Latest commit

History

30 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

AzResourceOps

Bring your own ARM templates to Enterprise-scale.

Objectives

This is an IaC module created to be used as an "extension" to Microsoft Enterprise-scale and AzOps. The main focus of this project is to supplement AzOps functionality and allow for deployment of all types of resources from within your Enterprise-scale repo without having to modify the Enterprise-scale code maintained by Microsoft.

The philosophy is that you "bring your own ARM templates" to handle deployment of resources at resource group level.

Scope

AzResourceOps is not meant to replace AzOps functionality. You should still use AzOps to deploy resources within the scope of AzOps, like:

  • Management Group hierarchy and Subscription organization
    • ResourceTypes:
      • Microsoft.Management/managementGroups
      • Microsoft.Management/managementGroups/subscriptions
      • Microsoft.Subscription/subscriptions
  • Policy Definition and Policy Assignment for Governance
    • ResourceTypes:
      • Microsoft.Authorization/policyDefinitions
      • Microsoft.Authorization/policySetDefinitions
      • Microsoft.Authorization/policyAssignments
  • Role Definition and Role Assignment
    • ResourceTypes:
      • Microsoft.Authorization/roleDefinitions
      • Microsoft.Authorization/roleAssignments

How it works

You drop your ARM template(s) and associated parameter file in the folder where you want your resource(s) deployed. For resource groups this will be the folder of the subscription in your Enterprise-scale repo where you want your resource group deployed. For all other resources this will be the folder of the resource group where you want your resources deployed. AzResourceOps searches the azops folder in your Enterprise-scale repo for any new template/parameter pairs, parses the files and creates a new subscription deployment ARM template containing all resources as nested deployments. Do not place your files in the .AzState folders as these will not be searched by AzResourceOps.

The example pipeline azresourceops-push.yml must be set up in your Enterprise-scale repo and all pushes must be done to branches with name starting with deploy/, the pipeline will only trigger when pushes are done to branches starting with this name (unless changed).

If pipeline succeeds, AzResourceOps deletes the deploy/* branch without merging anything to the main branch of your Enterprise-scale repo. This is to avoid cluttering the main repo.

Prerequisites

To start using AzResourceOps you need

  • An existing Enterprise-scale repo setup.
  • A service principal with Contributor permissions on subscriptions where you will deploy resources. You can use the SP already created for Enterprise-scale, for instance.

Getting Started

  • Clone this repository to your organization (currently only tested in Azure DevOps within the same organization as Enterprise-scale repo). The AzResourceOps repo must be possible to checkout from pipeline in your Enterprise-scale repo.
  • Copy file \.azure-pipelines\azresourceops-push.yml to your Enterprise-scale repo.
  • Change azresourceops-push.yml to reflect your environment. ES_REPO_NAME is the name of your Enterprise-scale repo, AZRESOURCEOPS_REPO_NAME is the name of your AzResourceOps repo. The folder in FilePath must be the name of the AzResourceOps repo (same as AZRESOURCEOPS_REPO_NAME). AzResourceOps pipeline YAML
  • Create a new pipeline in Enterprise-scale repo from azresourceops-push.yml.
  • Create a new secret pipeline variable called AZURE_CREDENTIALS containing your service principal.
    {
    "clientId": "xxxx-xxxx-xxxx-xxxx-xxxxx",
    "displayName": "AzOps",
    "name": "http://AzOps",
    "clientSecret": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "tenantId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "subscriptionId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx"
    }

How to use AzResourceOps

AzResourceOps requires a parameter file for each ARM template you wish to deploy. The parameter file has to have the same name as the ARM template with *.parameters.json appendend. I.ex. if you deploy a new Key Vault and the ARM template is called keyVault.json, your parameter file will have to be named keyVault.parameters.json.

Unless changed, the pipeline will trigger by default on push to all branches called deploy/*, where * can be whatever you want.

To deploy a new resource:

  • Make sure to pull latest changes from main.
  • Create a new branch in your Enterprise-scale repo called deploy/whateveryouwanthere.
  • Copy your ARM template(s) and parameter file(s) to the resource group folder where you want to deploy the resources. If the resource group does not exist, you will need to deploy the resource group first (see Limitations).
  • Resource group deployment file(s) will be placed in the folder of the subscription where you want to deploy the resource group(s).

Limitations

  • AzResourceOps is currently only tested in Azure DevOps, not GitHub or any other services.
  • Requires parameter file for all templates.
  • Deployment of resources assume that resource group already exists. You cannot deploy a new resource group and a new resource into the same resource group in the same operation, these deployments will have to be separated.

Contributing

There are probably a lot of scenarios and tests that should be covered and this project welcomes any contributions and suggestions.

More Information

For more information:

About

Bring your own ARM templates to Enterprise-scale.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Latest commit

History

30 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

AzResourceOps

Bring your own ARM templates to Enterprise-scale.

Objectives

This is an IaC module created to be used as an "extension" to Microsoft Enterprise-scale and AzOps. The main focus of this project is to supplement AzOps functionality and allow for deployment of all types of resources from within your Enterprise-scale repo without having to modify the Enterprise-scale code maintained by Microsoft.

The philosophy is that you "bring your own ARM templates" to handle deployment of resources at resource group level.

Scope

AzResourceOps is not meant to replace AzOps functionality. You should still use AzOps to deploy resources within the scope of AzOps, like:

  • Management Group hierarchy and Subscription organization
    • ResourceTypes:
      • Microsoft.Management/managementGroups
      • Microsoft.Management/managementGroups/subscriptions
      • Microsoft.Subscription/subscriptions
  • Policy Definition and Policy Assignment for Governance
    • ResourceTypes:
      • Microsoft.Authorization/policyDefinitions
      • Microsoft.Authorization/policySetDefinitions
      • Microsoft.Authorization/policyAssignments
  • Role Definition and Role Assignment
    • ResourceTypes:
      • Microsoft.Authorization/roleDefinitions
      • Microsoft.Authorization/roleAssignments

How it works

You drop your ARM template(s) and associated parameter file in the folder where you want your resource(s) deployed. For resource groups this will be the folder of the subscription in your Enterprise-scale repo where you want your resource group deployed. For all other resources this will be the folder of the resource group where you want your resources deployed. AzResourceOps searches the azops folder in your Enterprise-scale repo for any new template/parameter pairs, parses the files and creates a new subscription deployment ARM template containing all resources as nested deployments. Do not place your files in the .AzState folders as these will not be searched by AzResourceOps.

The example pipeline azresourceops-push.yml must be set up in your Enterprise-scale repo and all pushes must be done to branches with name starting with deploy/, the pipeline will only trigger when pushes are done to branches starting with this name (unless changed).

If pipeline succeeds, AzResourceOps deletes the deploy/* branch without merging anything to the main branch of your Enterprise-scale repo. This is to avoid cluttering the main repo.

Prerequisites

To start using AzResourceOps you need

  • An existing Enterprise-scale repo setup.
  • A service principal with Contributor permissions on subscriptions where you will deploy resources. You can use the SP already created for Enterprise-scale, for instance.

Getting Started

  • Clone this repository to your organization (currently only tested in Azure DevOps within the same organization as Enterprise-scale repo). The AzResourceOps repo must be possible to checkout from pipeline in your Enterprise-scale repo.
  • Copy file \.azure-pipelines\azresourceops-push.yml to your Enterprise-scale repo.
  • Change azresourceops-push.yml to reflect your environment. ES_REPO_NAME is the name of your Enterprise-scale repo, AZRESOURCEOPS_REPO_NAME is the name of your AzResourceOps repo. The folder in FilePath must be the name of the AzResourceOps repo (same as AZRESOURCEOPS_REPO_NAME). AzResourceOps pipeline YAML
  • Create a new pipeline in Enterprise-scale repo from azresourceops-push.yml.
  • Create a new secret pipeline variable called AZURE_CREDENTIALS containing your service principal.
    {
    "clientId": "xxxx-xxxx-xxxx-xxxx-xxxxx",
    "displayName": "AzOps",
    "name": "http://AzOps",
    "clientSecret": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "tenantId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "subscriptionId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx"
    }

How to use AzResourceOps

AzResourceOps requires a parameter file for each ARM template you wish to deploy. The parameter file has to have the same name as the ARM template with *.parameters.json appendend. I.ex. if you deploy a new Key Vault and the ARM template is called keyVault.json, your parameter file will have to be named keyVault.parameters.json.

Unless changed, the pipeline will trigger by default on push to all branches called deploy/*, where * can be whatever you want.

To deploy a new resource:

  • Make sure to pull latest changes from main.
  • Create a new branch in your Enterprise-scale repo called deploy/whateveryouwanthere.
  • Copy your ARM template(s) and parameter file(s) to the resource group folder where you want to deploy the resources. If the resource group does not exist, you will need to deploy the resource group first (see Limitations).
  • Resource group deployment file(s) will be placed in the folder of the subscription where you want to deploy the resource group(s).

Limitations

  • AzResourceOps is currently only tested in Azure DevOps, not GitHub or any other services.
  • Requires parameter file for all templates.
  • Deployment of resources assume that resource group already exists. You cannot deploy a new resource group and a new resource into the same resource group in the same operation, these deployments will have to be separated.

Contributing

There are probably a lot of scenarios and tests that should be covered and this project welcomes any contributions and suggestions.

More Information

For more information:

About

Bring your own ARM templates to Enterprise-scale.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

30 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

AzResourceOps

Bring your own ARM templates to Enterprise-scale.

Objectives

This is an IaC module created to be used as an "extension" to Microsoft Enterprise-scale and AzOps. The main focus of this project is to supplement AzOps functionality and allow for deployment of all types of resources from within your Enterprise-scale repo without having to modify the Enterprise-scale code maintained by Microsoft.

The philosophy is that you "bring your own ARM templates" to handle deployment of resources at resource group level.

Scope

AzResourceOps is not meant to replace AzOps functionality. You should still use AzOps to deploy resources within the scope of AzOps, like:

  • Management Group hierarchy and Subscription organization
    • ResourceTypes:
      • Microsoft.Management/managementGroups
      • Microsoft.Management/managementGroups/subscriptions
      • Microsoft.Subscription/subscriptions
  • Policy Definition and Policy Assignment for Governance
    • ResourceTypes:
      • Microsoft.Authorization/policyDefinitions
      • Microsoft.Authorization/policySetDefinitions
      • Microsoft.Authorization/policyAssignments
  • Role Definition and Role Assignment
    • ResourceTypes:
      • Microsoft.Authorization/roleDefinitions
      • Microsoft.Authorization/roleAssignments

How it works

You drop your ARM template(s) and associated parameter file in the folder where you want your resource(s) deployed. For resource groups this will be the folder of the subscription in your Enterprise-scale repo where you want your resource group deployed. For all other resources this will be the folder of the resource group where you want your resources deployed. AzResourceOps searches the azops folder in your Enterprise-scale repo for any new template/parameter pairs, parses the files and creates a new subscription deployment ARM template containing all resources as nested deployments. Do not place your files in the .AzState folders as these will not be searched by AzResourceOps.

The example pipeline azresourceops-push.yml must be set up in your Enterprise-scale repo and all pushes must be done to branches with name starting with deploy/, the pipeline will only trigger when pushes are done to branches starting with this name (unless changed).

If pipeline succeeds, AzResourceOps deletes the deploy/* branch without merging anything to the main branch of your Enterprise-scale repo. This is to avoid cluttering the main repo.

Prerequisites

To start using AzResourceOps you need

  • An existing Enterprise-scale repo setup.
  • A service principal with Contributor permissions on subscriptions where you will deploy resources. You can use the SP already created for Enterprise-scale, for instance.

Getting Started

  • Clone this repository to your organization (currently only tested in Azure DevOps within the same organization as Enterprise-scale repo). The AzResourceOps repo must be possible to checkout from pipeline in your Enterprise-scale repo.
  • Copy file \.azure-pipelines\azresourceops-push.yml to your Enterprise-scale repo.
  • Change azresourceops-push.yml to reflect your environment. ES_REPO_NAME is the name of your Enterprise-scale repo, AZRESOURCEOPS_REPO_NAME is the name of your AzResourceOps repo. The folder in FilePath must be the name of the AzResourceOps repo (same as AZRESOURCEOPS_REPO_NAME). AzResourceOps pipeline YAML
  • Create a new pipeline in Enterprise-scale repo from azresourceops-push.yml.
  • Create a new secret pipeline variable called AZURE_CREDENTIALS containing your service principal.
    {
    "clientId": "xxxx-xxxx-xxxx-xxxx-xxxxx",
    "displayName": "AzOps",
    "name": "http://AzOps",
    "clientSecret": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "tenantId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "subscriptionId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx"
    }

How to use AzResourceOps

AzResourceOps requires a parameter file for each ARM template you wish to deploy. The parameter file has to have the same name as the ARM template with *.parameters.json appendend. I.ex. if you deploy a new Key Vault and the ARM template is called keyVault.json, your parameter file will have to be named keyVault.parameters.json.

Unless changed, the pipeline will trigger by default on push to all branches called deploy/*, where * can be whatever you want.

To deploy a new resource:

  • Make sure to pull latest changes from main.
  • Create a new branch in your Enterprise-scale repo called deploy/whateveryouwanthere.
  • Copy your ARM template(s) and parameter file(s) to the resource group folder where you want to deploy the resources. If the resource group does not exist, you will need to deploy the resource group first (see Limitations).
  • Resource group deployment file(s) will be placed in the folder of the subscription where you want to deploy the resource group(s).

Limitations

  • AzResourceOps is currently only tested in Azure DevOps, not GitHub or any other services.
  • Requires parameter file for all templates.
  • Deployment of resources assume that resource group already exists. You cannot deploy a new resource group and a new resource into the same resource group in the same operation, these deployments will have to be separated.

Contributing

There are probably a lot of scenarios and tests that should be covered and this project welcomes any contributions and suggestions.

More Information

For more information:

About

Bring your own ARM templates to Enterprise-scale.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

30 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

AzResourceOps

Bring your own ARM templates to Enterprise-scale.

Objectives

This is an IaC module created to be used as an "extension" to Microsoft Enterprise-scale and AzOps. The main focus of this project is to supplement AzOps functionality and allow for deployment of all types of resources from within your Enterprise-scale repo without having to modify the Enterprise-scale code maintained by Microsoft.

The philosophy is that you "bring your own ARM templates" to handle deployment of resources at resource group level.

Scope

AzResourceOps is not meant to replace AzOps functionality. You should still use AzOps to deploy resources within the scope of AzOps, like:

  • Management Group hierarchy and Subscription organization
    • ResourceTypes:
      • Microsoft.Management/managementGroups
      • Microsoft.Management/managementGroups/subscriptions
      • Microsoft.Subscription/subscriptions
  • Policy Definition and Policy Assignment for Governance
    • ResourceTypes:
      • Microsoft.Authorization/policyDefinitions
      • Microsoft.Authorization/policySetDefinitions
      • Microsoft.Authorization/policyAssignments
  • Role Definition and Role Assignment
    • ResourceTypes:
      • Microsoft.Authorization/roleDefinitions
      • Microsoft.Authorization/roleAssignments

How it works

You drop your ARM template(s) and associated parameter file in the folder where you want your resource(s) deployed. For resource groups this will be the folder of the subscription in your Enterprise-scale repo where you want your resource group deployed. For all other resources this will be the folder of the resource group where you want your resources deployed. AzResourceOps searches the azops folder in your Enterprise-scale repo for any new template/parameter pairs, parses the files and creates a new subscription deployment ARM template containing all resources as nested deployments. Do not place your files in the .AzState folders as these will not be searched by AzResourceOps.

The example pipeline azresourceops-push.yml must be set up in your Enterprise-scale repo and all pushes must be done to branches with name starting with deploy/, the pipeline will only trigger when pushes are done to branches starting with this name (unless changed).

If pipeline succeeds, AzResourceOps deletes the deploy/* branch without merging anything to the main branch of your Enterprise-scale repo. This is to avoid cluttering the main repo.

Prerequisites

To start using AzResourceOps you need

  • An existing Enterprise-scale repo setup.
  • A service principal with Contributor permissions on subscriptions where you will deploy resources. You can use the SP already created for Enterprise-scale, for instance.

Getting Started

  • Clone this repository to your organization (currently only tested in Azure DevOps within the same organization as Enterprise-scale repo). The AzResourceOps repo must be possible to checkout from pipeline in your Enterprise-scale repo.
  • Copy file \.azure-pipelines\azresourceops-push.yml to your Enterprise-scale repo.
  • Change azresourceops-push.yml to reflect your environment. ES_REPO_NAME is the name of your Enterprise-scale repo, AZRESOURCEOPS_REPO_NAME is the name of your AzResourceOps repo. The folder in FilePath must be the name of the AzResourceOps repo (same as AZRESOURCEOPS_REPO_NAME). AzResourceOps pipeline YAML
  • Create a new pipeline in Enterprise-scale repo from azresourceops-push.yml.
  • Create a new secret pipeline variable called AZURE_CREDENTIALS containing your service principal.
    {
    "clientId": "xxxx-xxxx-xxxx-xxxx-xxxxx",
    "displayName": "AzOps",
    "name": "http://AzOps",
    "clientSecret": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "tenantId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "subscriptionId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx"
    }

How to use AzResourceOps

AzResourceOps requires a parameter file for each ARM template you wish to deploy. The parameter file has to have the same name as the ARM template with *.parameters.json appendend. I.ex. if you deploy a new Key Vault and the ARM template is called keyVault.json, your parameter file will have to be named keyVault.parameters.json.

Unless changed, the pipeline will trigger by default on push to all branches called deploy/*, where * can be whatever you want.

To deploy a new resource:

  • Make sure to pull latest changes from main.
  • Create a new branch in your Enterprise-scale repo called deploy/whateveryouwanthere.
  • Copy your ARM template(s) and parameter file(s) to the resource group folder where you want to deploy the resources. If the resource group does not exist, you will need to deploy the resource group first (see Limitations).
  • Resource group deployment file(s) will be placed in the folder of the subscription where you want to deploy the resource group(s).

Limitations

  • AzResourceOps is currently only tested in Azure DevOps, not GitHub or any other services.
  • Requires parameter file for all templates.
  • Deployment of resources assume that resource group already exists. You cannot deploy a new resource group and a new resource into the same resource group in the same operation, these deployments will have to be separated.

Contributing

There are probably a lot of scenarios and tests that should be covered and this project welcomes any contributions and suggestions.

More Information

For more information:

About

Bring your own ARM templates to Enterprise-scale.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Latest commit

History

30 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

AzResourceOps

Bring your own ARM templates to Enterprise-scale.

Objectives

This is an IaC module created to be used as an "extension" to Microsoft Enterprise-scale and AzOps. The main focus of this project is to supplement AzOps functionality and allow for deployment of all types of resources from within your Enterprise-scale repo without having to modify the Enterprise-scale code maintained by Microsoft.

The philosophy is that you "bring your own ARM templates" to handle deployment of resources at resource group level.

Scope

AzResourceOps is not meant to replace AzOps functionality. You should still use AzOps to deploy resources within the scope of AzOps, like:

  • Management Group hierarchy and Subscription organization
    • ResourceTypes:
      • Microsoft.Management/managementGroups
      • Microsoft.Management/managementGroups/subscriptions
      • Microsoft.Subscription/subscriptions
  • Policy Definition and Policy Assignment for Governance
    • ResourceTypes:
      • Microsoft.Authorization/policyDefinitions
      • Microsoft.Authorization/policySetDefinitions
      • Microsoft.Authorization/policyAssignments
  • Role Definition and Role Assignment
    • ResourceTypes:
      • Microsoft.Authorization/roleDefinitions
      • Microsoft.Authorization/roleAssignments

How it works

You drop your ARM template(s) and associated parameter file in the folder where you want your resource(s) deployed. For resource groups this will be the folder of the subscription in your Enterprise-scale repo where you want your resource group deployed. For all other resources this will be the folder of the resource group where you want your resources deployed. AzResourceOps searches the azops folder in your Enterprise-scale repo for any new template/parameter pairs, parses the files and creates a new subscription deployment ARM template containing all resources as nested deployments. Do not place your files in the .AzState folders as these will not be searched by AzResourceOps.

The example pipeline azresourceops-push.yml must be set up in your Enterprise-scale repo and all pushes must be done to branches with name starting with deploy/, the pipeline will only trigger when pushes are done to branches starting with this name (unless changed).

If pipeline succeeds, AzResourceOps deletes the deploy/* branch without merging anything to the main branch of your Enterprise-scale repo. This is to avoid cluttering the main repo.

Prerequisites

To start using AzResourceOps you need

  • An existing Enterprise-scale repo setup.
  • A service principal with Contributor permissions on subscriptions where you will deploy resources. You can use the SP already created for Enterprise-scale, for instance.

Getting Started

  • Clone this repository to your organization (currently only tested in Azure DevOps within the same organization as Enterprise-scale repo). The AzResourceOps repo must be possible to checkout from pipeline in your Enterprise-scale repo.
  • Copy file \.azure-pipelines\azresourceops-push.yml to your Enterprise-scale repo.
  • Change azresourceops-push.yml to reflect your environment. ES_REPO_NAME is the name of your Enterprise-scale repo, AZRESOURCEOPS_REPO_NAME is the name of your AzResourceOps repo. The folder in FilePath must be the name of the AzResourceOps repo (same as AZRESOURCEOPS_REPO_NAME). AzResourceOps pipeline YAML
  • Create a new pipeline in Enterprise-scale repo from azresourceops-push.yml.
  • Create a new secret pipeline variable called AZURE_CREDENTIALS containing your service principal.
    {
    "clientId": "xxxx-xxxx-xxxx-xxxx-xxxxx",
    "displayName": "AzOps",
    "name": "http://AzOps",
    "clientSecret": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "tenantId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "subscriptionId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx"
    }

How to use AzResourceOps

AzResourceOps requires a parameter file for each ARM template you wish to deploy. The parameter file has to have the same name as the ARM template with *.parameters.json appendend. I.ex. if you deploy a new Key Vault and the ARM template is called keyVault.json, your parameter file will have to be named keyVault.parameters.json.

Unless changed, the pipeline will trigger by default on push to all branches called deploy/*, where * can be whatever you want.

To deploy a new resource:

  • Make sure to pull latest changes from main.
  • Create a new branch in your Enterprise-scale repo called deploy/whateveryouwanthere.
  • Copy your ARM template(s) and parameter file(s) to the resource group folder where you want to deploy the resources. If the resource group does not exist, you will need to deploy the resource group first (see Limitations).
  • Resource group deployment file(s) will be placed in the folder of the subscription where you want to deploy the resource group(s).

Limitations

  • AzResourceOps is currently only tested in Azure DevOps, not GitHub or any other services.
  • Requires parameter file for all templates.
  • Deployment of resources assume that resource group already exists. You cannot deploy a new resource group and a new resource into the same resource group in the same operation, these deployments will have to be separated.

Contributing

There are probably a lot of scenarios and tests that should be covered and this project welcomes any contributions and suggestions.

More Information

For more information:

About

Bring your own ARM templates to Enterprise-scale.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

30 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

AzResourceOps

Bring your own ARM templates to Enterprise-scale.

Objectives

This is an IaC module created to be used as an "extension" to Microsoft Enterprise-scale and AzOps. The main focus of this project is to supplement AzOps functionality and allow for deployment of all types of resources from within your Enterprise-scale repo without having to modify the Enterprise-scale code maintained by Microsoft.

The philosophy is that you "bring your own ARM templates" to handle deployment of resources at resource group level.

Scope

AzResourceOps is not meant to replace AzOps functionality. You should still use AzOps to deploy resources within the scope of AzOps, like:

  • Management Group hierarchy and Subscription organization
    • ResourceTypes:
      • Microsoft.Management/managementGroups
      • Microsoft.Management/managementGroups/subscriptions
      • Microsoft.Subscription/subscriptions
  • Policy Definition and Policy Assignment for Governance
    • ResourceTypes:
      • Microsoft.Authorization/policyDefinitions
      • Microsoft.Authorization/policySetDefinitions
      • Microsoft.Authorization/policyAssignments
  • Role Definition and Role Assignment
    • ResourceTypes:
      • Microsoft.Authorization/roleDefinitions
      • Microsoft.Authorization/roleAssignments

How it works

You drop your ARM template(s) and associated parameter file in the folder where you want your resource(s) deployed. For resource groups this will be the folder of the subscription in your Enterprise-scale repo where you want your resource group deployed. For all other resources this will be the folder of the resource group where you want your resources deployed. AzResourceOps searches the azops folder in your Enterprise-scale repo for any new template/parameter pairs, parses the files and creates a new subscription deployment ARM template containing all resources as nested deployments. Do not place your files in the .AzState folders as these will not be searched by AzResourceOps.

The example pipeline azresourceops-push.yml must be set up in your Enterprise-scale repo and all pushes must be done to branches with name starting with deploy/, the pipeline will only trigger when pushes are done to branches starting with this name (unless changed).

If pipeline succeeds, AzResourceOps deletes the deploy/* branch without merging anything to the main branch of your Enterprise-scale repo. This is to avoid cluttering the main repo.

Prerequisites

To start using AzResourceOps you need

  • An existing Enterprise-scale repo setup.
  • A service principal with Contributor permissions on subscriptions where you will deploy resources. You can use the SP already created for Enterprise-scale, for instance.

Getting Started

  • Clone this repository to your organization (currently only tested in Azure DevOps within the same organization as Enterprise-scale repo). The AzResourceOps repo must be possible to checkout from pipeline in your Enterprise-scale repo.
  • Copy file \.azure-pipelines\azresourceops-push.yml to your Enterprise-scale repo.
  • Change azresourceops-push.yml to reflect your environment. ES_REPO_NAME is the name of your Enterprise-scale repo, AZRESOURCEOPS_REPO_NAME is the name of your AzResourceOps repo. The folder in FilePath must be the name of the AzResourceOps repo (same as AZRESOURCEOPS_REPO_NAME). AzResourceOps pipeline YAML
  • Create a new pipeline in Enterprise-scale repo from azresourceops-push.yml.
  • Create a new secret pipeline variable called AZURE_CREDENTIALS containing your service principal.
    {
    "clientId": "xxxx-xxxx-xxxx-xxxx-xxxxx",
    "displayName": "AzOps",
    "name": "http://AzOps",
    "clientSecret": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "tenantId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "subscriptionId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx"
    }

How to use AzResourceOps

AzResourceOps requires a parameter file for each ARM template you wish to deploy. The parameter file has to have the same name as the ARM template with *.parameters.json appendend. I.ex. if you deploy a new Key Vault and the ARM template is called keyVault.json, your parameter file will have to be named keyVault.parameters.json.

Unless changed, the pipeline will trigger by default on push to all branches called deploy/*, where * can be whatever you want.

To deploy a new resource:

  • Make sure to pull latest changes from main.
  • Create a new branch in your Enterprise-scale repo called deploy/whateveryouwanthere.
  • Copy your ARM template(s) and parameter file(s) to the resource group folder where you want to deploy the resources. If the resource group does not exist, you will need to deploy the resource group first (see Limitations).
  • Resource group deployment file(s) will be placed in the folder of the subscription where you want to deploy the resource group(s).

Limitations

  • AzResourceOps is currently only tested in Azure DevOps, not GitHub or any other services.
  • Requires parameter file for all templates.
  • Deployment of resources assume that resource group already exists. You cannot deploy a new resource group and a new resource into the same resource group in the same operation, these deployments will have to be separated.

Contributing

There are probably a lot of scenarios and tests that should be covered and this project welcomes any contributions and suggestions.

More Information

For more information:

About

Bring your own ARM templates to Enterprise-scale.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Latest commit

History

30 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

AzResourceOps

Bring your own ARM templates to Enterprise-scale.

Objectives

This is an IaC module created to be used as an "extension" to Microsoft Enterprise-scale and AzOps. The main focus of this project is to supplement AzOps functionality and allow for deployment of all types of resources from within your Enterprise-scale repo without having to modify the Enterprise-scale code maintained by Microsoft.

The philosophy is that you "bring your own ARM templates" to handle deployment of resources at resource group level.

Scope

AzResourceOps is not meant to replace AzOps functionality. You should still use AzOps to deploy resources within the scope of AzOps, like:

  • Management Group hierarchy and Subscription organization
    • ResourceTypes:
      • Microsoft.Management/managementGroups
      • Microsoft.Management/managementGroups/subscriptions
      • Microsoft.Subscription/subscriptions
  • Policy Definition and Policy Assignment for Governance
    • ResourceTypes:
      • Microsoft.Authorization/policyDefinitions
      • Microsoft.Authorization/policySetDefinitions
      • Microsoft.Authorization/policyAssignments
  • Role Definition and Role Assignment
    • ResourceTypes:
      • Microsoft.Authorization/roleDefinitions
      • Microsoft.Authorization/roleAssignments

How it works

You drop your ARM template(s) and associated parameter file in the folder where you want your resource(s) deployed. For resource groups this will be the folder of the subscription in your Enterprise-scale repo where you want your resource group deployed. For all other resources this will be the folder of the resource group where you want your resources deployed. AzResourceOps searches the azops folder in your Enterprise-scale repo for any new template/parameter pairs, parses the files and creates a new subscription deployment ARM template containing all resources as nested deployments. Do not place your files in the .AzState folders as these will not be searched by AzResourceOps.

The example pipeline azresourceops-push.yml must be set up in your Enterprise-scale repo and all pushes must be done to branches with name starting with deploy/, the pipeline will only trigger when pushes are done to branches starting with this name (unless changed).

If pipeline succeeds, AzResourceOps deletes the deploy/* branch without merging anything to the main branch of your Enterprise-scale repo. This is to avoid cluttering the main repo.

Prerequisites

To start using AzResourceOps you need

  • An existing Enterprise-scale repo setup.
  • A service principal with Contributor permissions on subscriptions where you will deploy resources. You can use the SP already created for Enterprise-scale, for instance.

Getting Started

  • Clone this repository to your organization (currently only tested in Azure DevOps within the same organization as Enterprise-scale repo). The AzResourceOps repo must be possible to checkout from pipeline in your Enterprise-scale repo.
  • Copy file \.azure-pipelines\azresourceops-push.yml to your Enterprise-scale repo.
  • Change azresourceops-push.yml to reflect your environment. ES_REPO_NAME is the name of your Enterprise-scale repo, AZRESOURCEOPS_REPO_NAME is the name of your AzResourceOps repo. The folder in FilePath must be the name of the AzResourceOps repo (same as AZRESOURCEOPS_REPO_NAME). AzResourceOps pipeline YAML
  • Create a new pipeline in Enterprise-scale repo from azresourceops-push.yml.
  • Create a new secret pipeline variable called AZURE_CREDENTIALS containing your service principal.
    {
    "clientId": "xxxx-xxxx-xxxx-xxxx-xxxxx",
    "displayName": "AzOps",
    "name": "http://AzOps",
    "clientSecret": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "tenantId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "subscriptionId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx"
    }

How to use AzResourceOps

AzResourceOps requires a parameter file for each ARM template you wish to deploy. The parameter file has to have the same name as the ARM template with *.parameters.json appendend. I.ex. if you deploy a new Key Vault and the ARM template is called keyVault.json, your parameter file will have to be named keyVault.parameters.json.

Unless changed, the pipeline will trigger by default on push to all branches called deploy/*, where * can be whatever you want.

To deploy a new resource:

  • Make sure to pull latest changes from main.
  • Create a new branch in your Enterprise-scale repo called deploy/whateveryouwanthere.
  • Copy your ARM template(s) and parameter file(s) to the resource group folder where you want to deploy the resources. If the resource group does not exist, you will need to deploy the resource group first (see Limitations).
  • Resource group deployment file(s) will be placed in the folder of the subscription where you want to deploy the resource group(s).

Limitations

  • AzResourceOps is currently only tested in Azure DevOps, not GitHub or any other services.
  • Requires parameter file for all templates.
  • Deployment of resources assume that resource group already exists. You cannot deploy a new resource group and a new resource into the same resource group in the same operation, these deployments will have to be separated.

Contributing

There are probably a lot of scenarios and tests that should be covered and this project welcomes any contributions and suggestions.

More Information

For more information:

About

Bring your own ARM templates to Enterprise-scale.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Latest commit

History

30 Commits

Folders and files

NameName
Last commit message
Last commit date

Repository files navigation

AzResourceOps

Bring your own ARM templates to Enterprise-scale.

Objectives

This is an IaC module created to be used as an "extension" to Microsoft Enterprise-scale and AzOps. The main focus of this project is to supplement AzOps functionality and allow for deployment of all types of resources from within your Enterprise-scale repo without having to modify the Enterprise-scale code maintained by Microsoft.

The philosophy is that you "bring your own ARM templates" to handle deployment of resources at resource group level.

Scope

AzResourceOps is not meant to replace AzOps functionality. You should still use AzOps to deploy resources within the scope of AzOps, like:

  • Management Group hierarchy and Subscription organization
    • ResourceTypes:
      • Microsoft.Management/managementGroups
      • Microsoft.Management/managementGroups/subscriptions
      • Microsoft.Subscription/subscriptions
  • Policy Definition and Policy Assignment for Governance
    • ResourceTypes:
      • Microsoft.Authorization/policyDefinitions
      • Microsoft.Authorization/policySetDefinitions
      • Microsoft.Authorization/policyAssignments
  • Role Definition and Role Assignment
    • ResourceTypes:
      • Microsoft.Authorization/roleDefinitions
      • Microsoft.Authorization/roleAssignments

How it works

You drop your ARM template(s) and associated parameter file in the folder where you want your resource(s) deployed. For resource groups this will be the folder of the subscription in your Enterprise-scale repo where you want your resource group deployed. For all other resources this will be the folder of the resource group where you want your resources deployed. AzResourceOps searches the azops folder in your Enterprise-scale repo for any new template/parameter pairs, parses the files and creates a new subscription deployment ARM template containing all resources as nested deployments. Do not place your files in the .AzState folders as these will not be searched by AzResourceOps.

The example pipeline azresourceops-push.yml must be set up in your Enterprise-scale repo and all pushes must be done to branches with name starting with deploy/, the pipeline will only trigger when pushes are done to branches starting with this name (unless changed).

If pipeline succeeds, AzResourceOps deletes the deploy/* branch without merging anything to the main branch of your Enterprise-scale repo. This is to avoid cluttering the main repo.

Prerequisites

To start using AzResourceOps you need

  • An existing Enterprise-scale repo setup.
  • A service principal with Contributor permissions on subscriptions where you will deploy resources. You can use the SP already created for Enterprise-scale, for instance.

Getting Started

  • Clone this repository to your organization (currently only tested in Azure DevOps within the same organization as Enterprise-scale repo). The AzResourceOps repo must be possible to checkout from pipeline in your Enterprise-scale repo.
  • Copy file \.azure-pipelines\azresourceops-push.yml to your Enterprise-scale repo.
  • Change azresourceops-push.yml to reflect your environment. ES_REPO_NAME is the name of your Enterprise-scale repo, AZRESOURCEOPS_REPO_NAME is the name of your AzResourceOps repo. The folder in FilePath must be the name of the AzResourceOps repo (same as AZRESOURCEOPS_REPO_NAME). AzResourceOps pipeline YAML
  • Create a new pipeline in Enterprise-scale repo from azresourceops-push.yml.
  • Create a new secret pipeline variable called AZURE_CREDENTIALS containing your service principal.
    {
    "clientId": "xxxx-xxxx-xxxx-xxxx-xxxxx",
    "displayName": "AzOps",
    "name": "http://AzOps",
    "clientSecret": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "tenantId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx",
    "subscriptionId": "xxxxxx-xxxx-xxxx-xxxx-xxxxxx"
    }

How to use AzResourceOps

AzResourceOps requires a parameter file for each ARM template you wish to deploy. The parameter file has to have the same name as the ARM template with *.parameters.json appendend. I.ex. if you deploy a new Key Vault and the ARM template is called keyVault.json, your parameter file will have to be named keyVault.parameters.json.

Unless changed, the pipeline will trigger by default on push to all branches called deploy/*, where * can be whatever you want.

To deploy a new resource:

  • Make sure to pull latest changes from main.
  • Create a new branch in your Enterprise-scale repo called deploy/whateveryouwanthere.
  • Copy your ARM template(s) and parameter file(s) to the resource group folder where you want to deploy the resources. If the resource group does not exist, you will need to deploy the resource group first (see Limitations).
  • Resource group deployment file(s) will be placed in the folder of the subscription where you want to deploy the resource group(s).

Limitations

  • AzResourceOps is currently only tested in Azure DevOps, not GitHub or any other services.
  • Requires parameter file for all templates.
  • Deployment of resources assume that resource group already exists. You cannot deploy a new resource group and a new resource into the same resource group in the same operation, these deployments will have to be separated.

Contributing

There are probably a lot of scenarios and tests that should be covered and this project welcomes any contributions and suggestions.

More Information

For more information:

About

Bring your own ARM templates to Enterprise-scale.

Topics

Resources

Stars

1 star

Watchers

1 watching

Forks

Contributors

Languages