The other day I ran into one of those Azure deployment problems that looks reasonable right up until you understand which service is actually making the call.
I had provisioned an Azure Key Vault with
enabled_for_template_deploymentset totrue. I was familiar with this setting from working with Bicep and ARM …
Read MoreProblem Space
When deploying Azure solutions with Infrastructure as Code, we often create role assignments as part of the deployment. For example, a Bicep deployment may give a Function App’s managed identity access to a Key Vault, storage account, or Service Bus namespace.
It is easy to focus on the role being …
Read MoreOverview
WEBSITE_CONTENTSHAREis an app setting used by Azure Functions and Logic Apps Standard (which runs on the Functions runtime) alongsideWEBSITE_CONTENTAZUREFILECONNECTIONSTRINGto identify the Azure Files share the app uses for its content.The important thing to call out up front: you don’t always need …
Read MoreThe Problem
I was recently doing some initial testing around the migration of a client’s Azure DevOps Server 2019 to Azure DevOps Services. The basic process is
- Upgrade to the current version of Azure DevOps Server, currently 2022.2
- Validate the Team Project Collection (TPC) to be migrated, fixing any issues …
Read MoreProblem Space
Role assignments are one of those areas in Azure that look simple on the surface, but can become awkward pretty quickly once you start automating them properly.
Anyone who has worked with RBAC through IaC for long enough will usually run into the same set of problems.
There are usually three things in …
Read MoreOver the last few years, Azure Logic Apps Standard has become a core building block for many integration workloads. The platform gives us flexibility, connector richness, and scalable runtime options, but as workflow solutions grow, so does the risk profile.
In many teams, validation still leans heavily on run history …
Read More