Andrew Wilson's Blog

{ ... Plan - Architect - Develop - Reflect - Improve - Repeat ... }

Azure Key Vault, Terraform, and the Control Plane/Data Plane Difference

The other day I ran into one of those Azure deployment problems that looks reasonable right up until you understand which service is actually making the call.

I had provisioned an Azure Key Vault with enabled_for_template_deployment set to true. I was familiar with this setting from working with …


Role Assignments | Role Based Access Control Administrator

Problem Space

When deploying Azure solutions with Infrastructure as Code, we often create role assignments as part of the deployment. For example, a Bicep deployment may give a Function App’s managed identity access to a Key Vault, storage account, or Service Bus namespace.

It is easy to focus …


Bicep Tips and Tricks | #11 | Working with Role Assignments

Problem Space

Role assignments are one of those areas in Azure that look simple on the surface, but can become awkward pretty quickly once you start automating them properly.

Anyone who has worked with RBAC through IaC for long enough will usually run into the same set of problems.

There are usually …


Unit Testing Bicep Logic with BicepConsoleTTK

Problem Space

In most Infrastructure as Code teams, Bicep quality checks start to look mature as soon as linting and deployment validation are in place. In practice, there is still a blind spot: logic-level testing of exported functions, types, and variables.

Most teams validate by deploying to a …


Azure Key Vault | Access Policies Removed On Deployment


⚠️ NOTE

Microsoft guidance is clear that Azure RBAC should be used for data plane authorization moving forward, instead of legacy access policies