Compute and Networking

Compares Azure VM, AKS, Functions, VNet, VPN Gateway, ExpressRoute, and other core services.

For those new to cloud, "compute" and "networking" can sound technical. But with everyday analogies, they become surprisingly approachable. This guide walks through Azure's core compute and networking services in plain language — no prior cloud experience required. Whether you are preparing for the AZ-900 exam or simply want to understand cloud concepts, this guide will help.

 

What Are Compute Services?

Compute services are simply "computers and execution environments provided by Azure." In the past, companies had to purchase their own servers, build data centers, and hire maintenance staff. In the cloud era, you hand all of that to Azure and rent only what you need.

Which service you choose comes down to two questions. First, how much do you want to manage yourself? Second, how do you want your code to run? The answers lead you to choose from VM, App Service, Functions, or containers.

 

Virtual Machines (VM) — The Rental Car

A VM is a virtual computer provided by Azure. The rental car analogy fits perfectly. You choose the model (operating system) and drive it yourself (manage the server). You have maximum freedom, but you are also responsible for everything — filling the gas tank, buying insurance, washing the car.

Why use a VM? Choose VMs when you need to move existing programs from a company server to the cloud exactly as they are — a "Lift and Shift" migration — or when you need complete control down to the operating system level. Examples include legacy software that requires a specific Linux kernel version, or environments where you must manage Windows Server licenses directly.

You install and manage everything: OS, middleware, runtime, and the application Choose from Windows Server, Ubuntu, CentOS, Red Hat, and many more OS images IaaS (Infrastructure as a Service) model — highest control, highest management responsibility Best suited for legacy application migration (Lift and Shift)

VM Scale Sets — The Automatic Parking Lot

VM Scale Sets groups multiple identical VMs together and automatically adds or removes them based on demand. Like a parking lot that opens an adjacent field when full and closes it when traffic dies down, VM Scale Sets adds VMs automatically when traffic spikes and removes them when things quiet down — saving costs. This is highly effective for unpredictable traffic surges like Black Friday sales or ticket reservation rushes.

Azure Virtual Desktop — Cloud Desktop

Azure Virtual Desktop delivers a complete Windows desktop environment from the cloud. Whether an employee is at home, in a café, or traveling abroad, they can access their own Windows screen exactly as they left it. It is ideal for remote work, BYOD (Bring Your Own Device) policies, and environments where storing data on a local PC is not allowed for security reasons.

 

Azure App Service — Renting a Food Court Stall

App Service is a fully managed PaaS (Platform as a Service) for web applications and REST APIs. Think of it like renting a stall in a food court. The building, electricity, plumbing, tables, and kitchen equipment are already in place. You just bring your food (code). The building owner (Azure) handles building management, safety inspections, and maintenance.

Why use App Service? Choose it when you want to deploy a website or API quickly but do not want to deal with server OS configuration, networking, or infrastructure maintenance. It is especially useful for startups and small teams where fast time-to-market matters.

Supports multiple languages and runtimes: .NET, Java, Node.js, Python, PHP, Ruby Auto-scaling: automatically adds instances when traffic increases Built-in load balancing — no extra configuration needed Automatic custom domain binding and SSL/TLS certificate management Deployment slots (Staging/Production) for zero-downtime deployments

 

Azure Functions — The Vending Machine (Serverless)

Azure Functions is a serverless computing service. The vending machine analogy is perfect. Insert a coin (trigger an event) and get your drink (code executes). When nobody uses the vending machine, the electricity cost is essentially zero.

"Serverless" sounds like there are no servers, but servers do exist. The difference is that you never manage them, and you only pay for the time your code actually runs. Instead of paying for a server running 24 hours a day, you are billed only for the actual execution time (down to milliseconds) and the number of executions.

Trigger types: HTTP request, timer, Azure Storage Queue, Blob upload, Cosmos DB change, and more Pay-per-use: includes up to 1 million free executions per month Write only the code — no server provisioning, OS patching, or scaling needed Best for short tasks (a few seconds); use Durable Functions for long-running work

 

Container Services — Lunchboxes and Large Cafeteria Kitchens

A container bundles an application with everything it needs to run — libraries, configuration, runtime — into a single package. It solves the classic problem: "It works on my machine but not on the server."

Azure Container Instances (ACI) — Pre-packaged Lunchbox

ACI is like a pre-packaged lunchbox. No complex kitchen (infrastructure) setup required — just open and eat (run). Use it when you want to run a single container quickly without dealing with complex orchestration like Kubernetes. Ideal for batch jobs, build pipelines, and one-time event processing.

AKS (Azure Kubernetes Service) — Large Cafeteria Kitchen

AKS is like a large cafeteria kitchen managing hundreds or thousands of lunchboxes. It automatically orchestrates which containers run, how many, and when. Failed containers restart automatically, and container counts adjust based on traffic. AKS plays a central role in large-scale microservices architectures.

| Service | Analogy | Best For | Management Complexity | |---------|---------|---------|----------------------| | Container Instances | Pre-packaged lunchbox | Quick runs, one-time tasks | Low | | AKS | Large cafeteria kitchen | Large-scale container operations | High |

 

Compute Services at a Glance

| Service | Analogy | Model | What You Manage | When to Use | |---------|---------|-------|----------------|------------| | Virtual Machines | Rental car (you drive) | IaaS | OS through app | Legacy migration, full control | | App Service | Food court stall | PaaS | Code only | Web apps, APIs, fast deployment | | Azure Functions | Vending machine | Serverless | Code only | Event-driven, short tasks | | Container Instances | Lunchbox | Container | Container image | One-time container runs | | AKS | Large kitchen | Container orchestration | Containers and cluster | Large-scale microservices |

 

Networking Services — Roads and Buildings in Azure

Azure networking services handle how resources communicate with each other and how they connect to the outside world. Just as a city needs roads, alleys, highways, traffic lights, and checkpoints, the cloud needs equivalent structures.

 

Azure Virtual Network (VNet) — A Fenced Private Property

A VNet is your own private network inside the Azure cloud. Think of it as fenced private property. Inside this property, your VMs, databases, and app services communicate securely with each other. Outsiders (the internet) cannot cross the fence without permission.

Why do you need a VNet? To isolate Azure resources from the outside world and to control communication between resources securely. For example, you can expose the web server to the internet while keeping the database server completely inaccessible from outside.

Subnets — Zones Inside the Property

A subnet is a logically divided zone within a VNet (property). Just as you divide property into a garden (front-end server zone), a warehouse (back-end server zone), and a living area (database zone), subnets divide the network by role.

NSG (Network Security Group) — Security Guard

An NSG is a security guard stationed in front of a subnet or individual VM. You define rules to specify which IP addresses are allowed, which ports to open, and which traffic to block. For example: "Allow port 80 (HTTP) from everywhere; allow port 3306 (MySQL) only from specific internal IPs."

VNet Peering — Passage Between Neighboring Properties

VNet Peering creates a dedicated passage between two different VNets. They connect directly through Azure's internal backbone network — no internet involved. It is fast, affordable, and secure.

 

VPN Gateway — An Encrypted Secret Tunnel Over a Public Road

VPN Gateway connects your office (on-premises) to an Azure VNet. Think of it as digging a secret encrypted tunnel through a public road (the internet). The data inside the tunnel is encrypted, so even if someone intercepts it in transit, they cannot read the contents.

Uses the internet, so speed and latency depend on connection quality Relatively quick and inexpensive to set up — suitable for small-scale or temporary connections Supports Site-to-Site VPN (office to Azure) and Point-to-Site VPN (individual PC to Azure)

 

Azure ExpressRoute — A Dedicated Private Highway

ExpressRoute connects on-premises infrastructure to Azure over a completely private, dedicated line — no internet whatsoever. Instead of using a public road, you get your own dedicated highway. The connection is established physically through a telecommunications provider or dedicated circuit provider.

Why use ExpressRoute? Use it when you need to transfer large amounts of data reliably, or in industries like finance, healthcare, and government where routing data through the internet is simply not permitted.

More stable and consistent speeds because the internet is not involved Low latency and stable bandwidth Takes more time to set up than VPN Gateway and costs more Bandwidth options: 50 Mbps to 10 Gbps

| Connection | Route | Speed and Stability | Setup Difficulty | Cost | Best For | |-----------|-------|---------------------|-----------------|------

Back to blog list