AI Native WorkshopGo from AI experimentation to AI-native execution across your organization.
Render → Azure migration

Render to Azure in an hour.
Under your own tenant.

One command. An agent reads your repository and your render.yaml, then deploys into the Azure subscription you already own - governed by the directory you already run.

No step is destructiveBoth stacks run in parallelRender stays up until you move DNS
your-app — qovery agent
$ deploy this project with Qovery
Scanning repository...
web Node.js 20 Dockerfile generated
worker Node.js 20 detected from render.yaml
scheduler cron 2 jobs
database PostgreSQL 15 Render Postgres, connected remotely
Plan: 3 services, 1 external database, 12 environment variables
Nothing has been created yet. Approve to continue.
200+ companies run on their own cloud with Qovery4.8 on G2 · 80+ reviews
  • Talkspace
  • Alan
  • Powens
  • Prezi
  • Prosperity
  • Getsafe
Migrated from Heroku
We migrated our whole staging environment with a single prompt. Production was a one-click clone of staging. Once the tests gave us confidence we moved DNS off Heroku - we have been running production on our own cloud with Qovery ever since.
Miguel VictoriaSoftware Engineer, Sofive
Migrated from Heroku
We liked the Heroku experience, and we knew the cloud meant skills and effort we did not have spare - that is why we kept putting the migration off. We do not regret doing it with Qovery. Deployments that took me over two hours now take 30 minutes.
Kyle FlavinDirector of DevOps, RxVantageCase study →
Where Render stops

Render is a good platform right up until it is not.

Nothing below is a criticism of how Render works. They are the boundaries of the model: a platform that runs your services in its own account can only ever offer you what it has already built.

Five regions, and a service cannot move between them

Oregon, Ohio, Virginia, Frankfurt and Singapore. If your customers or your regulator need somewhere else, there is no somewhere else. Render also does not support changing the region of an existing service - you create a new one and migrate the data across. And because each region has its own private network, two services in two regions cannot talk privately at all; that traffic crosses the public internet and you secure it yourself. In your own Azure subscription a region is a deployment parameter. Any Azure region, with multi-region and multi-cluster from one control plane.

The features that make it production-grade are plan gates

Autoscaling, preview environments and audit logs start at Pro. SAML SSO, SCIM and HIPAA-enabled workspaces start at Scale. Dedicated outbound IPs need Pro and then cost an additional monthly fee on top. Even reading Render’s SOC 2 Type 2 report requires Pro and an NDA. None of these are exotic - they are what a security review asks about, and each is a line on a pricing page rather than a property of infrastructure you control. In your own subscription, Entra ID governs access, the Azure activity log records what happened, and the three fixed egress IPs are simply how the network is built. No tier attached.

Fixed instance shapes, and disks that block scaling

Instance types are fixed RAM and CPU tiers, so a service needing slightly more memory buys a whole size class more of everything. A service with a persistent disk attached cannot run more than one instance at all, which turns a storage decision into a hard scaling ceiling. On Azure Virtual Machines the node shape is yours to choose, storage is a volume claim rather than a constraint, and Qovery can place interruptible pools on cheaper capacity while the web tier stays on demand.
How the migration runs

Three steps, then the agent does it.

Your side takes about five minutes. Everything after that is automated.

  1. 01

    A service principal provisions the network and an AKS cluster in your own subscription - about twenty minutes, and nothing leaves your boundary. Qovery gets a role you can read, scope down or revoke. Talk to a migration engineer before you connect anything.

  2. 02

  3. 03

  4. 04

    Optional
In the Azure console
One service principal, about twenty minutes.
network
your VPC, three fixed egress IPs
cluster
AKS, in your region
access
a role scoped to Qovery
10–60 min

From there it is automatic. Your apps come up running and live on Azure, reachable on a public URL - while the Render stack keeps serving traffic untouched.

What it costs

You pay Azure. And it counts toward your commitment.

Money spent with Render counts toward nothing. If your organisation has an Enterprise Agreement or a MACC, you have already promised Microsoft a level of spend - and every service still running on Render is spend that does not draw it down.

Depends on your instance types and counts, your Postgres and Key Value plans, egress, data volume and region. A migration engineer will model your estate against the equivalent Azure shape before you commit to anything.

Specific to Azure

Why Azure, if the blocker is a security review.

Teams rarely leave Render over compute pricing. They leave when someone asks who can deploy to production, where the audit trail is, and which tier those answers require.

Entra ID decides who deploys, on every plan

On Render, SAML SSO and SCIM start at the Scale plan and audit logs start at Pro. In your own Azure subscription, access is governed by the directory you already run - your Entra ID groups, your conditional access policies, your joiner-mover-leaver process. Qovery supports SAML SSO, and the Azure activity log records what happened to the infrastructure regardless of what anyone is paying.

Spend counts toward your EA or MACC

Compute runs on AKS inside your subscription, so it draws down an Enterprise Agreement or Microsoft Azure Consumption Commitment exactly like any other Azure workload. This is often the whole business case: the organisation already owes Microsoft the money, and paying Render instead means paying twice.

Compliance is a property of the account, not a plan tier

Render gates HIPAA-enabled workspaces behind Scale and puts its SOC 2 report behind Pro and an NDA. When the workload runs in your own subscription, residency, encryption keys, private endpoints and the audit trail are things you configure and evidence directly - the answer to an auditor stops depending on which plan the workspace is on.
Qovery is not a PaaS

Our control plane. Your account, your bill.

Qovery sits above the infrastructure and never owns it. Every cluster, database and bucket is provisioned inside the Azure subscription you already hold - Azure invoices you directly.

  • We do not take a cut of your Azure spend. A flat subscription, whether your bill is $2k or $200k.
  • We push it the other way: idle nodes, oversized requests and preview environments left running get flagged so you stop paying for them.
  • Render runs all of this in its own account. Qovery runs it in yours.

Not sure which Azure services fit your workload? A solution engineer will map it with you.

QoveryCONTROL PLANE
deploymentsenvironmentspreview envsRBAC + auditcost signals
provisions standard Terraform and Kubernetes manifests
Your Azure subscription
invoiced by Azure, directly to you
VPC · your network policy
AKS clusterwebworkercronpreview-pr-482Azure DatabaseAzure CacheBlob Storagesecrets
IAM: yours · data residency: yours · audit trail: yours

Stop paying Qovery and the stack keeps running - the manifests and qovery/qovery Terraform are already in your account.

Leave Render

Your first service on Azure,
live within the hour.

Any Azure region, with multi-region and multi-cluster from one control plane. Nothing you do here touches your existing Render services until you decide to move the domain.

Frequently asked

Render to Azure

Something not covered here? Talk to a migration engineer - they have done this on estates larger than yours.

How long does a Render to Azure migration take?

First app live in under an hour. Full estates finish in days: the agent reads your render.yaml Blueprint, so the service topology you already declared becomes the deployment plan rather than something anyone retypes. The pace is set by your data and your change windows, not by the tooling.

Will migrating disrupt our running Render services?

No. Nothing in the process modifies or removes anything on Render. Both stacks run in parallel until you move DNS, and you can move it back.

Can Qovery migrate our Render Postgres database to Azure?

Yes. Under 100 GB migrates live with minimal interruption. Larger datasets use a replication-based cutover rather than a dump and restore. The database lands in your own Azure subscription on Azure Database for PostgreSQL, under your keys and your backup policy.

Does Qovery read our render.yaml?

Yes. A Blueprint already declares your services, their instance types, their environment groups and how they connect, which is most of a migration plan. The agent uses it as the starting point and asks about anything the file does not cover, then shows you the plan before creating a single resource.

Is Qovery just another Render?

No, and this is the whole difference. Render runs your services in Render’s account. Qovery installs into the cloud account you already own - you hold the cloud bill, the VPC, the cluster and the audit trail. The control plane is ours, the infrastructure is yours.

What happens if we stop using Qovery?

Everything keeps running. Qovery generates standard Terraform and native Kubernetes manifests in your account, so the estate outlives the subscription. Leaving Render means moving the workload; leaving Qovery does not.

Can this burn our existing Azure commitment?

Yes. Compute runs on AKS in your own subscription, so the spend counts toward an Enterprise Agreement or a Microsoft Azure Consumption Commitment exactly like any other Azure workload. Money spent with Render counts toward neither.

Does Qovery work with Entra ID for single sign-on?

Yes. Qovery supports SAML single sign-on, so access is governed by the same Entra ID groups and conditional access policies as the rest of your Microsoft estate.

Does the workload stay inside our tenant?

Yes. The AKS cluster, the databases and the application data all live inside your own Azure subscription and your own virtual network. Qovery operates them through the Azure API and never hosts your workloads.

How does every Render primitive map to Azure?

On Render
On Azure
What changes
Web Service
AKS pod on Azure Virtual Machines
Autoscales on real utilisation, and the underlying node pool can carry a reservation, the savings plan for compute, or Spot - all billed to your subscription.
Background Worker
AKS pod in the same cluster
Long-running work without the 30-second router timeout.
Cron Job
Kubernetes CronJob
Real cron expressions instead of fixed ten-minute, hourly and daily buckets.
Private Service
A ClusterIP service on the cluster network
Reachable from your other workloads without a public URL - and, unlike a Render private network, reachable across regions because the network is yours.
Static Site
A static service behind your CDN
Served from your own bucket and CDN distribution, on the same domain and TLS certificate as the rest of the estate.
Render Postgres
Azure Database for PostgreSQL
Container mode for development, Azure Database for PostgreSQL Flexible Server for production - zone-redundant high availability, automated backups, and private endpoint access only.
Render Key Value
Azure Cache for Redis
Azure Cache for Redis, sized independently of the application and reachable over a private endpoint inside your virtual network.
Message brokers
Azure Service Bus or a Helm chart
Deployed by Qovery as a service inside your environment.
Persistent Disk
A PersistentVolumeClaim, or object storage
A service with a Render disk attached cannot run more than one instance. A PVC carries no such rule, and durable blobs belong in object storage rather than on a volume bolted to one pod.
Environment Groups
Qovery variables and secrets
Scoped per project, environment and service, with aliases and overrides instead of one flat list.
Preview Environments
Preview environments
One per pull request, created on open and shut down when idle - on every plan, rather than from Pro upward.
render.yaml Blueprint
Qovery environments and qovery/qovery Terraform
The agent reads your Blueprint to build the plan. What it writes out is standard Terraform and Kubernetes manifests in your own repository and account.
Render TLS and custom domains
an Azure Load Balancer with managed TLS
An Azure Load Balancer with managed TLS, certificates issued and renewed automatically, and no per-domain SSL add-on to buy.