Telemetry that Is Not Silently Thrown Away
When the daily cap is hit everything after it is discarded until midnight and the dashboard goes flat, and the one email that says so has its own switch. Ingestion sampling stacks on the SDK's sampling and the metrics rescale. Both are refused without being named, and availability tests are created with the alerts that make an outage reach a person rather than a chart.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "application_insights" {
source = "www.iac-bazaar.com/iac-bazaar/azure-application-insights/azure"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
azure-application-insights
An Application Insights resource whose telemetry is not silently thrown away.
Works with Terraform and OpenTofu (>= 1.6), azurerm provider
>= 4.0, < 5.0.
The daily cap drops data and the dashboard just goes flat. When ingestion
reaches daily_data_cap_in_gb, everything after it is discarded until
midnight UTC - not queued, discarded. Dashboards show a flat line that reads
as a quiet afternoon, and the one email that says otherwise is controlled by
daily_data_cap_notifications_enabled. On by default here; off needs
accept_silent_cap.
Ingestion sampling stacks on top of SDK sampling. sampling_percentage
is applied by the service after the SDK's adaptive sampling has already run,
and the metrics rescale so nothing looks wrong. Default 100; lower needs
accept_sampling.
The instrumentation key is not a secret. It ships in browser JavaScript,
and with local_authentication_enabled anyone who has seen it can write
telemetry into your resource. Server SDKs can use Entra ID instead; browser
SDKs cannot. key_is_enough_to_write reports which you have.
An instance with no availability test never notices the site is down. It
records what the application reports, and an application that is not running
reports nothing. Tests are created here with their alerts, and tests without
an action group are refused unless accept_unalerted_tests.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
azure-grafana
API keys are long-lived, unscoped bearer tokens that read every dashboard and end up in CI variables; the login page is public by default; and the Essential SKU is a single instance with no SLA. Keys off, login over a private endpoint, Standard SKU zone-redundant, fixed outbound addresses for data-source allow lists, and the identity it reads with exported for its Monitoring Reader grant.
azure-sentinel
retention_in_days defaults to 30, against intrusions usually discovered months later - so the first question, when did this start, gets silence rather than an answer. daily_quota_gb is a trap both ways and has no safe default, so the module makes you choose. And onboarding Sentinel connects no data source at all.
azure-monitor-baseline
Central Log Analytics workspace, diagnostic-settings-everywhere pattern, action groups and starter alert pack (metric + log + activity).
azure-flow-logs
enabled = false creates a flow log that logs nothing; a retention policy that is off keeps the JSON blobs until somebody deletes the storage account; and without Traffic Analytics nobody ever opens them. Every target is created enabled, retention defaults to 90 days, and Traffic Analytics is on whenever a workspace is given - raw blobs with no aggregation have to be asked for.