{"diagram_summary":"Client \u2192 DNS \u2192 Azure LB \u2192 Traefik (TLS) \u2192 Flask Service \u2192 Pods; Pods \u2192 postgres StatefulSet when needed. CI/CD: Azure DevOps \u2192 private agent \u2192 ACR + Helm \u2192 private AKS.","layers":[{"components":["Azure Load Balancer","Traefik","cert-manager","Let's Encrypt"],"name":"Edge & Ingress","role":"Public entry, TLS termination, routing into the cluster"},{"components":["Flask","Gunicorn","Deployment","ClusterIP Service"],"name":"Application","role":"Serve HTTP API and UI from pods behind the ingress"},{"components":["PostgreSQL StatefulSet","PVC","Service postgres"],"name":"Data","role":"Persistent relational store reachable only in-cluster"},{"components":["Private AKS","Private VNet","Azure ACR","Kubernetes"],"name":"Platform","role":"Private control plane and private workload network"},{"components":["Azure DevOps","Self-hosted agent","Helm","ACR"],"name":"CI/CD","role":"Build, push, and deploy without exposing the cluster API"}],"owner":"Abdul","project":"flask-aks-poc"}
