Andrew Wilson's Blog

{ ... Plan - Architect - Develop - Reflect - Improve - Repeat ... }

Azure Key Vault, Terraform, and the Control Plane/Data Plane Difference

The other day I ran into one of those Azure deployment problems that looks reasonable right up until you understand which service is actually making the call.

I had provisioned an Azure Key Vault with enabled_for_template_deployment set to true. I was familiar with this setting from working with …


Role Assignments | Role Based Access Control Administrator

Problem Space

When deploying Azure solutions with Infrastructure as Code, we often create role assignments as part of the deployment. For example, a Bicep deployment may give a Function App’s managed identity access to a Key Vault, storage account, or Service Bus namespace.

It is easy to focus …


Azure Logic Apps Standard | Keep WEBSITE_CONTENTSHARE Unique

Overview

WEBSITE_CONTENTSHARE is an app setting used by Azure Functions and Logic Apps Standard (which runs on the Functions runtime) alongside WEBSITE_CONTENTAZUREFILECONNECTIONSTRING to identify the Azure Files share the app uses for its content.

The important thing to call out up front: you …


Azure Logic Apps Standard | Testing Series

Over the last few years, Azure Logic Apps Standard has become a core building block for many integration workloads. The platform gives us flexibility, connector richness, and scalable runtime options, but as workflow solutions grow, so does the risk profile.

In many teams, validation still leans …


Unit Testing Bicep Logic with BicepConsoleTTK

Problem Space

In most Infrastructure as Code teams, Bicep quality checks start to look mature as soon as linting and deployment validation are in place. In practice, there is still a blind spot: logic-level testing of exported functions, types, and variables.

Most teams validate by deploying to a …