Saturday, September 29, 2018

Azure Blueprints: First Steps

In a previous post I described one of the newest features to the Azure Governance toolset: Blueprints.  In this post, I will walk through creating a simple blueprint from the portal.  If you looking for the official documentation, click here.

The goal is to use blueprints to model out what I would like my "production" environment to look like.  In this post, we will focus only on creating relevant resource groups that I require in all my environment.  There is one per-requisite that you will need to have in place, and that is Azure Management Groups.  Without them, you will not be able to assign your blueprint.

From the portal, you will want to navigate to blueprints from the All Services menu.  The main screen looks something like this.



After that, click on create under the Create A Blueprint heading.  The first two boxes on this screen are simple, and allow you name your blueprint and provide a detailed description for future reference.



The third box above asks for the definition location.  This is where Azure management groups comes in.  One of the features of Azure Blueprints is that instead of being a definition file that lives in source control (or on someones computer, or in someones head), this document is actually stored inside the management group hierarchy.  In my case, I just selected the root of my Azure Management hierarchy, in order to make this blueprint available to all nodes below.  (Just to make it easy for now).

One you have all that figured out, you will be taken to a screen that allows you to add artifacts.





Clicking on Add Artifact will pop up a side bar.  Select Resource Group as the Artifact Type.  In this example, I'm going to use a static parameter for the name (to enforce consistency) but use a dynamic parameter for the location.  To learn more about blueprint parameters, see this document.  Here is what your artifact list should look like when complete.



In the above diagram:

prodsharedservices:  Resource group for shared services such as Active directory deployments.
prodnetwork:  Resource group for networking components (VNETs, gateways, etc)
prodsecuritygroups:  Resource group for firewalls, and app/network security groups

After you have that set up, click on the Save Draft button at the bottom.  After the blueprint has saved, you should see it show up in the Blueprint Definitions tab.


In order to deploy this template to my subscription, there are two additional steps that are required.  The first is to publish the template.  You can do this by clicking on the template in the screen above and selecting Publish Blueprint.  It will ask you for a version.



When you have selected a good enough name (and put in some lengthy change notes) click on Publish at the bottom. Now that the blueprint is published, we can assign it to a scope.  This is done by navigating back to the blueprint, and selecting Assign Blueprint.

If you remember from above, one of the parameters (the name) was statically set in the template.  The other (the location) was left to be specified at assignment time.  We will now have to enter in the location.  Here is what that page looks like.



After filling out the required data, click on Assign.  Voila, we have now have our resource groups automatically created in our subscription.



In conclusion, the goal of this post was to take some initial first steps with blueprints.  We created a production blueprint that specified 3 common resource groups (and enforced their names).  We then applied that blueprint to an appropriate scope.  Enjoy!








Wednesday, September 26, 2018

What is an Azure Blueprint?

Over the past year or so, Azure has made a bunch of progress in helping customers manage their Azure environments better.  All of these concepts fit into the area of "Azure Governance" and include things like Azure management groups and Azure Policy.

At Ignite, another feature in the Azure governance toolset was released into preview, and that is Azure Blueprint.  So, what exactly is Azure Blueprint?

I've helped quite a few customers create Azure subscriptions from scratch.  Contrary to the marketing material, setting up an Azure subscription and ensuring that it is secure and compliant by default is no easy feat.  Some examples of initial tasks include:

- Setting up of appropriate RBAC permissions
- Planning for shared services
- Establishing a resource group layout
- Planning for networking, hybrid connectivity, etc
- Establishing a tagging strategy, for billing or otherwise
- Planning for number of subscriptions
- ... and much more

In the past, I would use a combination of tools for this job, which generally involved the portal, command line (read: scripting), ARM templates, and Visio.  Because what architecture would be complete without some Visio?

Azure Blueprint is the culmination of a bunch of work designed to make creating subscriptions easier.  From the documentation:

Blueprints is designed to help with environment setup, which often consists of a set of resource groups, policies, and role assignments, in addition to Resource Manager template deployments.
So, Blueprints consist of the following types of documents:

- ARM Templates (still the basis for everything)
- Resource Groups (ARM templates are still applied to a resource group)
- Policy (How security/compliance/governance teams can apply general rules to follow and/or enforce)
- Role Assignments (RBAC is still important)

Effectively, most operations that one would normally conduct during initial account setup can now be completely scripted and applied to multiple subscriptions in a management group hierarchy. To a certain degree, Azure Blueprints could even replace some of the planning components by codifying best practices into templates that are easy to distribute.

I am hoping to spend some time working with Azure Blueprints over the next few weeks. If you are interested in finding out more, here is the official documentation:

https://docs.microsoft.com/en-us/azure/governance/blueprints/overview