Credentials
- Working professionally as an Azure & Network Engineer
- ~3 years building & documenting Azure environments
- Microsoft Certified: Azure Administrator (AZ-104)
- IT student — enterprise cloud architecture focus
- Based in Switzerland
Find me
Joel Aggeler
I work professionally as an Azure & Network Engineer in Switzerland and am Microsoft Certified as an Azure Administrator (AZ-104). For close to three years I've been building and documenting Azure environments — landing zones, networking, identity, governance, and the infrastructure-as-code and operational foundations that keep them maintainable. I'm also an IT student focused on enterprise cloud architecture, and I'm still learning every day.
My focus is the platform and network layer: hub-spoke and Virtual WAN topologies, private connectivity and DNS, management group and subscription design, Entra ID and least-privilege access, Azure Policy guardrails, and the Bicep/Terraform automation that makes all of it reproducible. The work here is grounded in hands-on engineering and aligned with the Microsoft Cloud Adoption Framework — think of it as a careful engineering notebook where I document my reasoning and trade-offs in the open, not turnkey production guidance. Always validate anything here against your own requirements before applying it.
Infraze is my engineering notebook. I publish the documentation, architecture decisions, and trade-offs behind each design — not just what to build, but why a choice was made, where it breaks, and what I would do differently. The aim is to be a reliable, accurate Azure and platform-engineering reference, including the parts that are easy to get wrong.
I care about infrastructure that is secure, understandable, documented, and reproducible. You'll find the implementation details in the docs, the reasoning and lessons in the blog, and the code on GitHub.
Focus areas
Azure Architecture
Landing zones, subscription design, cloud foundations
Networking
Private endpoints, DNS, VPNs, firewalls
Identity & Security
Entra ID, RBAC, PIM, identity security
Infrastructure as Code
Bicep, Terraform, automation
Governance & Operations
Azure Policy, monitoring, operations
Platform Engineering
Kubernetes, GitOps, observability
Troubleshooting & Lessons
Real-world fixes and lessons learned