Azure VM modules
The modules in the terraform/azure-vm/modules folder are implementing a Virtual Machine with the associated network setup and storage.
This VM can be used to test/host the Docker services of this repo.
Prerequisites
Azure Storage Account for Remote State
Before using this Terraform configuration, create an Azure Storage Account to store the remote state.
IMPORTANT: The storage account name tfstateinfrandomanimal shown below is just an example. You must choose your own globally unique name.
Configuration Steps
Choose a unique storage account name (3-24 characters, lowercase letters and numbers only)
Update the configuration files:
Taskfile.yaml: Update theSTORAGE_ACCOUNT_NAMEvariablebackend.tf: Update thestorage_account_namevalue
Create the storage account:
- Assign RBAC permissions (required for Azure AD authentication):
GitHub Actions OIDC Setup (Optional)
To enable automated Terraform plans on pull requests via GitHub Actions:
- Create Azure AD Application:
Note: After the Key Vault is created (on first terraform apply), you need to grant the service principal access to manage secrets:
- Create Federated Credentials:
- Configure GitHub Secrets (Settings > Secrets and variables > Actions):
- Add
AZURE_CLIENT_ID: Application ID from above - Add
AZURE_TENANT_ID: Tenant ID from above - Add
AZURE_SUBSCRIPTION_ID: Subscription ID from above
For more details, see the Azure documentation.
State Migration
If migrating from local state to Azure remote state, use the migration task:
This will backup your local state and migrate it to Azure Blob Storage.
Usage
- Login to Azure account (without browser access on device):
az login --use-device-code - See the file
terraform/azure-vm/Taskfile.yamlfor availabletaskcommands for deploying/connection/deleting the VM. - Execute commands like
task plan(in this folder) ortask azure-vm:plan(anywhere within the repo).
Note: for the previous Makefile (which was replaced by Taskfile) see MR #168.
Cloud-init caveat:
custom_datais aForceNewattribute in the azurerm provider, meaning Terraform will destroy and recreate the VM if cloud-init templates change. The data disk is preserved thanks tolifecycle { prevent_destroy = true }in the storage module. To apply updated cloud-init content, runtask azure-vm:destroy-vmfollowed bytask azure-vm:apply.
Requirements
| Name | Version |
|---|---|
| terraform | >= 1.5 |
| azurerm | ~> 5.0 |
| random | ~> 3.0 |
Providers
| Name | Version |
|---|---|
| random | ~> 3.0 |
Modules
| Name | Source | Version |
|---|---|---|
| base | ./modules/base | n/a |
| keyvault | ./modules/keyvault | n/a |
| storage | ./modules/storage | n/a |
| vm | ./modules/vm | n/a |
Resources
| Name | Type |
|---|---|
| random_string.keyvault_suffix | resource |
Inputs
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| admin_source_address | Allow connections (SSH, …) only from this IP | string | n/a | yes |
| admin_user | Name of the administrative user on the VM | string | "azureuser" | no |
| git_credentials | Git credentials for accessing the infrastructure repository. Will be written to ~/.git-credentials | string | "" | no |
| location | Location of the resources | string | "westeurope" | no |
| repo_directory | Name of the infrastructure repository directory | string | "infra" | no |
| repo_url | URL of the infrastructure repository | string | n/a | yes |
| resourcegroup | Name of Resource Group | string | "HomeInfra" | no |
| storage_disk_size_gb | Size of the permanent disk in GB | number | 10 | no |
| subscription_id | Azure subscription ID (format: ‘00000000-xxxx-xxxx-xxxx-xxxxxxxxxxxx’) | string | n/a | yes |
| vm_domain_name_label | DNS name of the VM. The FQDN will be: <vm_domain_name_label>..cloudapp.azure.com | string | n/a | yes |
| vm_name | Name, hostname of the VM | string | n/a | yes |
| vm_size | Size of the VM | string | "Standard_D2s_v5" | no |
| vm_ubuntu_server_offer | Offer of the VM | string | "ubuntu-24_04-lts" | no |
| vm_ubuntu_server_sku | SKU of the VM | string | "server" | no |
Outputs
| Name | Description |
|---|---|
| key_vault_name | The name of the Key Vault containing git credentials |
| vm_fqdn | n/a |
| vm_id | n/a |
| vm_public_ip_address | n/a |
| vm_public_key_fingerprint_sha256 | n/a |
| vm_tls_private_key | n/a |