Skip to content

Commit 828ba1b

Browse files
committed
add infra code
1 parent 9a822c1 commit 828ba1b

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

47 files changed

+3758
-0
lines changed

azure.yaml

+13
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
# yaml-language-server: $schema=https://raw.githubusercontent.com/Azure/azure-dev/main/schemas/v1.0/azure.yaml.json
2+
3+
4+
name: azure-django-mysql-flexible-appservice
5+
metadata:
6+
7+
infra:
8+
provider: "bicep"
9+
services:
10+
web:
11+
project: src
12+
language: py
13+
host: appservice

infra/core/ai/cognitiveservices.bicep

+38
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,38 @@
1+
param name string
2+
param location string = resourceGroup().location
3+
param tags object = {}
4+
@description('The custom subdomain name used to access the API. Defaults to the value of the name parameter.')
5+
param customSubDomainName string = name
6+
param deployments array = []
7+
param kind string = 'OpenAI'
8+
param publicNetworkAccess string = 'Enabled'
9+
param sku object = {
10+
name: 'S0'
11+
}
12+
13+
resource account 'Microsoft.CognitiveServices/accounts@2022-10-01' = {
14+
name: name
15+
location: location
16+
tags: tags
17+
kind: kind
18+
properties: {
19+
customSubDomainName: customSubDomainName
20+
publicNetworkAccess: publicNetworkAccess
21+
}
22+
sku: sku
23+
}
24+
25+
@batchSize(1)
26+
resource deployment 'Microsoft.CognitiveServices/accounts/deployments@2022-10-01' = [for deployment in deployments: {
27+
parent: account
28+
name: deployment.name
29+
properties: {
30+
model: deployment.model
31+
raiPolicyName: contains(deployment, 'raiPolicyName') ? deployment.raiPolicyName : null
32+
scaleSettings: deployment.scaleSettings
33+
}
34+
}]
35+
36+
output endpoint string = account.properties.endpoint
37+
output id string = account.id
38+
output name string = account.name
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,48 @@
1+
param name string
2+
param location string = resourceGroup().location
3+
param tags object = {}
4+
5+
param connectionStringKey string = 'AZURE-COSMOS-CONNECTION-STRING'
6+
param keyVaultName string
7+
8+
@allowed([ 'GlobalDocumentDB', 'MongoDB', 'Parse' ])
9+
param kind string
10+
11+
resource cosmos 'Microsoft.DocumentDB/databaseAccounts@2022-08-15' = {
12+
name: name
13+
kind: kind
14+
location: location
15+
tags: tags
16+
properties: {
17+
consistencyPolicy: { defaultConsistencyLevel: 'Session' }
18+
locations: [
19+
{
20+
locationName: location
21+
failoverPriority: 0
22+
isZoneRedundant: false
23+
}
24+
]
25+
databaseAccountOfferType: 'Standard'
26+
enableAutomaticFailover: false
27+
enableMultipleWriteLocations: false
28+
apiProperties: (kind == 'MongoDB') ? { serverVersion: '4.0' } : {}
29+
capabilities: [ { name: 'EnableServerless' } ]
30+
}
31+
}
32+
33+
resource cosmosConnectionString 'Microsoft.KeyVault/vaults/secrets@2022-07-01' = {
34+
parent: keyVault
35+
name: connectionStringKey
36+
properties: {
37+
value: cosmos.listConnectionStrings().connectionStrings[0].connectionString
38+
}
39+
}
40+
41+
resource keyVault 'Microsoft.KeyVault/vaults@2022-07-01' existing = {
42+
name: keyVaultName
43+
}
44+
45+
output connectionStringKey string = connectionStringKey
46+
output endpoint string = cosmos.properties.documentEndpoint
47+
output id string = cosmos.id
48+
output name string = cosmos.name
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,62 @@
1+
param name string
2+
param location string = resourceGroup().location
3+
param tags object = {}
4+
5+
param administratorLogin string
6+
@secure()
7+
param administratorLoginPassword string
8+
9+
param coordinatorServerEdition string
10+
param coordinatorStorageQuotainMb int
11+
param coordinatorVCores int
12+
param databaseName string
13+
param nodeCount int
14+
param nodeVCores int
15+
param allowAzureIPsFirewall bool = false
16+
param allowAllIPsFirewall bool = false
17+
param allowedSingleIPs array = []
18+
param postgresqlVersion string
19+
20+
resource postgresCluster 'Microsoft.DBforPostgreSQL/serverGroupsv2@2023-03-02-preview' = {
21+
name: name
22+
location: location
23+
tags: tags
24+
properties: {
25+
administratorLogin: administratorLogin
26+
administratorLoginPassword: administratorLoginPassword
27+
coordinatorServerEdition: coordinatorServerEdition
28+
coordinatorStorageQuotaInMb: coordinatorStorageQuotainMb
29+
coordinatorVCores: coordinatorVCores
30+
postgresqlVersion: postgresqlVersion
31+
nodeCount: nodeCount
32+
nodeVCores: nodeVCores
33+
databaseName: databaseName
34+
}
35+
36+
resource firewall_all 'firewallRules' = if (allowAllIPsFirewall) {
37+
name: 'allow-all-IPs'
38+
properties: {
39+
startIpAddress: '0.0.0.0'
40+
endIpAddress: '255.255.255.255'
41+
}
42+
}
43+
44+
resource firewall_azure 'firewallRules' = if (allowAzureIPsFirewall) {
45+
name: 'allow-all-azure-internal-IPs'
46+
properties: {
47+
startIpAddress: '0.0.0.0'
48+
endIpAddress: '0.0.0.0'
49+
}
50+
}
51+
52+
resource firewall_single 'firewallRules' = [for ip in allowedSingleIPs: {
53+
name: 'allow-single-${replace(ip, '.', '')}'
54+
properties: {
55+
startIpAddress: ip
56+
endIpAddress: ip
57+
}
58+
}]
59+
60+
}
61+
62+
output domainName string = postgresCluster.properties.serverNames[0].fullyQualifiedDomainName
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
param name string
2+
param location string = resourceGroup().location
3+
param tags object = {}
4+
5+
param keyVaultName string
6+
param connectionStringKey string = 'AZURE-COSMOS-CONNECTION-STRING'
7+
8+
module cosmos '../../cosmos/cosmos-account.bicep' = {
9+
name: 'cosmos-account'
10+
params: {
11+
name: name
12+
location: location
13+
connectionStringKey: connectionStringKey
14+
keyVaultName: keyVaultName
15+
kind: 'MongoDB'
16+
tags: tags
17+
}
18+
}
19+
20+
output connectionStringKey string = cosmos.outputs.connectionStringKey
21+
output endpoint string = cosmos.outputs.endpoint
22+
output id string = cosmos.outputs.id
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
param accountName string
2+
param databaseName string
3+
param location string = resourceGroup().location
4+
param tags object = {}
5+
6+
param collections array = []
7+
param connectionStringKey string = 'AZURE-COSMOS-CONNECTION-STRING'
8+
param keyVaultName string
9+
10+
module cosmos 'cosmos-mongo-account.bicep' = {
11+
name: 'cosmos-mongo-account'
12+
params: {
13+
name: accountName
14+
location: location
15+
keyVaultName: keyVaultName
16+
tags: tags
17+
connectionStringKey: connectionStringKey
18+
}
19+
}
20+
21+
resource database 'Microsoft.DocumentDB/databaseAccounts/mongodbDatabases@2022-08-15' = {
22+
name: '${accountName}/${databaseName}'
23+
tags: tags
24+
properties: {
25+
resource: { id: databaseName }
26+
}
27+
28+
resource list 'collections' = [for collection in collections: {
29+
name: collection.name
30+
properties: {
31+
resource: {
32+
id: collection.id
33+
shardKey: { _id: collection.shardKey }
34+
indexes: [ { key: { keys: [ collection.indexKey ] } } ]
35+
}
36+
}
37+
}]
38+
39+
dependsOn: [
40+
cosmos
41+
]
42+
}
43+
44+
output connectionStringKey string = connectionStringKey
45+
output databaseName string = databaseName
46+
output endpoint string = cosmos.outputs.endpoint
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
param name string
2+
param location string = resourceGroup().location
3+
param tags object = {}
4+
5+
param keyVaultName string
6+
7+
module cosmos '../../cosmos/cosmos-account.bicep' = {
8+
name: 'cosmos-account'
9+
params: {
10+
name: name
11+
location: location
12+
tags: tags
13+
keyVaultName: keyVaultName
14+
kind: 'GlobalDocumentDB'
15+
}
16+
}
17+
18+
output connectionStringKey string = cosmos.outputs.connectionStringKey
19+
output endpoint string = cosmos.outputs.endpoint
20+
output id string = cosmos.outputs.id
21+
output name string = cosmos.outputs.name
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,73 @@
1+
param accountName string
2+
param databaseName string
3+
param location string = resourceGroup().location
4+
param tags object = {}
5+
6+
param containers array = []
7+
param keyVaultName string
8+
param principalIds array = []
9+
10+
module cosmos 'cosmos-sql-account.bicep' = {
11+
name: 'cosmos-sql-account'
12+
params: {
13+
name: accountName
14+
location: location
15+
tags: tags
16+
keyVaultName: keyVaultName
17+
}
18+
}
19+
20+
resource database 'Microsoft.DocumentDB/databaseAccounts/sqlDatabases@2022-05-15' = {
21+
name: '${accountName}/${databaseName}'
22+
properties: {
23+
resource: { id: databaseName }
24+
}
25+
26+
resource list 'containers' = [for container in containers: {
27+
name: container.name
28+
properties: {
29+
resource: {
30+
id: container.id
31+
partitionKey: { paths: [ container.partitionKey ] }
32+
}
33+
options: {}
34+
}
35+
}]
36+
37+
dependsOn: [
38+
cosmos
39+
]
40+
}
41+
42+
module roleDefintion 'cosmos-sql-role-def.bicep' = {
43+
name: 'cosmos-sql-role-definition'
44+
params: {
45+
accountName: accountName
46+
}
47+
dependsOn: [
48+
cosmos
49+
database
50+
]
51+
}
52+
53+
// We need batchSize(1) here because sql role assignments have to be done sequentially
54+
@batchSize(1)
55+
module userRole 'cosmos-sql-role-assign.bicep' = [for principalId in principalIds: if (!empty(principalId)) {
56+
name: 'cosmos-sql-user-role-${uniqueString(principalId)}'
57+
params: {
58+
accountName: accountName
59+
roleDefinitionId: roleDefintion.outputs.id
60+
principalId: principalId
61+
}
62+
dependsOn: [
63+
cosmos
64+
database
65+
]
66+
}]
67+
68+
output accountId string = cosmos.outputs.id
69+
output accountName string = cosmos.outputs.name
70+
output connectionStringKey string = cosmos.outputs.connectionStringKey
71+
output databaseName string = databaseName
72+
output endpoint string = cosmos.outputs.endpoint
73+
output roleDefinitionId string = roleDefintion.outputs.id
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
param accountName string
2+
3+
param roleDefinitionId string
4+
param principalId string = ''
5+
6+
resource role 'Microsoft.DocumentDB/databaseAccounts/sqlRoleAssignments@2022-05-15' = {
7+
parent: cosmos
8+
name: guid(roleDefinitionId, principalId, cosmos.id)
9+
properties: {
10+
principalId: principalId
11+
roleDefinitionId: roleDefinitionId
12+
scope: cosmos.id
13+
}
14+
}
15+
16+
resource cosmos 'Microsoft.DocumentDB/databaseAccounts@2022-08-15' existing = {
17+
name: accountName
18+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,29 @@
1+
param accountName string
2+
3+
resource roleDefinition 'Microsoft.DocumentDB/databaseAccounts/sqlRoleDefinitions@2022-08-15' = {
4+
parent: cosmos
5+
name: guid(cosmos.id, accountName, 'sql-role')
6+
properties: {
7+
assignableScopes: [
8+
cosmos.id
9+
]
10+
permissions: [
11+
{
12+
dataActions: [
13+
'Microsoft.DocumentDB/databaseAccounts/readMetadata'
14+
'Microsoft.DocumentDB/databaseAccounts/sqlDatabases/containers/items/*'
15+
'Microsoft.DocumentDB/databaseAccounts/sqlDatabases/containers/*'
16+
]
17+
notDataActions: []
18+
}
19+
]
20+
roleName: 'Reader Writer'
21+
type: 'CustomRole'
22+
}
23+
}
24+
25+
resource cosmos 'Microsoft.DocumentDB/databaseAccounts@2022-08-15' existing = {
26+
name: accountName
27+
}
28+
29+
output id string = roleDefinition.id

0 commit comments

Comments
 (0)