Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 10 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,5 +7,14 @@ Infrastructure as code for homelab ingress Azure deployments
Service principal is created at subscription-level scope for bootstrapping
Azure resources. Authentication is set up via a federated identity credential.

- [Service Principal (spn-gh-actions-deploy)](https://portal.azure.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/efc8dd45-b094-4d96-bc95-cc56d49e6b20/appId/26532c64-b438-4b0f-85b4-8d6e9ffea5f4)
Creating the initial service principal:

```
az ad sp create-for-rbac \
--name spn-gh-actions-vm \
--role Contributor \
--scopes /subscriptions/<SUBCRIPTION_ID>
```

- [Azure Login OIDC Docs](https://learn.microsoft.com/en-us/azure/developer/github/connect-from-azure-openid-connect)
- [Service Principal (spn-gh-actions-deploy)](https://portal.azure.com/#view/Microsoft_AAD_IAM/ManagedAppMenuBlade/~/Overview/objectId/efc8dd45-b094-4d96-bc95-cc56d49e6b20/appId/26532c64-b438-4b0f-85b4-8d6e9ffea5f4)
26 changes: 11 additions & 15 deletions bicep/deploy.bicep
Original file line number Diff line number Diff line change
Expand Up @@ -4,14 +4,8 @@ targetScope = 'subscription'
@description('initial admin password for the vm')
param edge_vm_admin_password string

@description('name of the user assigned managed id for the vm')
param edge_vm_managed_id_name string

@description('name of the vm resource group')
param edge_vm_resource_group_name string

@description('name of the dns resource group')
param dns_resource_group_name string
@description('suffix to use for resource names')
param resource_name_suffix string

@description('name of the key vault resource')
param key_vault_name string
Expand All @@ -22,17 +16,19 @@ param tailscale_auth_vault_key string
@description('project tags')
param tags object

var raw = loadTextContent('./templates/cloud-init.yml')
var raw2 = replace(raw, '<PLACEHOLDER_TS_VAULT_NAME>', key_vault_name)
// replace placeholder values in the cloud-init template
var raw1 = loadTextContent('./templates/cloud-init.yml')
var raw2 = replace(raw1, '<PLACEHOLDER_TS_VAULT_NAME>', key_vault_name)
var cloud_init_data = replace(raw2,'<PLACEHOLDER_TS_VAULT_KEY>', tailscale_auth_vault_key)

module edge_vm './modules/machine/main.bicep' = {
name: '${edge_vm_resource_group_name}-deployment'
scope: resourceGroup(edge_vm_resource_group_name)
name: 'rg-vm-${resource_name_suffix}-deployment'
scope: resourceGroup('rg-vm-${resource_name_suffix}')
params: {
admin_username: 'ppanda'
admin_password: edge_vm_admin_password
managed_id_name: edge_vm_managed_id_name
managed_id_name: 'mi-${resource_name_suffix}'
name_suffix: resource_name_suffix
cloud_init_data: cloud_init_data
subnet_cidr: '10.0.0.0/24'
vm_size: 'Standard_B2s'
Expand All @@ -42,8 +38,8 @@ module edge_vm './modules/machine/main.bicep' = {
}

module dns './modules/dns/main.bicep' = {
name: '${dns_resource_group_name}-deployment'
scope: resourceGroup(dns_resource_group_name)
name: 'rg-dns-${resource_name_suffix}-deployment'
scope: resourceGroup('rg-dns-${resource_name_suffix}')
params: {
edge_vm_public_ip: edge_vm.outputs.edge_vm_public_ip
dns_zone_primary_name: 'ppanda.org'
Expand Down
20 changes: 7 additions & 13 deletions bicep/init.bicep
Original file line number Diff line number Diff line change
@@ -1,13 +1,7 @@
targetScope = 'subscription'

@description('name of the vm managed id')
param edge_vm_managed_id_name string

@description('name of the vm resource group')
param edge_vm_resource_group_name string

@description('name of the dns resource group')
param dns_resource_group_name string
@description('suffix to use for resource names')
param resource_name_suffix string

@description('name of the key vault resource')
param key_vault_name string
Expand All @@ -24,19 +18,19 @@ module resource_groups './modules/misc/rg.bicep' = {
params: {
location: deployment().location
rg_names:[
dns_resource_group_name
edge_vm_resource_group_name
'rg-dns-${resource_name_suffix}'
'rg-vm-${resource_name_suffix}'
]
tags: tags
}
}

module key_vault './modules/misc/kv.bicep' = {
name: '${edge_vm_resource_group_name}-key-vault-deployment'
scope: resourceGroup(edge_vm_resource_group_name)
name: 'rg-vm-${resource_name_suffix}-kv-deployment'
scope: resourceGroup('rg-vm-${resource_name_suffix}')
params: {
key_vault_name: key_vault_name
managed_id_name: edge_vm_managed_id_name
managed_id_name: 'mi-${resource_name_suffix}'
ci_service_principal_object_id: ci_service_principal_object_id
tags: tags
}
Expand Down
2 changes: 1 addition & 1 deletion bicep/modules/machine/main.bicep
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
@description('suffix for the vm resource names')
param name_suffix string = 'edge-pub-${resourceGroup().location}'
param name_suffix string

@description('admin username for the vm')
param admin_username string
Expand Down
12 changes: 3 additions & 9 deletions bicep/templates/params.shared.json
Original file line number Diff line number Diff line change
@@ -1,17 +1,11 @@
{
"edge_vm_managed_id_name": {
"value": "mi-edge-pub-westus"
},
"edge_vm_resource_group_name": {
"value": "rg-edge-pub-westus"
},
"dns_resource_group_name": {
"value": "rg-dns-pub-westus"
"resource_name_suffix": {
"value": "edge-prod-westus"
},
"tags": {
"value": {
"deployment_type": "automated",
"environment": "public",
"environment": "production",
"project": "homelab",
"purpose": "public-ingress"
}
Expand Down