Render to Azure in an hour.
Under your own tenant.
One command. An agent reads your repository and your render.yaml, then deploys into the Azure subscription you already own - governed by the directory you already run.
“We migrated our whole staging environment with a single prompt. Production was a one-click clone of staging. Once the tests gave us confidence we moved DNS off Heroku - we have been running production on our own cloud with Qovery ever since.”
“We liked the Heroku experience, and we knew the cloud meant skills and effort we did not have spare - that is why we kept putting the migration off. We do not regret doing it with Qovery. Deployments that took me over two hours now take 30 minutes.”
Render is a good platform right up until it is not.
Nothing below is a criticism of how Render works. They are the boundaries of the model: a platform that runs your services in its own account can only ever offer you what it has already built.
Five regions, and a service cannot move between them
- Oregon, Ohio, Virginia, Frankfurt and Singapore. If your customers or your regulator need somewhere else, there is no somewhere else. Render also does not support changing the region of an existing service - you create a new one and migrate the data across. And because each region has its own private network, two services in two regions cannot talk privately at all; that traffic crosses the public internet and you secure it yourself. In your own Azure subscription a region is a deployment parameter. Any Azure region, with multi-region and multi-cluster from one control plane.
The features that make it production-grade are plan gates
- Autoscaling, preview environments and audit logs start at Pro. SAML SSO, SCIM and HIPAA-enabled workspaces start at Scale. Dedicated outbound IPs need Pro and then cost an additional monthly fee on top. Even reading Render’s SOC 2 Type 2 report requires Pro and an NDA. None of these are exotic - they are what a security review asks about, and each is a line on a pricing page rather than a property of infrastructure you control. In your own subscription, Entra ID governs access, the Azure activity log records what happened, and the three fixed egress IPs are simply how the network is built. No tier attached.
Fixed instance shapes, and disks that block scaling
- Instance types are fixed RAM and CPU tiers, so a service needing slightly more memory buys a whole size class more of everything. A service with a persistent disk attached cannot run more than one instance at all, which turns a storage decision into a hard scaling ceiling. On Azure Virtual Machines the node shape is yours to choose, storage is a volume claim rather than a constraint, and Qovery can place interruptible pools on cheaper capacity while the web tier stays on demand.
Three steps, then the agent does it.
Your side takes about five minutes. Everything after that is automated.
- 01
A service principal provisions the network and an AKS cluster in your own subscription - about twenty minutes, and nothing leaves your boundary. Qovery gets a role you can read, scope down or revoke. Talk to a migration engineer before you connect anything.
- 02
One command teaches your coding agent how to read the repository - a render.yaml Blueprint, a Dockerfile, a build command, a set of environment variables - and describe the deployment in Qovery’s own terms. Nothing is deployed at this point. You are only giving the agent the vocabulary.
- 03
The agent detects every service, writes a Dockerfile where one is missing, maps your Render environment variables to Qovery variables and secrets, and shows you the plan. You approve it before a single resource is created - and your Render Postgres stays where it is, connected over the network, so you validate against real data before migrating a byte.
- 04Optional
Take this first or last - some teams want it as step zero, before they connect anything. A Qovery staff solution engineer reviews the cluster setup and environment layout with your team, then goes through the practices that keep the estate cheap and quiet: node sizing and Spot policy, autoscaling thresholds, preview-environment lifetimes, secret scoping and how to promote the same artifact between stages.
- network
- your VPC, three fixed egress IPs
- cluster
- AKS, in your region
- access
- a role scoped to Qovery
Works with any coding agent that reads skills. Nothing is deployed at this point.
web Node.js 20 Dockerfile generated worker Node.js 20 detected from render.yaml scheduler cron 2 jobs database PostgreSQL 15 Render Postgres, connected remotely
Nothing has been created yet. You approve the plan first.
- cluster
- node sizing, Spot policy, autoscaling
- workflow
- stages, approval gates, preview TTLs
- access
- secret scoping, roles per environment
From there it is automatic. Your apps come up running and live on Azure, reachable on a public URL - while the Render stack keeps serving traffic untouched.
You pay Azure. And it counts toward your commitment.
Money spent with Render counts toward nothing. If your organisation has an Enterprise Agreement or a MACC, you have already promised Microsoft a level of spend - and every service still running on Render is spend that does not draw it down.
Depends on your instance types and counts, your Postgres and Key Value plans, egress, data volume and region. A migration engineer will model your estate against the equivalent Azure shape before you commit to anything.
Why Azure, if the blocker is a security review.
Teams rarely leave Render over compute pricing. They leave when someone asks who can deploy to production, where the audit trail is, and which tier those answers require.
Entra ID decides who deploys, on every plan
- On Render, SAML SSO and SCIM start at the Scale plan and audit logs start at Pro. In your own Azure subscription, access is governed by the directory you already run - your Entra ID groups, your conditional access policies, your joiner-mover-leaver process. Qovery supports SAML SSO, and the Azure activity log records what happened to the infrastructure regardless of what anyone is paying.
Spend counts toward your EA or MACC
- Compute runs on AKS inside your subscription, so it draws down an Enterprise Agreement or Microsoft Azure Consumption Commitment exactly like any other Azure workload. This is often the whole business case: the organisation already owes Microsoft the money, and paying Render instead means paying twice.
Compliance is a property of the account, not a plan tier
- Render gates HIPAA-enabled workspaces behind Scale and puts its SOC 2 report behind Pro and an NDA. When the workload runs in your own subscription, residency, encryption keys, private endpoints and the audit trail are things you configure and evidence directly - the answer to an auditor stops depending on which plan the workspace is on.
Our control plane. Your account, your bill.
Qovery sits above the infrastructure and never owns it. Every cluster, database and bucket is provisioned inside the Azure subscription you already hold - Azure invoices you directly.
- We do not take a cut of your Azure spend. A flat subscription, whether your bill is $2k or $200k.
- We push it the other way: idle nodes, oversized requests and preview environments left running get flagged so you stop paying for them.
- Render runs all of this in its own account. Qovery runs it in yours.
Not sure which Azure services fit your workload? A solution engineer will map it with you.
Stop paying Qovery and the stack keeps running - the manifests and qovery/qovery Terraform are already in your account.
Your first service on Azure,
live within the hour.
Any Azure region, with multi-region and multi-cluster from one control plane. Nothing you do here touches your existing Render services until you decide to move the domain.
Render to Azure
Something not covered here? Talk to a migration engineer - they have done this on estates larger than yours.