Azure Infrastructure-as-Code modules
85 verified ansible / terraform modules for Azure, spanning Azure, Cloud Tooling. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.
38 of 85 Azure modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 47 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.
All Azure modules
azure-b2c
An Azure AD B2C tenant created where its customer directory should live, on PremiumP1 or P2, linked to the subscription that pays per monthly active user. Data residency and the onmicrosoft.com name are chosen once and cannot change; user flows, policies and app registrations are configured inside the tenant with an azuread provider pointed at the exported tenant ID.
azure-budget
Azure requires a notification block, which makes the problem look solved: a notification can be created disabled, and contact_roles = Owner emails whoever holds the role, which is often a service principal with no mailbox. Insists on an enabled notification with a real address or action group, and on a Forecasted threshold so the first message arrives while there is still a month to act.
azure-chaos-studio
Chaos Studio has no stop condition: an experiment runs for its actions' duration or until somebody presses Stop, so the duration is the only guardrail and every action here is capped. The experiment acts as its own identity and fails safely without a role on each target; every fault it can inject is a capability somebody enabled on an onboarded target, so the scope cannot quietly widen.
azure-ddos-protection-plan
The plan is a fixed monthly charge of roughly three thousand dollars from the moment it exists, attached VNets or not; it protects only the VNets that reference it; and DDoS IP Protection on the addresses themselves is an order of magnitude cheaper for a handful. The charge accepted by name before the plan is created, the plan ID exported for azure-vnet, an output that says it bills unattached.
azure-data-factory
The managed virtual network cannot be turned on after creation, and without it the integration runtime that copies your data reaches every source over public endpoints; the studio endpoint is public by default; and a factory with no git repository keeps its pipelines only in the service, with no review. Managed VNet on, studio private, git required, Key Vault linked for secrets.
azure-database-migration
An Azure Database Migration Service instance placed in a subnet that must reach both source and target, on the Premium SKU that runs online migrations with continuous sync so a cutover is minutes (the Standard tiers are offline), with a migration project per source and target pair from a map. Tasks and credentials are supplied when a migration runs, not here.
azure-databricks
The default deployment puts the clusters in a managed network you cannot see with a public IP per node, and the workspace URL - notebooks, jobs, tokens - is reachable from the internet. VNet injection into your subnets with no public IPs, the workspace endpoint off the internet, and one Key Vault key wired to all four encryption settings including the DBFS root, a separate resource.
azure-file-share
A share inherits its security boundary from the storage account, which defaults to public access and TLS 1.0; the quota is the price on premium; and a share is backed up only when a Recovery Services vault protects it through a policy and an assignment. A private account with TLS 1.2, the quota deliberate, share soft delete on, vault, policy and protection created together (none by name).
azure-firewall
Every security feature on this service defaults to telling you, not to stopping it: threat_intelligence_mode defaults to Alert, which logs traffic to known-malicious destinations and forwards it, and intrusion detection does the same. Deny for both here, with the DNS proxy on so FQDN rules and the client agree on an answer.
azure-managed-certificate
A free App Service managed certificate for a custom subdomain, with its hostname binding, the SNI binding that puts it to use, and optionally the DNS records. Microsoft blocks issuance and renewal when the CNAME passes through anything before the app, so the module writes the direct record and refuses the wildcards, apex names and long hostnames the product does not support.
azure-grafana
API keys are long-lived, unscoped bearer tokens that read every dashboard and end up in CI variables; the login page is public by default; and the Essential SKU is a single instance with no SLA. Keys off, login over a private endpoint, Standard SKU zone-redundant, fixed outbound addresses for data-source allow lists, and the identity it reads with exported for its Monitoring Reader grant.
azure-data-explorer
The Dev(No SLA) SKUs say it in the name and are what a proof of concept becomes production on; public network access is on by default; disk and double encryption are off by default and set only at creation. Standard SKU with two instances across zones, private endpoints, both encryption layers on, a customer-managed key, and purge enabled because it is the only way to honour an erasure request.
azure-entra-domain-services
Microsoft Entra Domain Services with NTLM v1, TLS 1.0 and RC4 off and Kerberos armoring on, the WinRM network security group the service insists on, the AAD DC Administrators group with the members you name, and the Domain Controller Services principal registered, all of which fail late when missing. Notifications go to the admins; filtered sync and LDAPS are inputs.
azure-managed-disk
A managed disk's export SAS works from anywhere until public access is off; your key is a disk encryption set nobody creates; and Azure Backup for disks is a vault, a policy and an instance, where the instance is the assignment most vaults lack. Public export closed, the encryption set taken when given, and vault, policy, role assignments and backup instance created together (none by name).
azure-sql-managed-instance
The public data endpoint turns a private database into one listening on the internet on port 3342; SQL logins put an administrator password in state when Entra-only authentication would remove them entirely; and zone redundancy is off by default. Private, Entra-only with SQL authentication accepted by name, Business Critical across zones, TLS 1.2, and geo-zone-redundant backups.
azure-cognitive-services
custom_subdomain_name looks cosmetic and decides everything: without it Entra ID auth does not work and no private endpoint can attach, so the account is silently key-only and public - and it is ForceNew. Restricting outbound access is the data-loss-prevention control for an OpenAI account.
azure-update-manager
A maintenance configuration is a schedule and a filter; a machine follows it only through an assignment, and one with no assignment appears scheduled and touches no host. reboot Never installs the kernel and runs the old one; a VM on image-default patching is assigned and skipped. Machines or a dynamic scope come with it; IfRequired reboots; the patch mode every VM needs is an output.
azure-policy
enforce = false is Azure DoNotEnforce: the assignment appears, resources are evaluated, a compliance percentage is charted - and every violating resource is created anyway. From the portal compliance view that is indistinguishable from an enforced policy. Also refuses a silent not_scopes exclusion and an unexplained denial.
azure-powerbi-embedded
A Power BI Embedded Gen2 capacity with the administrators who may assign workspaces named (required), in the size you chose with no default because the capacity bills by the hour from creation whether a report is rendered or not. Workspaces are assigned to the capacity in Power BI, which is an admin action outside the module.
azure-purview
A Microsoft Purview account for the data map with public network access off, the managed Event Hub that bills monthly whether used or not turned off, a system identity, and Storage Blob Data Reader granted to that identity on every storage account it will scan, since a scan fails otherwise. The account bills for data map capacity from creation; public access is accepted by name.
azure-dns-private-resolver
A resolver is five resources - endpoints, ruleset, rules and VNet links - and the half-built state most sit in resolves Azure names and forwards nothing to on-premises; a ruleset not linked to a VNet applies to nothing; and each endpoint needs its own delegated subnet. All five created, forwarding rules required, VNet links expected (none by name), the inbound address exported.
azure-sentinel
retention_in_days defaults to 30, against intrusions usually discovered months later - so the first question, when did this start, gets silence rather than an answer. daily_quota_gb is a trap both ways and has no safe default, so the module makes you choose. And onboarding Sentinel connects no data source at all.
azure-search-service
One replica - the default - is excluded from the availability SLA; the admin key, on by default, reads and writes every index and is revoked only by regenerating it for everyone; and the query endpoint is public by default. Three replicas, Entra ID only, private endpoint, 0.0.0.0/0 refused in the allow list, and optional enforcement that refuses an index without a customer-managed key.
azure-vpn-gateway
A connection with no ipsec_policy negotiates from a built-in list that still offers 1024-bit Diffie-Hellman and SHA-1, so a peer that proposes them gets them and the tunnel comes up looking healthy. Always writes an explicit policy and refuses the weak groups. A gateway with no connection bills by the hour for nothing, so the sites come with the gateway; BGP is on, Basic is refused.
azure-app-configuration
local_auth_enabled defaults true and the keys carry no identity: a read key reads every value, cannot be scoped, and is revoked only by regenerating it for everybody. Purge protection defaults off, and purging frees the name - which frees the endpoint your applications trust.
azure-synapse
A Synapse workspace with a dedicated SQL pool and no SQL login: Entra-only authentication with a group as admin, a managed virtual network with data exfiltration protection (neither can be turned on later), public endpoints off, extended auditing and threat detection on the workspace and the pool, and vulnerability scans when you name a container. The pool bills by the hour while online.
azure-virtual-wan
A hub is billed from the moment it exists and routes nothing until something connects; disable_vpn_encryption sends branch traffic in clear; and a VNet connection without internet security sends 0.0.0.0/0 out its own default route, bypassing the hub firewall. Connections come with it, branch encryption stays on, every connection routes the internet through the hub, and the prefix must be a /23.
azure-waf-policy
Detection mode evaluates every rule, logs every match and forwards every request - the dashboard fills with blocked-looking entries while the backend receives them all. Prevention by default, Detection only by name. A policy attached to no listener protects nothing, so the attached listeners are an output; every exclusion is a hole and has to carry a reason.
azure-api-management
An API Management gateway tuned for the serverless Consumption tier - scale-to-zero, billed per call - with a system-assigned managed identity, TLS hardening, and HTTP/2 enabled.
azure-expressroute
A provider circuit is a clear-text path across the provider's network - MACsec is for Direct ports only, and IPsec over the private peering is yours to build - so the module requires that to be stated and exports encrypted = false. The SKU tier decides where the circuit reaches; a circuit with no peering carries nothing once provisioned. Private peering with its /30 pairs and VLAN is created here.
azure-hdinsight-spark
An HDInsight Spark cluster in your virtual network, reached over a private link, on ADLS Gen2 through a user-assigned identity so no storage key sits in state, with encryption in transit and TLS 1.2 on the gateway. There is no scale-to-zero: nodes_at_rest says what bills when the cluster idles. An external Hive metastore makes the cluster disposable; the public gateway is accepted by name.
azure-iot-hub
Shared access keys are symmetric credentials that grant everything their policy names and are revoked only by regeneration; the endpoint is public by default; telemetry that matches no route is dropped when the fallback route is off; and the built-in endpoint keeps one day. Keys off, private endpoints, TLS 1.2, the fallback route on so unrouted telemetry lands, and seven days of retention.
azure-machine-learning
The workspace endpoint is public by default, and the managed network compute runs in defaults to Disabled isolation - unrestricted outbound internet from a network that holds training data. Private workspace, outbound isolation on, high-business-impact flag set so less leaves for Microsoft, identity-based storage access, and a customer-managed key; the four dependencies stay yours.
azure-storage-mover
Azure Storage Mover from an NFS share to a blob container: the mover, project, endpoints and job definition, with the agent registered from its Arc machine and granted Storage Blob Data Contributor when its IDs are given. Additive copy mode; Mirror, which deletes at the target what the source no longer has, is accepted by name. The run itself is started outside Terraform.
azure-network-security-group
Every NSG carries default rules nobody wrote; a group with no subnet or NIC association is a rule set in the portal that filters nothing; and SSH and RDP from Internet are the first rules the portal offers. Your allows in priority order with an explicit DenyAllInbound at 4000, subnets associated by the module (none by name), 22 and 3389 from Internet refused unless accepted.
azure-application-gateway
Regional L7 load balancer with WAF v2 policy, TLS termination from Key Vault, autoscaling and health probes.
azure-app-service
App Service plan + Linux web app with deployment slots, custom domain + managed TLS, VNet integration and autoscale.
azure-bastion-jumpbox
Bastion (Developer/Basic/Standard SKU) with optional hardened Linux VM, JIT-style NSG rules and boot diagnostics for secure VM access without public IPs.
ansible-azure-cli
The Azure CLI on EL 10 from Microsoft's rhel/10/prod repository, signed by the 2025 key: the key in most guides carries SHA-1 signatures and fails the GPG check, and the repository in most guides tops out at a 2022 build. Pinned, telemetry and the survey prompt off for every login shell; the live test asserts the SHA-1 key was never imported. Original role, live-tested on Rocky Linux 10.
azure-redis-cache
Azure Cache for Redis done cheap by default - the Basic C0 tier with TLS 1.2 minimum and the non-SSL port disabled - scaling cleanly up to Standard and Premium via precondition-guarded inputs.
azure-container-apps
Container Apps environment with workload profiles, Dapr, KEDA scale rules, ACR pull identity and custom domain.
azure-container-instances
Runs one or more containers on Azure Container Instances without VMs or an orchestrator - secure by default with no privileged containers, redacted secret fields, and an optional managed identity.
azure-acr
ACR with geo-replication, retention/trust policies, private endpoint and AcrPull role wiring for AKS/Container Apps.
azure-cosmos-db
Cosmos DB (NoSQL or MongoDB API) with multi-region failover, autoscale throughput, private endpoint and backup policy.
azure-devops
Bootstraps an Azure DevOps project with an initialized Git repository and a YAML build pipeline - repeatable team setup as code.
azure-front-door
Global entry point: Front Door profile, endpoints, origin groups, custom domains with managed TLS and WAF policy.
azure-functions
Function app (Flex Consumption or Premium) with storage, Application Insights, managed identity and VNet integration.
azure-key-vault
RBAC-mode Key Vault with private endpoint, diagnostics, and managed keys/secrets/certificates scaffolding.
azure-aks
Hardened AKS with system/user node pools, workload identity, Entra RBAC integration, Azure CNI overlay, and Container Insights wired in.
azure-landing-zone-core
Management-group hierarchy, policy baseline (ALZ-aligned), centralized logging and RBAC scaffolding - the flagship enterprise starter.
azure-vmss
A self-contained Linux VM Scale Set (Uniform orchestration) on Azure - one apply creates the resource group, VNet, subnet, NSG and an SSH-key-only scale set with deny-all-inbound and no public IPs.
azure-virtual-machine
A fully self-contained general-purpose Linux VM on Azure - one apply creates the resource group, VNet, subnet, NSG, NIC, optional public IP and an SSH-key-only VM with a system-assigned identity.
azure-monitor-baseline
Central Log Analytics workspace, diagnostic-settings-everywhere pattern, action groups and starter alert pack (metric + log + activity).
azure-private-dns
A self-contained Azure Private DNS zone with virtual-network links and optional record sets for private name resolution across VNets and Private Endpoints - VM auto-registration off by default.
azure-private-endpoint
An Azure Private Endpoint giving a target PaaS resource a private IP inside your VNet so traffic stays on the Microsoft backbone - wire to existing subnet/target or run fully self-contained.
azure-dns-zone
An Azure public DNS zone plus a map-driven set of record sets - A, AAAA, CNAME, TXT, MX, NS, CAA and SRV - with relative naming, verbatim TXT values, and apex footgun guards.
azure-sql-database
Logical SQL server + database with Entra-only auth, firewall/private endpoint, auditing, TDE and failover-group option.
azure-load-balancer
An Azure Standard L4 load balancer with a self-created static public IP frontend, a backend address pool, health probes and load-balancing rules - Standard SKU throughout.
azure-static-web-app
Globally distributed hosting for static sites and SPAs on Azure Static Web Apps with optional serverless APIs, free auto-renewing TLS, and a built-in global CDN - defaulting to the cost-free Free SKU.
azure-storage-account
Storage account with containers/file shares, lifecycle rules, network rules, CMK encryption and private endpoint options - Azure's most-deployed resource done right.
azure-traffic-manager
Global, DNS-based load balancing with a Traffic Manager profile and map-driven external endpoints - Performance, Priority, Weighted, Geographic, Subnet or MultiValue routing with an HTTPS health probe.
azure-vnet
Production VNet with subnets, NSGs, route tables, peering and optional NAT Gateway - the network backbone every Azure deployment starts with.
ansible-kubelogin
kubelogin on EL 10 from the GitHub release, get_url refuses it unless its SHA-256 is the vendor's per-file .sha256, and the live test re-checks it, then converts an azure auth-provider kubeconfig into an exec block and runs get-token until it needs the Azure CLI. Pinned. Original role, live-tested on Rocky Linux 10.
azure-backup
Soft delete covers deletion; it does not cover somebody shortening a retention policy so every backup ages out on its own - which deletes nothing, so no soft-delete window opens. immutability is the control that refuses that edit, and it defaults to Disabled. Locked is irreversible and gets its own acknowledgement.
azure-vnet-peering
Both halves of a hub-and-spoke VNet peering in one apply, since one half alone sits in Initiated and carries nothing. hub_has_gateway writes allow_gateway_transit on the hub and use_remote_gateways on the spoke, in the order Azure requires; forwarded traffic is on for both halves because a hub firewall forwards by definition. One subscription; both directions bill per gigabyte.
azure-defender-for-cloud
A subscription with no Defender plan still has a full Defender for Cloud page: a Secure Score, hundreds of recommendations, a compliance dashboard - and not one threat detection, because those come from the paid plans, each Off until somebody turns it on. Sets Standard per resource type, always creates the security contact, and defaults alert notifications on.
azure-nat-gateway
Default outbound access is retired, so a subnet with no NAT gateway has no internet at all and fails as a timeout rather than an error. Each public IP gives 64,512 SNAT ports held for the whole idle timeout; exceed that and connections fail intermittently in a way that looks like the remote service being flaky.
azure-communication-email
Azure Communication Services email from your own domain: the email service, the domain with the DNS records to publish exported, sender addresses as a map, and the Communication Services resource that sends. CustomerManaged rather than the random azurecomm.net subdomain (accepted by name), engagement tracking off, and the key-based connection string sensitive; managed identity is the better path.
azure-entra-id-baseline
App registrations, service principals, groups and federated credentials (OIDC for GitHub/Terraform) - the identity plumbing every Azure org rebuilds by hand.
azure-event-grid
An Event Grid custom topic plus event subscriptions with an optional in-module Storage Queue target - SAS auth off (Entra ID), a system-assigned identity, and HTTPS-only TLS 1.2+ storage.
azure-event-hubs
An Event Hubs namespace plus hubs, each with consumer groups and least-privilege SAS rules for high-throughput (Kafka-compatible) ingestion - TLS 1.2 floor and optional default-deny networking.
azure-flow-logs
enabled = false creates a flow log that logs nothing; a retention policy that is off keeps the JSON blobs until somebody deletes the storage account; and without Traffic Analytics nobody ever opens them. Every target is created enabled, retention defaults to 90 days, and Traffic Analytics is on whenever a workspace is given - raw blobs with no aggregation have to be asked for.
azure-image-gallery
Community sharing publishes every image version to every Azure customer, unauthenticated, with your publisher email attached; trusted launch supported means a VM may boot without Secure Boot, and an image with no end-of-life date is a 2021 build still being deployed. Private by default, trusted launch required on every definition, an end-of-life date on each, and Hyper-V generation 2 throughout.
azure-jenkins
Self-hosted Jenkins on a hardened Azure Linux VM - self-contained vnet/subnet/NSG, SSH-key auth only, managed-disk encryption, Jenkins installed via cloud-init.
azure-logic-app
An Azure Logic App (Consumption) workflow with a built-in Recurrence trigger - serverless pay-per-execution automation with a system-assigned managed identity and inbound IP allowlists.
azure-managed-lustre
Azure Managed Lustre with the blob containers that make the data outlive the file system, root squash naming the clients that keep root, a customer-managed key through a user-assigned identity, and the capacity checked against the SKU's step before the plan. No blob integration, root on every client and the platform key are each accepted by name; the file system is zonal.
azure-mysql-flexible
Azure Database for MySQL Flexible Server with TLS required by default, correct delegated-subnet + private DNS zone ordering, an Entra administrator, databases, and cheapest-by-default Burstable sizing.
azure-postgresql-flexible
Flexible Server with HA option, private VNet delegation, Entra auth, firewall and tuned server parameters.
azure-pim
Azure defaults for an activation policy require MFA and a justification and no approval, so an eligible Owner activates alone at 3am with the reason fix; and eligibility itself is permanent unless somebody sets an end date. Manages the role policy per scope with approval required for Owner-class roles, gives every eligible assignment an expiry, and time-boxes the active ones kept for break-glass.
azure-resource-group-baseline
Opinionated resource group factory with CAF-compliant naming, mandatory tags, locks and budget alert.
azure-service-bus
An Azure Service Bus namespace with queues, topics and subscriptions on the Standard SKU - SAS local auth off (Entra ID + RBAC), TLS 1.2+ minimum, and dead-lettering of expired messages.
azure-application-insights
When the daily cap is hit everything after it is discarded until midnight and the dashboard goes flat, and the one email that says so has its own switch. Ingestion sampling stacks on the SDK's sampling and the metrics rescale. Both are refused without being named, and availability tests are created with the alerts that make an outage reach a person rather than a chart.
azure-activity-log
The subscription's Activity Log exported to a Log Analytics workspace, a storage account and/or an Event Hub, because Azure keeps it for ninety days and then forgets. All eight categories go; dropping Administrative, Security or Policy, the three an investigation asks for, is accepted by name. The workspace's retention is the workspace's setting; the years live in the storage account.
azure-uptime-check
Application Insights Standard tests with the metric alert that makes them tell somebody. Microsoft says a test without an alert rule only notifies the portal, recommends five locations and alerting at locations minus two, and retires URL ping tests on 30 September 2026. The module follows all three, checks certificate lifetime, and lets content, not only a 200, decide what up means.
azure-managed-identity
A map-driven module creating one or many user-assigned managed identities, each with optional workload identity federation (OIDC) and least-privilege RBAC role assignments - no secrets to rotate.
Azure reference architectures
All stacks →Curated stacks of these verified modules, in the order they wire together.
Compare across clouds
All solutions →See how the services Azure covers here compare on other providers.