' intellectual property separated from the host organisation's data?Every component was authored by Kristen Hall and the authorship record establishes when. This requires an explicit answer in writing, not an assurance.
Where do repositories, storage, backups and container images physically live, and which region holds the data?
Can every repository and container be exported and run locally, without the platform?Not distrust of the platform — it is what makes the work defensible independent of any vendor, and a county will ask.
Who is billed, and under what arrangement?The subscription owner is the party the invoice reaches. If that is the host organisation it must be explicit rather than assumed.
Which component moves through the complete workflow first?The recommendation from this side is the mail-ballot lifecycle and custody service — the most complete component, the one a county can buy, and the one that does not depend on an unsettled cryptographic argument.
Agreed scope — group A complete means the build can begin
Platform team — name and signature
Born Between 2 Generals LLC
Date
Born Between 2 Generals LLC
Platform requirements checklist · companion to the election application brief, the one-page architecture summary, and the full engineering specification · 27 August 2026. Azure quota enforcement, confidential VM capability and PostgreSQL tier limits were read from Microsoft's documentation on 27 August 2026. Cost figures are independent estimates to be confirmed in the portal for the chosen region. Controlled — contains unregistered intellectual property and pre-filing subject matter. Not for distribution.