An ML Workspace that Is Private, Isolated and Encrypted with Your Key
The workspace endpoint is public by default, and the managed network compute runs in defaults to Disabled isolation - unrestricted outbound internet from a network that holds training data. Private workspace, outbound isolation on, high-business-impact flag set so less leaves for Microsoft, identity-based storage access, and a customer-managed key; the four dependencies stay yours.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "machine_learning" {
source = "www.iac-bazaar.com/iac-bazaar/azure-machine-learning/azure"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
azure-machine-learning
A Machine Learning workspace that is private, isolated, and encrypted with
your key. Works with Terraform and OpenTofu (>= 1.6), azurerm provider
>= 4.0, < 5.0.
public_network_access_enabled defaults to true. Off here; on needs
accept_public_workspace.
managed_network.isolation_mode defaults to Disabled, which gives
compute and serverless endpoints unrestricted outbound internet access from
a network that holds training data. AllowInternetOutbound by default here;
Disabled needs accept_unrestricted_outbound.
high_business_impact reduces the diagnostic data Microsoft collects;
on here.
The four dependencies are yours - storage, key vault, App Insights, registry - so their network rules and keys are decided where the rest of your data lives.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage