> For the complete documentation index, see [llms.txt](https://docs.duplocloud.com/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.duplocloud.com/docs/automation-platform/application-focused-interface-duplocloud-architecture.md).

# Policy Model

A high-level overview of the building blocks of DuploCloud's infrastructure-based architecture

The DuploCloud Policy Model is an application-infrastructure-centric abstraction created atop the user's cloud provider account. The following diagram shows the abstractions within which applications are deployed and users operate. The below bullet points are a brief introduction to the concepts and subsequent sub-pages explain this in details

* **DuploCloud Platform** installs in customer's cloud account. In case of Azure and GCP, a single instance can manage multiple subscriptions and GCP projects respectively. In case of AWS we need one Agent per AWS account, but they come together in a federated fashion to expose a single interface. This is described more in detail under the Management Portal Scope [Section below](/docs/automation-platform/application-focused-interface-duplocloud-architecture/management-portal-scope.md)
* **Infrastructure**: An infrastructure maps to a VPC in a region with optionally a Kubernetes Cluster. One cloud account (AWS account, GCP project or Azure subscription) can have multiple infrastructures (1:N). For more details of infrastructure see [here](/docs/automation-platform/application-focused-interface-duplocloud-architecture.md).
* **Plan**: When you create an[ Infrastructure](/docs/automation-platform/application-focused-interface-duplocloud-architecture/infrastructure.md) in DuploCloud, a Plan is automatically generated. A Plan is a placeholder or a template for configurations. These configurations are consistently applied to all Tenants within the Plan (or Infrastructure). For more details of Plan [see here](/docs/automation-platform/application-focused-interface-duplocloud-architecture/plan.md)
* **Tenant**: A Tenant is like an environment and is a child of the Infrastructure. It is the most fundamental construct in DuploCloud. While Infrastructure is a VPC-level isolation, Tenant is the next level of isolation implemented by segregating Tenants using concepts like Security Groups, IAM roles, Instance Profiles, K8S Namespaces, KMS Keys, etc. For more details of Tenant see the [following section](/docs/automation-platform/application-focused-interface-duplocloud-architecture/tenant.md)

<div data-full-width="true"><figure><img src="https://2471407984-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F68cb0s9ce5UIUKWPuYs8%2Fuploads%2FwzNJ4NWXuUeCWrIEFoM2%2FScreenshot%20(786).png?alt=media&amp;token=0eddb5df-83bb-4ba6-a4d5-b7c453d7fd7e" alt=""><figcaption><p>A diagram of DuploCloud application deployment</p></figcaption></figure></div>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://docs.duplocloud.com/docs/automation-platform/application-focused-interface-duplocloud-architecture.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
