Skip to content

Parameters — Advanced reference

Use Standard parameters for the initial checklist. This reference covers the public configuration surface, not every Bash local or internal Bicep/ARM module parameter.

Scope and authoritative sources

The generated tables include every unique key in these shared templates:

  • environment_setup/aifactory/bicep/copy_to_local_settings/github-actions/.env.template
  • environment_setup/aifactory/bicep/copy_to_local_settings/azure-devops/esml-yaml-pipelines/variables/variables.yaml
  • environment_setup/aifactory/variables.json — every section and key, including all Dev and Stage/Prod SKU fields.

They also cover external create-bootstrap environment inputs and the configuration helper's CLI options, from bootstrap/lib/create-new-aifactory-scaleset.sh, bootstrap/lib/release_version.sh, the GH/ADO update launchers, and bootstrap/lib/aifactory_scaleset_config.py. Public Bash command switches are documented below. Internal resume flags, generated state, shell implementation locals, external service API schemas, and module-internal ARM inputs are excluded. There is no separate checked-in bootstrap .env template in these sources: bootstrap reads process environment inputs, then writes the selected route's files. Do not confuse that input environment with the generated GitHub .env.

Two distinct JSON contracts

The raw checked-in consumer template environment_setup/aifactory/variables.json currently has a dev section only. Stage/Prod SKU pairs such as dev.skuAISearchStageProd are present inside it; there is no checked-in top-level stage_prod section. The legacy bootstrap helper's update_json() updates dev. The generated inventory below reports that shared template exactly; it is not the Azure Factory v2 output schema.

Each backend-generated Azure Factory v2 project has one variables.json with direct top-level dev and stage_prod sections, stored at factories/<key>/scalesets/<immutable storage_suffix>/projects/projectNNN/variables.json. Both sections retain the full configuration, with separate subscription and SKU values. They are not nested inside a wrapper or split across per-environment files. Review the selected project's two sections before CLI/API dispatch.

Reading defaults and requirements

  • M — mandatory in the source template's deployment context. A supplied default can satisfy the input; it does not mean you must edit every M row.
  • C — conditionally required. Applies only to the selected environment, identity route, service or networking mode. For example, Stage service connections are not prerequisites for a Dev-only run.
  • O — optional override or feature switch. O does not mean safe to enable without its dependencies. Optional switches remain O even if a preset fixes them on; the required private-agent service bundle is C for that architecture.
  • Values are actual assignments, not the sometimes stale <default> text in comments. Empty strings and <todo> / <optional> placeholders are shown literally and are not usable credentials or resource IDs.
  • YAML and GHA marker annotations occasionally differ. Each GHA row retains its own annotation; a JSON key inherits the YAML annotation where available. Untagged settings default to O, with route/service conditions described in text.
  • Binding names come from shared workflow expressions, preflight getval mappings, bootstrap writers and explicitly reviewed template correspondences. No automatic case conversion is used. A binding may be a workflow fallback rather than an equivalent standalone input.

Important cross-format semantics

Networking and DNS

The shared template default is shared-subscriptions with common_vnet_cidr=172.16.XX.0/18 and network-aligned Dev/Stage/Prod selectors 0 / 64 / 128. Own-subscription /20 planning uses 0 / 16 / 32. XX replaces the third octet in the VNet and subnet templates. Environments, VPN client pools and existing networks must not overlap. Address intent does not create peering or resize existing networks.

centralDnsZoneByPolicyInHub enableAIFactoryHub Meaning
false false Standalone DNS/network intent
false true Own AI Factory hub intent
true Either External central-DNS hub takes precedence; supply its subscription/resource group

The hub flag alone is configuration intent, not a deployment operation. JSON stores these flags as booleans while YAML/GHA templates use string values. The three public-access flags govern service access, not repository visibility and not every telemetry endpoint. enableAMPLS=false does not provide private-only Application Insights/Log Analytics ingestion.

Models, SKUs and aliases

modelGPTXSku / MODEL_GPTX_SKU and default_model_sku / DEFAULT_MODEL_SKU default to DataZoneStandard. Model availability, version support, capacity and quota must be checked for the selected region/subscription; a template value is not a capacity reservation. Dev and Stage/Prod service SKUs remain separate fields.

AI Search has a particularly important fallback: skuAISearchDev reads SKU_AISEARCH_DEV, then ADMIN_AISEARCH_TIER; skuAISearchStageProd reads SKU_AISEARCH_STAGEPROD, then ADMIN_AISEARCH_TIER. The shared ADMIN_AISEARCH_TIER=basic can therefore override the workflow's final Stage/Prod standard fallback. ADMIN_AI_SEARCH_TIER is another spelling consumed by preflight, not a safe rename of every workflow input. Likewise, semantic tier and Azure ML principal-ID compatibility spellings coexist in the template.

Capacity-only service fallbacks

Both ADO and GitHub Actions isolate AI Search, PostgreSQL Flexible Server and Container Apps from their cognitive/database/compute batches. Each has three separately visible attempt steps immediately after its batch. Only recognized regional/SKU capacity failures schedule another attempt; unrelated errors fail immediately, and exhausted candidates fail the pipeline before downstream deployments. Attempts 2 and 3 wait 240 seconds at their start when scheduled. Successful attempts export the effective SKU (and PostgreSQL tier) for later steps. The existing JSON-array names skuAISearchDevArray and skuAISearchStageProdArray remain supported alongside the comma-separated skuArrayAISearchDev / skuArrayAISearchStageProd names. A customized spelling takes precedence over the unchanged default; differing custom values fail validation rather than silently discarding either configuration. Container Apps detected before the run retain their existing application images and configuration. Retry reconciliation uses the original existence flags, so only resources absent at the start are reapplied unless explicitly opted in.

The selected Dev or Stage/Prod SKU is tried first, followed by the remaining configured candidates in array order. Defaults are:

Service Selected defaults (Dev / Stage/Prod) Candidate arrays (both environments) Retry switch
AI Search basic / standard basic,standard,standard2 aisearchRetryCapcityArray
PostgreSQL Standard_B1ms / Standard_B1ms Standard_B1ms,Standard_B2s,Standard_B2ms postgreSQLRetryCapacityArray
Container Apps Consumption / Consumption Consumption,D4,D8 containerAppsRetryCapacityArray

Configure skuArray<Service>Dev / skuArray<Service>StageProd alongside sku<Service>Dev / sku<Service>StageProd. All retry switches default to true; false attempts only the selected SKU and fails on its first error. Keep the existing Capcity spelling in the AI Search switch. The generated inventory below lists the corresponding GitHub uppercase variable names.

Attempts honor the infra phase, deletion and service/debug switches, retaining the cognitive/database capability-host debug override used by ADO. AI Search also runs when private Foundry requires it (enableAIFoundry=true and enablePublicGenAIAccess!=true), even if enableAISearch=false. Preflight quota headroom checks are not a capacity guarantee. Container Apps fallback from Consumption to D4 or D8 changes to dedicated workload-profile pricing; review costs before enabling these candidates.

ADO has separate Dev/Stage/Prod seeding-vault coordinates and service connections. GHA commonly uses one seeding-vault variable name with environment-specific overrides. Review the collision table rather than copying one value into all environments. Some source defaults genuinely differ, including resource naming, Hybrid Benefit, user RBAC restrictions, placeholders and tag macros.

Identity, secrets and lifecycle

Secret-name inputs identify entries in the seeding Key Vault; they are not secret values. Federated managed-identity/OIDC bootstrap can leave legacy service-principal secret-name fields empty. A seeding-vault shell may still be required. Existing-SP and PAT routes require secrets only when selected; keep them out of committed files, logs and command history.

Deletion and debug switches are public template inputs and therefore included. Their presence is not a recommendation to enable them. Review the exact target, backups, policy/RBAC permissions, network reachability and the deployment plan. A complete configuration reference is not a guarantee of deployment success.

Bash create and update contract

Run these entrypoints from the generated consumer checkout, using Bash/Git Bash. They use the existing deployment engine and route configuration.

Entrypoint Public switch Meaning
GHA-create-new-aifactory-scaleset.sh, ADO-create-new-aifactory-scaleset.sh --repo-root PATH Explicit legacy consumer root
Create --aifactory-version VERSION Explicit source version, e.g. main, 124, 125, 1.100, 10.2
Create --dry-run Collect/validate without mutation; not an offline preview or supported simple-mode launch
Create --prepare-only Prepare Azure, identity, configuration and automation without completing deployment
Create --no-wait Dispatch without waiting; incompatible with the simple-mode dependent chain
Create --non-interactive Read answers from process environment
Create --yes Accept the execution summary
Create/update --help, -h Show entrypoint help
ALL-create-new-aifactory-scaleset.sh --orchestrator ado\|gha Select one route, then forward create options
GH-update-aifactory-and-run-project.sh, GHA-update-aifactory-and-run-project.sh, ADO-update-aifactory-and-run-project.sh --project-only Dispatch project only; skip factory/template updates
Update --aifactory-env dev\|stage\|prod Dispatch only the selected environment; conflicts with a different AIFACTORY_TARGET_ENVIRONMENT.
Update --aifactory-version VERSION Choose update source version explicitly

Create and update default to main unless an explicit version selector is provided; project-only is not an upgrade operation. Current create validation accepts AIF_NETWORK_MODE=priv only, despite legacy help also mentioning h/pub. Its general region prompt defaults to swedencentral, whereas the shared configuration templates default to eastus2. Initial legacy bootstrap deploys Dev only and seeds Stage/Prod subscription values from Dev; that is not a reviewed multi-environment network plan.

Register-managed targets are a distinct contract: these legacy launchers do not initialize or modify azurefactory/register.json. Use the corresponding lifecycle CLI/API with an explicit, reviewed target manifest instead. Legacy create explicitly rejects AIF_CREATE_PROJECTS and AIF_PROJECT_MODE; they are not supported substitutes for a scoped lifecycle manifest.

Simple-mode technical contract

AIF_SIMPLE_MODE=true opts the GHA create entrypoint into contract v2, private-ai-foundation-v2. Use --non-interactive --yes --repo-root PATH and wait for the full common → access hub → project chain, followed by the private HTTPS gateway only when its deployment is enabled. Use the following offline, read-only preview instead of a deployment dry run:

python bootstrap/lib/aifactory_scaleset_config.py --simple-mode-manifest
python bootstrap/lib/aifactory_scaleset_config.py --simple-mode-manifest --enable-application-gateway false

Provide tenant/subscription, region, prefix, repository and initial team identity inputs, plus a published AIF_SUBMODULE_REF. Existing Azure/GitHub authentication is required. Prefix validation accepts 2–16 lowercase letters, digits or hyphens. The default suffix is 001; the cost-center default is 123456.

Fixed settings are AIF_TOPOLOGY=s, AIF_NETWORK_MODE=priv, AIF_ACCESS_HUB_MODE=i, AIF_IDENTITY_MODE=c, AIF_SEEDING_MODE=c, AIF_SEED_PROJECT_SP=false, AIF_SETUP_HUB_ACCESS=true, AIF_CONFIGURE_VPN_CLIENT=false, AIF_DEV_VNET_CIDR=172.16.0.0/20, and AIF_PROJECT_NUMBER=001.

Only project Storage, Key Vault and managed identities are always required. Foundry is optional and selected by default, together with its capability host, Basic AI Search, Cosmos DB and Application Insights. Selecting Foundry requires all three dependencies; its capability host cannot be selected without Foundry. The UI clears those three when Foundry is unchecked, after which Search and Cosmos DB can be selected independently. Explicit AIF_SIMPLE_PROJECT_RESOURCES_JSON=[] deploys only the baseline project foundation. Omitting the selection preserves the default Foundry bundle. Explicit incomplete dependencies are rejected before Azure mutations, not silently re-enabled; valid selections are ordered by the catalog.

Additional optional IDs are azure-machine-learning, aks-for-azure-ml, aks, databricks, datafactory, event-hubs, postgresql and container-apps. aks-for-azure-ml requires azure-machine-learning; standalone aks is independent. AML and Container Apps also require their linked Application Insights; this is a conditional dependency, not a globally required service. Include that dependency in explicit CLI selections (for example ["azure-machine-learning","application-insights"]). All selected services map to the existing pipeline flags, with canonical baseline SKUs (Event Hubs Standard is required for Private Link). Resource-provider registration follows the selection. ML/Databricks materialize only their selected first-party enterprise applications, never temporary public workspaces; a tenant administrator may need to provision those applications or supply their object IDs. Foundry-specific deployment and capability-host checks skip when Foundry is off; agent network injection is disabled, while the common, networking, project, data and ML phases still run.

The additive literal projectResourceSelection manifest contract has version 1 and strict dependency validation. Publish the matching source before using it. All model deployment toggles remain off and model SKU defaults stay DataZoneStandard. This is not a preloaded-model or runnable-agent guarantee.

Deploying a new Application Gateway is optional, not a prerequisite for private Foundry agents. New UI selections default off. Set AIF_ENABLE_APPLICATION_GATEWAY=false to avoid deploying a second billable gateway when a customer already has a central gateway, or when no application ingress is needed. This does not adopt, integrate with, or modify that existing gateway. The environment accepts only lowercase true or false; empty/noncanonical values fail before cloud operations. Omitting it preserves legacy enabled behavior for existing automation.

When false, gateway hostname/backend/certificate inputs may be blank and all gateway-specific feature/certificate checks, subnet reservation, NSG, identity, certificate role grant/private endpoint, frontend DNS, deployment and backend health checks are skipped. VPN, DNS Private Resolver, required private DNS zones and the selected project workloads remain enabled. No environment, including Prod, universally requires a new Application Gateway.

This is an additive v2 capability (AIF_SIMPLE_OPTIONAL_GATEWAY_CONTRACT=1), not a replacement for v2. The manifest's literal appGatewayDeployment advertises default: false, omittedDefault: true, and supported: [false, true]. Publish the matching bootstrap and infrastructure source together and use the verified published commit before deploying; updating only the UI/API is insufficient.

Gateway inputs below are required only when deploying a new gateway:

Environment input Helper/API input Constraint
AIF_ENABLE_APPLICATION_GATEWAY --enable-application-gateway / enable_application_gateway true or false; new UI false, omitted legacy true
AIF_APP_GATEWAY_HOSTNAME --app-gateway-hostname / app_gateway_hostname Custom frontend FQDN covered by certificate DNS SAN
AIF_APP_GATEWAY_BACKEND_FQDN --app-gateway-backend-fqdn / app_gateway_backend_fqdn Distinct private RFC1918 HTTPS backend, reachable from the new VNet, trusted TLS, unauthenticated GET / returns 200–399
AIF_APP_GATEWAY_CERT_SECRET_ID --app-gateway-certificate-secret-id / app_gateway_certificate_secret_id Versionless https://<vault>.vault.azure.net/secrets/<name> URI of an enabled, valid, exportable PFX certificate in an RBAC-enabled Dev-subscription vault

No certificate secret value is embedded in these inputs. When gateway deployment is enabled, the private-network Application Gateway subscription feature must already be registered; existing secure HTTPS validation and readiness checks remain. VPN gateway/resolver subnets are reserved before project allocation: 172.16.1.0/27, 172.16.1.32/28. The Application Gateway block 172.16.2.0/24 is reserved only when its deployment is enabled. Conflicting existing allocations are rejected, not moved or deleted.

The access hub includes billable VPN Gateway and DNS Private Resolver resources. VPN transport uses a public IP; Azure service access remains independently controlled. The exported VPN profile is a sensitive connection artifact; connect the client manually. Bastion Developer requires regional support, has no automatic paid-SKU fallback, and does not create an admin VM.

GITHUB_REPOSITORY_VISIBILITY=private|public defaults to private for this contract, unlike the generic .env.template repository default. An existing repository must be empty and match the requested visibility. Review generated code and non-secret metadata before publication. Ignore rules for .env, populated configuration, certificates and VPN files are not a general-purpose secret sanitizer.

Maintaining the reference

The generator reads only the named shared sources. It has no dependency on a separate configuration application or consumer workspace. From repository root:

python documentation/gh-io/tools/generate_parameters.py
python documentation/gh-io/tools/generate_parameters.py --check

The check compares the exact source-qualified union with generated row markers, rejects duplicate JSON keys/reference rows and detects stale defaults, descriptions, aliases and inventory counts. Repeated source assignments are reported, not silently represented as multiple settings.

Targeted regression tests:

python -m unittest discover -s environment_setup/unit-tests/test-bicep/unit -p test_parameter_documentation.py -v

Source coverage

Source Unique public keys
yaml 357
env 357
bootstrap 90
helper 17
state 46
json.dev 361

Counts are source-qualified: a spelling present in YAML and JSON is covered in each source, not counted as two settings. Repeated template assignments are consolidated below (last assignment wins).

  • Source duplicate: env:ADMIN_COMMON_RESOURCE_SUFFIX, lines 135, 380; one reference row.
  • Source duplicate: env:ADMIN_PRJ_RESOURCE_SUFFIX, lines 136, 381; one reference row.
  • Source duplicate: env:USE_COMMON_ACR_OVERRIDE, lines 382, 406; one reference row.

YAML and variables.json reference

Exact YAML keys are under variables:; JSON paths are <section>.<key>. Y = YAML assignment; J.section = JSON value. JSON quoting and scalar types are preserved. A missing source is explicitly marked. GHA names include workflow bindings/fallbacks and explicitly reviewed template counterparts; they are not automatically interchangeable and inclusion does not guarantee every workflow consumes them.

Services and feature switches

YAML / JSON key GHA binding(s) M/C/O Source defaults Description / conditions
AMLStudioUIPrivate AML_STUDIO_UI_PRIVATE O Y: "true"
J.dev: "true"
AML Studio UI private access otherwise: false, only data plane is private; control plane is public.
ENABLE_APIM ENABLE_APIM O Y: "false"
J.dev: "false"
Deploy APIM Azure OpenAI pool, token guard, 429-aware backend circuit breakers, and API policy.
ENABLE_KONG ENABLE_KONG O Y: "false"
J.dev: "false"
Deploys Kong as an optional private edge proxy to APIM.
acr_SKU ACR_SKU M Y: "Premium"
J.dev: "Premium"
ACR SKU mandatory: ACR SKU ensure: Premium required for private endpoints and CMK support.
acr_adminUserEnabled ACR_ADMIN_USER_ENABLED O Y: "false"
J.dev: "false"
ACR admin user enabled recommended: false, disable admin user for security. otherwise: true, enable for simpler dev access.
acr_dedicated ACR_DEDICATED M Y: "true"
J.dev: "true"
ACR dedicated (Premium tier) mandatory: ACR dedicated (Premium tier) ensure: must be true when using private endpoints or CMK.
addAIFoundry ADD_AI_FOUNDRY O Y: "false"
J.dev: "false"
Add new AI Foundry instance with new name otherwise: true, provisions a new AI Foundry with a new random name (for debugging or re-run) to get a fresh start. Still you should delete the old instance.
addAIFoundryHub ADD_AI_FOUNDRY_HUB O Y: "false"
J.dev: "false"
DEPRECATED. Do not enable. keep-as-is: DEPRECATED. Do not enable.
addAISearch ADD_AI_SEARCH O Y: "false"
J.dev: "false"
Add new AI Search instance otherwise: false, CreateIfNotExists logic.
addAzureMachineLearning ADD_AZURE_MACHINE_LEARNING O Y: "false"
J.dev: "false"
Add new Azure ML workspace
addBastionHost ADD_BASTION_HOST O Y: "false"
J.dev: "false"
Add Bastion Host in common RG
apimGatewayAggregateTpm APIM_GATEWAY_AGGREGATE_TPM C Y: ""
J.dev: ""
80-90% of the summed TPM across all GPT-5.5 backends. Required by the separate AI gateway workflow when APIM is enabled.
apimGatewayApiId APIM_GATEWAY_API_ID O Y: "azure-openai-gpt55"
J.dev: "azure-openai-gpt55"
Apim gateway api id.
apimGatewayApiPath APIM_GATEWAY_API_PATH O Y: "openai"
J.dev: "openai"
Apim gateway api path.
apimGatewayAssignOpenAIUserRole APIM_GATEWAY_ASSIGN_OPENAI_USER_ROLE O Y: "false"
J.dev: "false"
Requires roleAssignments/write in every backend subscription.
apimGatewayBackendPoolName APIM_GATEWAY_BACKEND_POOL_NAME O Y: "aoai-gpt55-pool"
J.dev: "aoai-gpt55-pool"
Apim gateway backend pool name.
apimGatewayBackendsJson APIM_GATEWAY_BACKENDS_JSON C Y: "[]"
J.dev: "[]"
JSON array; see esml-common/ai-gateway/apim/README.md. Required by the separate AI gateway workflow when APIM is enabled.
apimGatewayCallerTpm APIM_GATEWAY_CALLER_TPM O Y: "10000"
J.dev: "10000"
Fair-use TPM allocation per APIM subscription.
apimGatewayResourceGroup APIM_GATEWAY_RESOURCE_GROUP C Y: ""
J.dev: ""
Resource group containing the existing APIM service. Required by the separate AI gateway workflow when APIM is enabled.
apimGatewayRetryCount APIM_GATEWAY_RETRY_COUNT O Y: "2"
J.dev: "2"
Apim gateway retry count.
apimGatewayServiceName APIM_GATEWAY_SERVICE_NAME C Y: ""
J.dev: ""
Existing APIM service with system-assigned managed identity enabled. Required by the separate AI gateway workflow when APIM is enabled.
apimGatewaySku APIM_GATEWAY_SKU O Y: "StandardV2"
J.dev: "StandardV2"
AI gateway SKU: BasicV2=dev/test; StandardV2=production default with VNet integration; PremiumV2=private inbound/outbound, zones, and high scale. Classic Developer/Basic/Standard/Premium are supported but cannot be migrated to v2 in place. Consumption is unsupported because APIM backend circuit breakers are unavailable.
apimGatewaySkuCapacity APIM_GATEWAY_SKU_CAPACITY O Y: 1
J.dev: 1
BasicV2/StandardV2 scale to 10 units; PremiumV2 scales to 30 units. Set capacity based on APIM gateway CPU/memory metrics.
apimGatewaySubscriptionId APIM_GATEWAY_SUBSCRIPTION_ID O Y: ""
J.dev: ""
Subscription containing APIM. Empty uses the environment subscription.
cleanFoundryCaphost CLEAN_FOUNDRY_CAPHOST O Y: "false"
J.dev: "false"
Clean up capability host on deletion otherwise: false, leaves capability host and its resources (such as VMs) in place when deleting the Foundry project.
databricksOID DATABRICKS_OID C Y: "<optional>_ObjectID"
J.dev: "<optional>_ObjectID"
Databricks object ID mandatory: if enableDatabricks:'true' ensure: find Databricks object ID in Entra ID.
databricksPrivate DATABRICKS_PRIVATE O Y: "true"
J.dev: "true"
Databricks private control plane otherwise: false, only data plane is private; control plane is public.
disable_whitelisting_for_build_agents DISABLE_WHITELISTING_FOR_BUILD_AGENTS O Y: "false"
J.dev: "false"
Disable runner IP whitelisting otherwise: true, skip whitelisting (use only if runner already has network access).
elasticCompanyName ELASTIC_COMPANY_NAME C Y: "Organization"
J.dev: "Organization"
Elastic Cloud company name mandatory: if enableElasticsearch:'true'
elasticDeploymentSize ELASTIC_DEPLOYMENT_SIZE O Y: "small"
J.dev: "small"
Elasticsearch deployment size otherwise: "medium" or "large".
elasticEmail ELASTIC_EMAIL C Y: "admin@example.com"
J.dev: "admin@example.com"
Elastic Cloud account email mandatory: if enableElasticsearch:'true' ensure: valid email address.
elasticFirstName ELASTIC_FIRST_NAME C Y: "AI"
J.dev: "AI"
Elastic Cloud contact first name mandatory: if enableElasticsearch:'true'
elasticLastName ELASTIC_LAST_NAME C Y: "Factory"
J.dev: "Factory"
Elastic Cloud contact last name mandatory: if enableElasticsearch:'true'
elasticSku ELASTIC_SKU O Y: "ess-consumption-2024_Monthly"
J.dev: "ess-consumption-2024_Monthly"
Elastic Cloud SKU
elasticType ELASTIC_TYPE O Y: "ElasticCloud"
J.dev: "ElasticCloud"
Elasticsearch deployment type otherwise: "SelfManagedOnAKS" (future support).
enableAFoundryCaphost ENABLE_FOUNDRY_CAPHOST C Y: "true"
J.dev: "true"
Required for this private Foundry standard-agent architecture. Cannot be disabled; binds Cosmos DB thread storage, AI Search vector storage, and project Storage. mandatory: Required for this private Foundry standard-agent architecture. Cannot be disabled; binds Cosmos DB thread storage, AI Search vector storage, and project Storage. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths.
enableAIDocIntelligence ENABLE_AI_DOC_INTELLIGENCE O Y: "false"
J.dev: "false"
Deploy Azure AI Document Intelligence
enableAIFactoryCreatedDefaultProjectForAIFv2 ENABLE_AIFACTORY_CREATED_DEFAULT_PROJECT_FOR_AIFV2 O Y: "true"
J.dev: "true"
AI Factory default project for AIFv2 otherwise: false, Azure creates a default project with additional CosmosDB, Storage, AI Search, and connections.
enableAIFactoryHub ENABLE_AI_FACTORY_HUB O Y: "false"
J.dev: false
Own AI Factory Hub intent
enableAIFoundry ENABLE_AI_FOUNDRY C Y: "true"
J.dev: "true"
Enable AI Foundry mandatory: Enable AI Foundry recommended: AI Foundry with default project; enterprise-grade private networking, BYOvNet, existing infra. GA. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths.
enableAIFoundryHub ENABLE_AI_FOUNDRY_HUB O Y: "false"
J.dev: "false"
DEPRECATED. AI Foundry Hub (V1) service. Do not enable. Use enableAIFoundry instead. keep-as-is: DEPRECATED. AI Foundry Hub (V1) service. Do not enable. Use enableAIFoundry instead.
enableAISearch ENABLE_AI_SEARCH C Y: "true"
J.dev: "true"
Required capability-host vector store for private Foundry standard agents. mandatory: Required capability-host vector store for private Foundry standard agents. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths.
enableAISearchSharedPrivateLink ENABLE_AI_SEARCH_SHARED_PRIVATE_LINK O Y: "true"
J.dev: "true"
AI Search shared private link otherwise: false, creates a private endpoint in the project vNet.
enableAIServices ENABLE_AI_SERVICES O Y: "false"
J.dev: "false"
DEPRECATED. Standalone AI Services account with Azure OpenAI endpoint. Do not enable. Use enableAIFoundry instead. keep-as-is: DEPRECATED. Standalone AI Services account with Azure OpenAI endpoint. Do not enable. Use enableAIFoundry instead.
enableAKS ENABLE_AKS O Y: "false"
J.dev: "false"
Deploy standalone AKS cluster in project RG
enableAMPLS ENABLE_AMPLS O Y: "false"
J.dev: "false"
Enable AMPLS in Hub otherwise: true, AMPLS created in Hub subscription; AppInsights in private/private mode.
enableAdminVM ENABLE_ADMIN_VM O Y: "false"
J.dev: "false"
Enable Admin VM in common RG
enableAksForAzureML ENABLE_AKS_FOR_AZURE_ML O Y: "false"
J.dev: "false"
Deploy AKS for Azure ML inference
enableAppInsightsDashboard ENABLE_APPINSIGHTS_DASHBOARD O Y: "false"
J.dev: "false"
Deploy Application Insights dashboard
enableApplicationInsights ENABLE_APPLICATION_INSIGHTS O Y: "true"
J.dev: "true"
Deploy project Application Insights
enableAzureAIVision ENABLE_AZURE_AI_VISION O Y: "false"
J.dev: "false"
Deploy Azure AI Vision
enableAzureMachineLearning ENABLE_AZURE_MACHINE_LEARNING O Y: "false"
J.dev: "false"
Deploy Azure ML workspace
enableAzureMcpServer ENABLE_AZURE_MCP_SERVER O Y: "false"
J.dev: absent
Private, read-only MCP deployment; requires prepared project-scoped configuration.
enableAzureOpenAI ENABLE_AZURE_OPENAI O Y: "false"
J.dev: "false"
Deploy standalone Azure OpenAI
enableAzureSpeech ENABLE_AZURE_SPEECH O Y: "false"
J.dev: "false"
Deploy Azure AI Speech
enableBing ENABLE_BING O Y: "false"
J.dev: "false"
Deploy Bing Search
enableBingCustomSearch ENABLE_BING_CUSTOM_SEARCH O Y: "false"
J.dev: "false"
Deploy Bing Custom Search
enableBotService ENABLE_BOT_SERVICE O Y: "true"
J.dev: "true"
Deploy Azure Bot Service keep-as-is: Required for Microsoft Foundry agent scenarios.
enableContainerApps ENABLE_CONTAINER_APPS O Y: "false"
J.dev: "false"
Deploy Azure Container Apps
enableContentSafety ENABLE_CONTENT_SAFETY O Y: "false"
J.dev: "false"
Deploy Azure AI Content Safety
enableCosmosDB ENABLE_COSMOS_DB C Y: "true"
J.dev: "true"
Required capability-host thread and agent-history store for private Foundry standard agents. mandatory: Required capability-host thread and agent-history store for private Foundry standard agents. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths.
enableDatabricks ENABLE_DATABRICKS O Y: "false"
J.dev: "false"
Deploy Databricks workspace
enableDatafactory ENABLE_DATAFACTORY O Y: "false"
J.dev: "false"
Deploy Azure Data Factory in project RG
enableDatafactoryCommon ENABLE_DATAFACTORY_COMMON O Y: "false"
J.dev: "false"
Deploy Azure Data Factory in common RG
enableDefenderforAIResourceLevel ENABLE_DEFENDER_FOR_AI_RESOURCE_LEVEL O Y: "false"
J.dev: "false"
Defender for AI at resource level otherwise: true, enable Microsoft Defender for AI at per-resource level.
enableDefenderforAISubLevel ENABLE_DEFENDER_FOR_AI_SUB_LEVEL O Y: "false"
J.dev: "false"
Defender for AI at subscription level otherwise: true, enable Microsoft Defender for AI at subscription level.
enableDeleteForDisabledResources ENABLE_DELETE_FOR_DISABLED_RESOURCES O Y: "false"
J.dev: "false"
Delete disabled services otherwise: false, keeps all existing resources regardless of ENABLE_* flags.
enableElasticsearch ENABLE_ELASTICSEARCH O Y: "false"
J.dev: "false"
Deploy Elasticsearch keep-as-is: Elastic Cloud managed service.
enableEventHubs ENABLE_EVENT_HUBS O Y: "false"
J.dev: "false"
Deploy Azure Event Hubs
enableFunction ENABLE_FUNCTION O Y: "false"
J.dev: "false"
Deploy Azure Function App
enableLogicApps ENABLE_LOGIC_APPS O Y: "false"
J.dev: "false"
Deploy Azure Logic Apps
enablePostgreSQL ENABLE_POSTGRESQL O Y: "false"
J.dev: "false"
Deploy Azure PostgreSQL
enableRedisCache ENABLE_REDIS_CACHE O Y: "false"
J.dev: "false"
Deploy Azure Cache for Redis
enableRetries ENABLE_RETRIES O Y: "false"
J.dev: "false"
Enable automatic job retries otherwise: true, enable automatic retries on failure for GenAI services deployment.
enableSQLDatabase ENABLE_SQL_DATABASE O Y: "false"
J.dev: "false"
Deploy Azure SQL Database
enableWebApp ENABLE_WEBAPP, ENABLE_WEB_APP (not in .env template) O Y: "false"
J.dev: "false"
Deploy Azure Web App
foundryApiManagementResourceId FOUNDRY_API_MANAGEMENT_RESOURCE_ID O Y: ""
J.dev: ""
APIM resource ID for Foundry integration otherwise: provide existing API Management resource ID to integrate with Microsoft Foundry.
foundryDeploymentType FOUNDRY_DEPLOYMENT_TYPE O Y: "2"
J.dev: "2"
<deprecated>Retained for configuration compatibility. AI Foundry now always uses the second-option account deployment.
kongGatewayApimHost KONG_GATEWAY_APIM_HOST C Y: ""
J.dev: ""
APIM gateway hostname without protocol/path. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret.
kongGatewayCpu KONG_GATEWAY_CPU O Y: 2
J.dev: 2
Kong gateway cpu.
kongGatewayImage KONG_GATEWAY_IMAGE O Y: "kong/kong-gateway:3.9"
J.dev: "kong/kong-gateway:3.9"
Kong gateway image.
kongGatewayMemoryGb KONG_GATEWAY_MEMORY_GB O Y: 4
J.dev: 4
Kong gateway memory gb.
serviceSettingDeployProjectVM SERVICE_SETTING_DEPLOY_PROJECT_VM O Y: "false"
J.dev: "false"
Deploy VM in project resource group otherwise: true, deploy a jumpbox VM for use with Azure Bastion.
updateAIFoundry UPDATE_AI_FOUNDRY O Y: "false"
J.dev: "false"
Update AI Foundry properties otherwise: true, re-run to update AI Foundry properties and RBAC.

Factory, project, naming and orchestration

YAML / JSON key GHA binding(s) M/C/O Source defaults Description / conditions
AZURE_CLIENT_ID AZURE_CLIENT_ID O Y: absent
J.dev: ""
Preferred credentialless deployment identity: client ID of a federated app or user-assigned managed identity. When set, workflows use OIDC instead of AZURE_CREDENTIALS.
GITHUB_NEW_REPO GITHUB_NEW_REPO M Y: absent
J.dev: ""
New GitHub repository path mandatory: New GitHub repository path ensure: format:
GITHUB_NEW_REPO_VISIBILITY GITHUB_NEW_REPO_VISIBILITY O Y: absent
J.dev: "public"
New repository visibility otherwise: private or internal.
GITHUB_TEMPLATE_REPO GITHUB_TEMPLATE_REPO O Y: absent
J.dev: "azure/enterprise-scale-aifactory"
GitHub template repository keep-as-is: Leave as-is if BYO repo.
GITHUB_USERNAME GITHUB_USERNAME M Y: absent
J.dev: ""
GitHub username or org mandatory: GitHub username or org
GITHUB_USE_SSH GITHUB_USE_SSH O Y: absent
J.dev: "false"
Use SSH for git operations otherwise: true, use SSH instead of HTTPS.
aca_w_registry_image ACA_W_REGISTRY_IMAGE O Y: "mcr.microsoft.com/azuredocs/containerapps-helloworld:latest"
J.dev: "mcr.microsoft.com/azuredocs/containerapps-helloworld:latest"
Container Apps default image otherwise: replace with your own ACR image.
adminUsername ADMIN_USERNAME O Y: "esmladmin"
J.dev: "esmladmin"
VM admin username
admin_aiSearchTier ADMIN_AISEARCH_TIER M Y: "basic"
J.dev: "basic"
AI Search SKU tier mandatory: AI Search SKU tier ensure: 'free' is not allowed when using private endpoints. ['free', 'basic', 'standard', 'standard2', 'standard3', 'storage_optimized_l1', 'storage_optimized_l2']
admin_aifactoryPrefixRG AIFACTORY_PREFIX O Y: "mrvel-1-"
J.dev: "mrvel-1-"
AI Factory resource group prefix keep-as-is: Max 6 chars. otherwise: set your company prefix, e.g. "acme-ai-", "contoso-".
admin_aifactorySuffixRG AIFACTORY_SUFFIX M Y: "-001"
J.dev: "-001"
AI Factory scaleset suffix mandatory: AI Factory scaleset suffix keep-as-is: For 1st scaleset. otherwise: increment to '-002', '-003' for additional scalesets.
admin_commonResourceSuffix ADMIN_COMMON_RESOURCE_SUFFIX O Y: "-001"
J.dev: "-001"
Common resources suffix otherwise: change to reprovision new services in the same common RG while keeping old ones.
admin_hybridBenefit ADMIN_HYBRID_BENEFIT O Y: "false"
J.dev: "false"
Azure Hybrid Benefit for VMs otherwise: true, if you have eligible Windows licenses with Software Assurance (pay-as-you-go avoided).
admin_ip_fw ADMIN_IP_FW O Y: ""
J.dev: ""
Leave empty. Will be automatically set by the pipeline to the build agent IP. keep-as-is: Leave empty. Will be automatically set by the pipeline to the build agent IP.
admin_keyvaultSoftDeleteDays KEYVAULT_SOFT_DELETE C Y: 7
J.dev: 7
Key Vault soft delete days mandatory: if cmk:'true' (purge protection required). otherwise: 90 days recommended; 0 to disable.
admin_location AIFACTORY_LOCATION M Y: "eastus2"
J.dev: "eastus2"
Azure region mandatory: Azure region
admin_locationSuffix AIFACTORY_LOCATION_SHORT M Y: "eus2"
J.dev: "eus2"
Region short name mandatory: Region short name
admin_prjResourceSuffix ADMIN_PRJ_RESOURCE_SUFFIX O Y: "-001"
J.dev: "-001"
Project resources suffix otherwise: change to reprovision new services in the same project RG while keeping old ones.
admin_projectType PROJECT_TYPE M Y: "all"
J.dev: "all"
admin_semanticSearchTier ADMIN_SEMANTIC_SEARCH_TIER, AISEARCH_SEMANTIC_TIER M Y: "free"
J.dev: "free"
Semantic search tier mandatory: Semantic search tier
aiSearchLocation AI_SEARCH_LOCATION O Y: ""
J.dev: ""
AI Search region override. Empty keeps the project region; use another supported region only when regional Search capacity is unavailable.
aifactory-dash-01 AIFACTORY_DASHBOARD_URL O Y: ""
J.dev: ""
Existing Azure Portal AI Factory dashboard URL; never deploys a dashboard.
aifactory_branch_chosen AIFACTORY_BRANCH_CHOSEN O Y: "release/v1.24"
J.dev: "release/v1.24"
Submodule release branch
aifactory_salt AIFACTORY_SALT O Y: ""
J.dev: ""
Leave empty, 5 characters. A deteministic unique value, from COMMON RG
aifactory_salt_random AIFACTORY_SALT_RANDOM O Y: ""
J.dev: ""
Leave empty. 10-character unique random value derived from User-Assigned Managed Identity. Auto-populated by the pipeline. keep-as-is: Leave empty. 10-character unique random value derived from User-Assigned Managed Identity. Auto-populated by the pipeline.
aifactory_version_major AIFACTORY_VERSION_MAJOR O Y: "1"
J.dev: "1"
AI Factory major version keep-as-is: Used to determine which bicep files to use.
aifactory_version_minor AIFACTORY_VERSION_MINOR O Y: "24"
J.dev: "24"
AI Factory minor version keep-as-is: 2025-09-20: 24 = release/v1.24
aisearchRetryCapcityArray AISEARCH_RETRY_CAPCITY_ARRAY O Y: "true"
J.dev: "true"
Validate all candidates' quota headroom and retry only Azure AI Search capacity failures.
aseSku ASE_SKU O Y: "IsolatedV2"
J.dev: "IsolatedV2"
App Service Environment SKU keep-as-is: Used only if byoASEv3:'true' or a dedicated ASE is provisioned.
aseSkuCode ASE_SKU_CODE O Y: "I1v2"
J.dev: "I1v2"
App Service Environment SKU code
aseSkuWorkers ASE_SKU_WORKERS O Y: 1
J.dev: 1
App Service Environment worker count
bastion_custom_name BASTION_CUSTOM_NAME O Y: ""
J.dev: ""
Bastion name override for common RG RBAC keep-as-is: Empty uses the standard Bastion naming convention.
bastion_subscription_resource_group BASTION_SUBSCRIPTION_RESOURCE_GROUP O Y: ""
J.dev: ""
Bastion resource group override for common RG RBAC keep-as-is: Empty uses the common resource group.
bingCustomSearchSku BING_CUSTOM_SEARCH_SKU O Y: "G2"
J.dev: "G2"
Bing Custom Search SKU keep-as-is: ['G2'] G2 is custom search with grounding.
commonLakeNamePrefixMax8chars COMMON_LAKE_NAME_PREFIX_MAX8CHARS (not in .env template), LAKE_PREFIX O Y: "mrvel"
J.dev: "mrvel"
Data lake storage name prefix keep-as-is: Max 8 characters.
commonResourceGroup_param COMMON_RESOURCE_GROUP_PARAM O Y: ""
J.dev: ""
BYO common resource group name otherwise: provide a custom name for the common resource group.
containerAppsRetryCapacityArray CONTAINER_APPS_RETRY_CAPACITY_ARRAY O Y: "true"
J.dev: "true"
Retry only Container Apps capacity failures, with 240 seconds before attempts 2 and 3.
cosmosKind COSMOS_KIND O Y: "GlobalDocumentDB"
J.dev: "GlobalDocumentDB"
Cosmos DB kind otherwise: "MongoDB".
datalakeName_param DATALAKE_NAME_PARAM O Y: ""
J.dev: ""
BYO data lake storage account name otherwise: provide a custom storage account name.
dev_admin_bicep_input_keyvault_subscription AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID M Y: "<todo>_SubID"
J.dev: "<todo>_SubID"
DEV seeding KV subscription ID mandatory: DEV seeding KV subscription ID ensure: subscription where the DEV seeding Key Vault resides.
dev_admin_bicep_kv_fw AIFACTORY_SEEDING_KEYVAULT_NAME M Y: "<todo>_Name_Dev"
J.dev: "<todo>_Name_Dev"
DEV seeding KV name mandatory: DEV seeding KV name ensure: Key Vault name storing secrets mapped to PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID.
dev_admin_bicep_kv_fw_rg AIFACTORY_SEEDING_KEYVAULT_RG M Y: "<todo>_ResourceGroup_DEV"
J.dev: "<todo>_ResourceGroup_DEV"
DEV seeding KV resource group mandatory: DEV seeding KV resource group ensure: resource group where the DEV seeding Key Vault resides.
dev_sub_id DEV_SUBSCRIPTION_ID M Y: "<todo>_SubID"
J.dev: "<todo>_SubID"
DEV subscription ID mandatory: DEV subscription ID
functionRuntime FUNCTION_RUNTIME O Y: "dotnet"
J.dev: "dotnet"
Azure Function runtime otherwise: "python", "node", "java", "powershell".
functionVersion FUNCTION_VERSION O Y: "v7.0"
J.dev: "v7.0"
Azure Function runtime version
kvNameFromCOMMON_param KV_NAME_FROM_COMMON_PARAM O Y: ""
J.dev: ""
BYO common Key Vault name otherwise: provide a custom Key Vault name.
lakeContainerName LAKE_CONTAINER_NAME O Y: "lake3"
J.dev: "lake3"
Data lake container name
org-department-id ORG_DEPARTMENT_ID O Y: ""
J.dev: ""
Project organizational department ID keep-as-is: Text, max 128 characters, not necessarily a GUID; identical across environments. No identity or authentication effect.
org-department-name ORG_DEPARTMENT_NAME O Y: ""
J.dev: ""
Project organizational department name keep-as-is: Unicode text, max 200 characters; identical across environments, independent of cost center. No factory inheritance or Azure tag writes.
postGresAdminEmails POSTGRES_ADMIN_EMAILS C Y: "email_adress_only"
J.dev: "email_adress_only"
PostgreSQL admin emails mandatory: if enablePostgreSQL:'true' ensure: valid comma-separated email addresses.
postgreSQLRetryCapacityArray POSTGRESQL_RETRY_CAPACITY_ARRAY O Y: "true"
J.dev: "true"
Retry only PostgreSQL regional/SKU capacity failures, with 240 seconds before attempts 2 and 3.
prod_admin_bicep_input_keyvault_subscription AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID C Y: "<todo>_SubID"
J.dev: "<todo>_SubID"
PROD seeding KV subscription ID mandatory: PROD seeding KV subscription ID ensure: subscription where the PROD seeding Key Vault resides. Required when deploying that environment.
prod_admin_bicep_kv_fw AIFACTORY_SEEDING_KEYVAULT_NAME C Y: "<todo>_Name_Prod"
J.dev: "<todo>_Name_Prod"
PROD seeding KV name mandatory: PROD seeding KV name ensure: Key Vault name storing secrets mapped to PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID. Required when deploying that environment.
prod_admin_bicep_kv_fw_rg AIFACTORY_SEEDING_KEYVAULT_RG C Y: "<todo>_ResourceGroup_Prod"
J.dev: "<todo>_ResourceGroup_Prod"
PROD seeding KV resource group mandatory: PROD seeding KV resource group ensure: resource group where the PROD seeding Key Vault resides. Required when deploying that environment.
prod_sub_id PROD_SUBSCRIPTION_ID C Y: "<todo>_SubID"
J.dev: "<todo>_SubID"
PROD subscription ID recommended: separate subscription from DEV. otherwise: can reuse dev_sub_id. Required when deploying that environment.
projectPrefix PROJECT_PREFIX O Y: "esml-"
J.dev: "esml-"
Project resource group prefix
projectSuffix PROJECT_SUFFIX O Y: "-rg"
J.dev: "-rg"
Project resource group suffix
project_number_000 PROJECT_NUMBER M Y: "001"
J.dev: "001"
Project number mandatory: Project number keep-as-is: For 1st project. otherwise: increment to '002', '003', etc.
tag_costcenter CostCenter (not in .env template), TAG_COSTCENTER O Y: "1234"
J.dev: "1234"
Project cost center tag keep-as-is: Metadata for per-project cost tracking on resource group level.
tag_costceter_common TAG_COSTCETER_COMMON O Y: "9999"
J.dev: "9999"
Common cost center tag keep-as-is: Metadata for Resource group cost tracking.
tag_repository TAG_REPOSITORY O Y: "aifactory"
J.dev: "aifactory"
Repository name tag
tag_repository_branch TAG_REPOSITORY_BRANCH O Y: "aifactory-001"
J.dev: "aifactory-001"
Repository branch tag otherwise: per scaleset 'aifactory-002', or per project 'aifactory-001/project001-main'.
tags TAGS O Y: "{\"CostCenter\":\"$(tag_costceter_common)\",\"Description\":\"AI Factory common\",\"AIF-Repo\":\"$(tag_repository)\",\"AIF-Branch\":\"$(tag_repository_branch)\",\"AIF-Version\":\"$(aifactory_version_major).$(aifactory_version_minor)\",\"AIF-Submodule-Chosen-Branch\":\"$(aifactory_branch_chosen)\",\"AIF-Scaleset\":\"$(admin_aifactorySuffixRG)\",\"AIF-Environment\":\"$(dev_test_prod)\",\"AIF-Project Owners\":\"$(technical_admins_email)\",\"AIFactory project\":\"$(project_number_000)\",\"AIF-Networking\":\"$(allowPublicAccessWhenBehindVnet),$(enablePublicGenAIAccess),$(enablePublicAccessWithPerimeter)\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"$(enableAIFactoryCreatedDefaultProjectForAIFv2)\",\"AIF-disableAgentNetworkInjection\":\"$(disableAgentNetworkInjection)\",\"AIF-byoASEv3\":\"$(byoASEv3)\",\"AIF-BYO_subnets\":\"$(BYO_subnets)\"}"
J.dev: "{\"CostCenter\":\"$(tag_costceter_common)\",\"Description\":\"AI Factory common\",\"AIF-Repo\":\"$(tag_repository)\",\"AIF-Branch\":\"$(tag_repository_branch)\",\"AIF-Version\":\"$(aifactory_version_major).$(aifactory_version_minor)\",\"AIF-Submodule-Chosen-Branch\":\"$(aifactory_branch_chosen)\",\"AIF-Scaleset\":\"$(admin_aifactorySuffixRG)\",\"AIF-Environment\":\"$(dev_test_prod)\",\"AIF-Project Owners\":\"$(technical_admins_email)\",\"AIFactory project\":\"$(project_number_000)\",\"AIF-Networking\":\"$(allowPublicAccessWhenBehindVnet),$(enablePublicGenAIAccess),$(enablePublicAccessWithPerimeter)\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"$(enableAIFactoryCreatedDefaultProjectForAIFv2)\",\"AIF-disableAgentNetworkInjection\":\"$(disableAgentNetworkInjection)\",\"AIF-byoASEv3\":\"$(byoASEv3)\",\"AIF-BYO_subnets\":\"$(BYO_subnets)\"}"
Common resource tags as a JSON string; Azure DevOps macro expressions are preserved.
tagsProject TAGS_PROJECT O Y: "{\"CostCenter\":\"$(tag_costcenter)\",\"Description\":\"RAG Chat 1\",\"AIF-Branch\":\"$(tag_repository_branch)/project$(project_number_000)\",\"AIF-Scaleset\":\"$(admin_aifactorySuffixRG)\",\"AIF-Environment\":\"$(dev_test_prod)\",\"AIF-Project Owners\":\"$(technical_admins_email)\",\"AIFactory project\":\"$(project_number_000)\",\"AIF-Networking\":\"$(allowPublicAccessWhenBehindVnet),$(enablePublicGenAIAccess),$(enablePublicAccessWithPerimeter)\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"$(enableAIFactoryCreatedDefaultProjectForAIFv2)\",\"AIF-disableAgentNetworkInjection\":\"$(disableAgentNetworkInjection)\",\"AIF-byoASEv3\":\"$(byoASEv3)\",\"AIF-BYO_subnets\":\"$(BYO_subnets)\"}"
J.dev: "{\"CostCenter\":\"$(tag_costcenter)\",\"Description\":\"RAG Chat 1\",\"AIF-Branch\":\"$(tag_repository_branch)/project$(project_number_000)\",\"AIF-Scaleset\":\"$(admin_aifactorySuffixRG)\",\"AIF-Environment\":\"$(dev_test_prod)\",\"AIF-Project Owners\":\"$(technical_admins_email)\",\"AIFactory project\":\"$(project_number_000)\",\"AIF-Networking\":\"$(allowPublicAccessWhenBehindVnet),$(enablePublicGenAIAccess),$(enablePublicAccessWithPerimeter)\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"$(enableAIFactoryCreatedDefaultProjectForAIFv2)\",\"AIF-disableAgentNetworkInjection\":\"$(disableAgentNetworkInjection)\",\"AIF-byoASEv3\":\"$(byoASEv3)\",\"AIF-BYO_subnets\":\"$(BYO_subnets)\"}"
Project resource tags as a JSON string; Azure DevOps macro expressions are preserved.
test_admin_bicep_input_keyvault_subscription AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID C Y: "<todo>_SubID"
J.dev: "<todo>_SubID"
STAGE seeding KV subscription ID mandatory: STAGE seeding KV subscription ID ensure: subscription where the STAGE seeding Key Vault resides. Required when deploying that environment.
test_admin_bicep_kv_fw AIFACTORY_SEEDING_KEYVAULT_NAME C Y: "<todo>_Name_Test"
J.dev: "<todo>_Name_Test"
STAGE seeding KV name mandatory: STAGE seeding KV name ensure: Key Vault name storing secrets mapped to PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID. Required when deploying that environment.
test_admin_bicep_kv_fw_rg AIFACTORY_SEEDING_KEYVAULT_RG C Y: "<todo>_ResourceGroup_Test"
J.dev: "<todo>_ResourceGroup_Test"
STAGE seeding KV resource group mandatory: STAGE seeding KV resource group ensure: resource group where the STAGE seeding Key Vault resides. Required when deploying that environment.
test_sub_id STAGE_SUBSCRIPTION_ID C Y: "<todo>_SubID"
J.dev: "<todo>_SubID"
STAGE subscription ID recommended: separate subscription from DEV. otherwise: can reuse dev_sub_id. Required when deploying that environment.
useCommonACR USE_COMMON_ACR_FOR_PROJECTS O Y: "true"
J.dev: "true"
Use shared ACR across projects otherwise: false, each project gets its own ACR (higher cost).
useCommonACR_override USE_COMMON_ACR_FOR_PROJECTS, USE_COMMON_ACR_OVERRIDE O Y: "true"
J.dev: "true"
Use shared ACR override otherwise: false, each project gets its own ACR (higher cost).
webAppRuntime WEBAPP_RUNTIME O Y: "python"
J.dev: "python"
Azure Web App runtime otherwise: "dotnet", "node", "java".
webAppRuntimeVersion WEBAPP_RUNTIME_VERSION O Y: "3.11"
J.dev: "3.11"
Azure Web App runtime version

Networking, DNS and existing resources

YAML / JSON key GHA binding(s) M/C/O Source defaults Description / conditions
BYOContributorRoleID BYO_CONTRIBUTOR_ROLE_ID O Y: "b24988ac-6180-42a0-ab88-20f7382dd24c"
J.dev: "b24988ac-6180-42a0-ab88-20f7382dd24c"
Contributor role ID keep-as-is: Azure built-in Contributor. otherwise: provide a custom role ID for finer-grained access control.
BYO_subnets BYO_SUBNETS O Y: "false"
J.dev: "false"
Bring your own subnets otherwise: true, uses pre-existing subnets defined by the BYO subnet variables below.
acr_IP_whitelist ACR_IP_WHITELIST O Y: ""
J.dev: ""
ACR IP allowlist otherwise: provide comma-separated IPv4 addresses if ACR network restrictions are needed.
allowPublicAccessWhenBehindVnet ALLOW_PUBLIC_ACCESS_WHEN_BEHIND_VNET (not in .env template) O Y: "true"
J.dev: "true"
Public UI access when behind vNet recommended: false to enable fully private networking.
byoASEv3 BYO_ASEV3 O Y: "false"
J.dev: "false"
Use BYO App Service Environment v3 otherwise: true, use an existing ASEv3 specified in byoAseFullResourceId.
byoAseAppServicePlanResourceId BYO_ASE_APP_SERVICE_PLAN_RESOURCE_ID O Y: ""
J.dev: ""
BYO App Service Plan resource ID otherwise: provide full ARM resource ID of an existing App Service Plan within the ASEv3.
byoAseFullResourceId BYO_ASE_FULL_RESOURCE_ID C Y: "subscriptions/...yourASEnameS2"
J.dev: "subscriptions/...yourASEnameS2"
BYO ASEv3 ARM resource ID. Note - remove leading slash / in Resource ID mandatory: if byoASEv3:'true' ensure: full ARM resource ID of the existing ASEv3.
centralDnsZoneByPolicyInHub CENTRAL_DNS_ZONE_BY_POLICY_IN_HUB O Y: "false"
J.dev: false
Centralized DNS via Hub policy otherwise: true, uses central private DNS zones in HUB resource group managed by Azure Policy.
common_bastion_subnet_cidr COMMON_BASTION_SUBNET_CIDR M Y: "172.16.XX.192/26"
J.dev: "172.16.XX.192/26"
Bastion subnet CIDR mandatory: Bastion subnet CIDR keep-as-is: XX replaced by the selected environment range. ensure: within common_vnet_cidr.
common_bastion_subnet_name COMMON_BASTION_SUBNET_NAME M Y: "AzureBastionSubnet"
J.dev: "AzureBastionSubnet"
Bastion subnet name mandatory: Bastion subnet name keep-as-is: Required name for Azure Bastion. ensure: within common_vnet_cidr.
common_pbi_subnet_cidr COMMON_PBI_SUBNET_CIDR M Y: "172.16.XX.128/26"
J.dev: "172.16.XX.128/26"
Power BI gateway subnet CIDR mandatory: Power BI gateway subnet CIDR keep-as-is: XX replaced by the selected environment range. ensure: within common_vnet_cidr.
common_pbi_subnet_name COMMON_PBI_SUBNET_NAME M Y: "snet-esml-cmn-pbi-001"
J.dev: "snet-esml-cmn-pbi-001"
Power BI gateway subnet name mandatory: Power BI gateway subnet name ensure: within common_vnet_cidr.
common_subnet_cidr COMMON_SUBNET_CIDR M Y: "172.16.XX.0/26"
J.dev: "172.16.XX.0/26"
Common subnet CIDR mandatory: Common subnet CIDR keep-as-is: XX replaced by the selected environment range. ensure: within common_vnet_cidr.
common_subnet_name COMMON_SUBNET_NAME (not in .env template), SUBNET_COMMON_BASE O Y: "snet-esml-cmn-001"
J.dev: "snet-esml-cmn-001"
Common subnet name
common_subnet_scoring_cidr COMMON_SUBNET_SCORING_CIDR M Y: "172.16.XX.64/26"
J.dev: "172.16.XX.64/26"
Scoring subnet CIDR mandatory: Scoring subnet CIDR keep-as-is: XX replaced by the selected environment range. ensure: within common_vnet_cidr.
common_vnet_cidr COMMON_VNET_CIDR M Y: "172.16.XX.0/18"
J.dev: "172.16.XX.0/18"
Common vNet CIDR mandatory: Common vNet CIDR keep-as-is: XX is the network-aligned per-environment octet; Dev/Stage/Prod must not overlap. Address intent only, not actual peering.
dev_cidr_range DEV_CIDR_RANGE M Y: "0"
J.dev: "0"
DEV network-aligned XX value mandatory: DEV network-aligned XX value keep-as-is: VNet 172.16.0.0/18.
disableAgentNetworkInjection DISABLE_AGENT_NETWORK_INJECTION O Y: "false"
J.dev: "false"
Disable agent network injection keep-as-is: false, requires Container Apps subnet in 172.16.0.0/12 or 192.168.0.0/16. otherwise: true, disables network injection.
disableSubnetJoinAction DISABLE_SUBNET_JOIN_ACTION O Y: "false"
J.dev: "false"
Disable VNet subnet join RBAC recommended: false, grants Network Contributor role for subnet join actions (required for APIM, Container Apps, AKS). otherwise: true, skip if subnet permissions managed externally.
enablePublicAccessWithPerimeter ENABLE_PUBLIC_ACCESS_WITH_PERIMETER O Y: "true"
J.dev: "true"
Public access with network perimeter recommended: false to enable fully private networking.
enablePublicGenAIAccess ENABLE_PUBLIC_GENAI_ACCESS O Y: "true"
J.dev: "true"
Public GenAI access (control plane) recommended: false to enable fully private networking.
kongGatewaySubnetCidr KONG_GATEWAY_SUBNET_CIDR C Y: ""
J.dev: ""
Dedicated, unused /28 or larger subnet. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret.
kongGatewaySubnetName KONG_GATEWAY_SUBNET_NAME O Y: "snet-kong-001"
J.dev: "snet-kong-001"
Kong gateway subnet name.
kongGatewayVnetName KONG_GATEWAY_VNET_NAME C Y: ""
J.dev: ""
Kong gateway vnet name. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret.
kongGatewayVnetResourceGroup KONG_GATEWAY_VNET_RESOURCE_GROUP C Y: ""
J.dev: ""
Kong gateway vnet resource group. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret.
network_env_dev DEV_NETWORK_ENV O Y: "dev-"
J.dev: "dev-"
DEV environment prefix for BYO subnets otherwise: set to empty string if not using environment-prefixed naming.
network_env_prod PROD_NETWORK_ENV O Y: "prd-"
J.dev: "prd-"
PROD environment prefix for BYO subnets otherwise: "prod-", "pr-", or empty string.
network_env_stage STAGE_NETWORK_ENV O Y: "tst2-"
J.dev: "tst2-"
STAGE environment prefix for BYO subnets otherwise: "test-", "tst-", or empty string.
privDnsResourceGroup_param PRIV_DNS_RESOURCE_GROUP_PARAM C Y: "<todo>_ResourceGroup_name"
J.dev: "<todo>_ResourceGroup_name"
Hub DNS resource group mandatory: if centralDnsZoneByPolicyInHub:'true' ensure: Hub connectivity resource group where central private DNS zones are deployed.
privDnsSubscription_param PRIV_DNS_SUBSCRIPTION_PARAM C Y: "<todo>_SubscriptionID"
J.dev: "<todo>_SubscriptionID"
Hub DNS subscription ID mandatory: if centralDnsZoneByPolicyInHub:'true' ensure: Hub connectivity subscription ID where central private DNS zones are deployed.
prod_cidr_range PROD_CIDR_RANGE M Y: "128"
J.dev: "128"
PROD network-aligned XX value mandatory: PROD network-aligned XX value keep-as-is: VNet 172.16.128.0/18.
project_IP_whitelist PROJECT_IP_WHITELIST (not in .env template), PROJECT_MEMBERS_IP_ADDRESS C Y: ""
J.dev: ""
Project UI IP allowlist mandatory: if using IP-whitelisting networking mode ensure: comma-separated IPv4 addresses without spaces, e.g. "10.123.456.10,124.56.78.0/24".
runNetworkingVar RUN_JOB1_NETWORKING M Y: "true"
J.dev: "true"
Run networking module mandatory: Run networking module keep-as-is: true when creating or updating a project. otherwise: false, to skip networking on service-only updates.
scaling-mode SCALING_MODE O Y: "shared-subscriptions"
J.dev: "shared-subscriptions"
Address-planning preset: own-subscriptions or shared-subscriptions. Does not create subscriptions, resize networks, or establish peering.
subnetCommon SUBNET_COMMON C Y: "snet-dev-esml-cmn-001"
J.dev: "snet-dev-esml-cmn-001"
BYO common subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists in your vNet.
subnetCommonPowerbiGw SUBNET_COMMON_POWERBI_GW C Y: "snet-esml-cmn-pbi-001"
J.dev: "snet-esml-cmn-pbi-001"
BYO Power BI gateway subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists.
subnetCommonScoring SUBNET_COMMON_SCORING C Y: "snet-<network_env>esml-cmn-001-scoring"
J.dev: "snet-<network_env>esml-cmn-001-scoring"
BYO scoring subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists.
subnetProjACA SUBNET_PROJ_ACA C Y: "snt-prj<xxx>-aca"
J.dev: "snt-prj<xxx>-aca"
ContainerApps subnet. BYO project Container Apps subnet mandatory: if BYO_subnets:'true' ensure: subnet exists and CIDR is in 172.16.0.0/12 or 192.168.0.0/16 if disableAgentNetworkInjection:'false'.
subnetProjACA2 SUBNET_PROJ_ACA2 C Y: "snt-prj<xxx>-aca-002"
J.dev: "snt-prj<xxx>-aca-002"
Agent subnet. BYO project secondary Container Apps subnet mandatory: if BYO_subnets:'true' AND enableAIFoundry:'true' AND disableAgentNetworkInjection is 'false'
subnetProjAKS SUBNET_PROJ_AKS C Y: "snt-prj<xxx>-aks"
J.dev: "snt-prj<xxx>-aks"
BYO project AKS subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists.
subnetProjAKS2 SUBNET_PROJ_AKS2 C Y: "snt-<network_env>prj<xxx>-aks2"
J.dev: "snt-<network_env>prj<xxx>-aks2"
BYO project secondary AKS subnet mandatory: if BYO_subnets:'true' ensure: subnet exists.
subnetProjDatabricksPrivate SUBNET_PROJ_DATABRICKS_PRIVATE, SUBNET_PROJ_DBX_PRIVATE (not in .env template) C Y: "snt-prj<xxx>-dbxpriv"
J.dev: "snt-prj<xxx>-dbxpriv"
BYO Databricks private subnet mandatory: if BYO_subnets:'true' and enableDatabricks:'true'.
subnetProjDatabricksPublic SUBNET_PROJ_DATABRICKS_PUBLIC, SUBNET_PROJ_DBX_PUBLIC (not in .env template) C Y: "snt-prj001-dbxpub"
J.dev: "snt-prj001-dbxpub"
BYO Databricks public subnet mandatory: if BYO_subnets:'true' and enableDatabricks:'true'.
subnetProjGenAI SUBNET_PROJ_GENAI C Y: "snt-dev-prj<xxx>-genai"
J.dev: "snt-dev-prj<xxx>-genai"
BYO project GenAI subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists.
subnetProjWebapp SUBNET_PROJ_WEBAPP C Y: "snt-prj<xxx>-webapp"
J.dev: "snt-prj<xxx>-webapp"
App Service/Function VNet integration subnet (delegated to Microsoft.Web/serverFarms) mandatory: if BYO_subnets:'true' AND (enableWebApp:'true' OR enableFunction:'true') ensure: subnet exists.
test_cidr_range STAGE_CIDR_RANGE M Y: "64"
J.dev: "64"
STAGE network-aligned XX value mandatory: STAGE network-aligned XX value keep-as-is: VNet 172.16.64.0/18.
vnetNameBase VNET_NAME_BASE O Y: "vnt-esmlcmn"
J.dev: "vnt-esmlcmn"
Common vNet base name otherwise: ignored if vnetNameFull_param is set (BYOvNet).
vnetNameFull_param VNET_NAME_FULL_PARAM O Y: ""
J.dev: ""
BYO vNet full name otherwise: provide the full name of your existing vNet.
vnetResourceGroupBase VNET_RESOURCE_GROUP_BASE O Y: "esml-common"
J.dev: "esml-common"
Common vNet resource group base otherwise: ignored if vnetResourceGroup_param is set (BYOvNet).
vnetResourceGroup_param VNET_RESOURCE_GROUP_PARAM O Y: ""
J.dev: ""
BYO vNet resource group otherwise: provide the full RG name of your existing vNet.

Operations, diagnostics and lifecycle

YAML / JSON key GHA binding(s) M/C/O Source defaults Description / conditions
adminVMBuildAgentName No verified binding O Y: ""
J.dev: ""
Azure DevOps agent name override keep-as-is: Leave empty for the Bicep-generated admin VM name; set to an existing VM agent name such as vm-test when reusing one.
adminVMBuildAgentPool No verified binding O Y: "Default"
J.dev: "Default"
Azure DevOps pool hosting the admin VM agent keep-as-is: Change only when the agent is registered in a custom pool.
debugEnableCleaning DEBUG_ENABLE_CLEANING O Y: "false"
J.dev: "false"
Enable error cleanup tasks otherwise: true, enables cleanup tasks (71-73) that delete resources on deployment failures. Use only when debugging.
debug_disable_05_build_acr_image DEBUG_DISABLE_05_BUILD_ACR_IMAGE O Y: "false"
J.dev: "false"
Skip ACR image build step otherwise: true, skip. Cannot be disabled if enableContainerApps:'true'.
debug_disable_10_aifactory_dashboards DEBUG_DISABLE_10_AIFACTORY_DASHBOARDS O Y: "true"
J.dev: "true"
Skip AI Factory dashboards step
debug_disable_61_foundation DEBUG_DISABLE_61_FOUNDATION O Y: "false"
J.dev: "false"
Skip foundation step otherwise: true, skip: Resource groups, User-Assigned Managed Identities, VMs.
debug_disable_62_core_infrastructure DEBUG_DISABLE_62_CORE_INFRASTRUCTURE O Y: "false"
J.dev: "false"
Skip core infrastructure step otherwise: true, skip: Application Insights, Key Vault, Storage, ACR.
debug_disable_63_cognitive_services DEBUG_DISABLE_63_COGNITIVE_SERVICES O Y: "false"
J.dev: "false"
Skip cognitive services step otherwise: true, skip: AI Search, OpenAI, Vision, Speech, etc.
debug_disable_64_databases DEBUG_DISABLE_64_DATABASES O Y: "false"
J.dev: "false"
Skip databases step otherwise: true, skip: Cosmos DB, SQL Database, etc.
debug_disable_65_compute_services DEBUG_DISABLE_65_COMPUTE_SERVICES O Y: "false"
J.dev: "false"
Skip compute services step otherwise: true, skip: Container Apps, Web App, Function App.
debug_disable_66_ai_platform DEBUG_DISABLE_66_AI_PLATFORM O Y: "false"
J.dev: "false"
Skip AI platform step otherwise: true, skip: AI Foundry Hub (V1) with default project and connections.
debug_disable_67_data_ml_platform DEBUG_DISABLE_67_ML_PLATFORM O Y: "false"
J.dev: "false"
Skip ML platform step otherwise: true, skip: Azure Machine Learning, Data Factory, Databricks.
debug_disable_68_integration DEBUG_DISABLE_68_INTEGRATION O Y: "false"
J.dev: "false"
Skip integration step otherwise: true, skip: Logic Apps, Event Hubs.
debug_disable_69_aifoundry_2025 DEBUG_DISABLE_69_AIFOUNDRY_2025 O Y: "false"
J.dev: "false"
Skip AI Foundry V2 step otherwise: true, skip: AI Foundry V2 including RBAC and default project.
debug_disable_validation_tasks DEBUG_DISABLE_VALIDATION_TASKS O Y: "false"
J.dev: "false"
Disable validation tasks otherwise: true, skip subnet validation, submodule check, DNS zones check to speed up re-runs.
deleteAllForProject DELETE_ALL_FOR_PROJECT O Y: "false"
J.dev: "false"
ULTRA DELETE MODE - Delete ALL resources in project RG and networking resources (subnets, NSGs) in common RG. Use with extreme caution!
deleteAllServicesForProject DELETE_ALL_SERVICES_FOR_PROJECT O Y: "false"
J.dev: "false"
Delete all project services otherwise: true, deletes all services in project RG in step 04 then quits pipeline (Key Vault retained by default; set deleteKeyvaultAlso:'true' to also delete it).
deleteKeyvaultAlso DELETE_KEYVAULT_ALSO O Y: "false"
J.dev: "false"
Also delete Key Vault when deleteAllServicesForProject:'true' recommended: false, retains Key Vault as a safety net (secrets, CMK keys, RBAC). otherwise: true, also deletes the project Key Vault.
diagnosticSettingLevel DIAGNOSTIC_SETTING_LEVEL O Y: "gold"
J.dev: "gold"
Diagnostics level otherwise: silver or bronze for less verbose (lower cost) logging.
maxRetryAttempts MAX_RETRY_ATTEMPTS O Y: "2"
J.dev: "2"
Max total retry attempts keep-as-is: Total attempts (1 original + N retries). Valid values: 1, 2, or 3.
policyExemptionAssignmentIds POLICY_EXEMPTION_ASSIGNMENT_IDS O Y: "[]"
J.dev: "[]"
JSON array of policy assignment IDs (deployIfNotExists or auditIfNotExists) to exempt on the VNet RG otherwise: e.g. '["/subscriptions/
policyExemptionDefinitionReferenceIds POLICY_EXEMPTION_DEFINITION_REFERENCE_IDS O Y: "[]"
J.dev: "[]"
JSON array of policyDefinitionReferenceIds within an initiative to narrow the exemption keep-as-is: Leave empty to exempt the full assignment.
retryMinutes RETRY_MINUTES O Y: "5"
J.dev: "5"
Retry wait (minutes) 1st attempt keep-as-is: Minutes between 1st and 2nd retry.
retryMinutesExtended RETRY_MINUTES_EXTENDED O Y: "15"
J.dev: "15"
Retry wait (minutes) 2nd attempt keep-as-is: Minutes between 2nd and 3rd retry.
selfHostedRunnerLabel SELF_HOSTED_RUNNER_LABEL O Y: "aifactory-admin-vm"
J.dev: "aifactory-admin-vm"
GitHub self-hosted runner label
useSelfHostedBuildAgent USE_SELF_HOSTED_BUILD_AGENT O Y: "false"
J.dev: "false"
Use a self-hosted build agent/runner keep-as-is: ADO uses adminVMBuildAgentPool/adminVMBuildAgentName; GHA uses selfHostedRunnerLabel.

Per-environment SKUs and compute sizing

YAML / JSON key GHA binding(s) M/C/O Source defaults Description / conditions
adminVMSize ADMIN_VM_SIZE O Y: "Standard_D2s_v5"
J.dev: absent
Admin VM size keep-as-is: Override when the regional SKU is unavailable.
admin_aks_gpu_sku_dev_override ADMIN_AKS_GPU_SKU_DEV_OVERRIDE O Y: "Standard_D4s_v5"
J.dev: "Standard_D4s_v5"
AKS system node VM SKU for DEV ensure: use an AKS-supported system-pool SKU; configure GPU workloads in a separate user pool.
admin_aks_gpu_sku_test_prod_override ADMIN_AKS_GPU_SKU_TEST_PROD_OVERRIDE O Y: "Standard_DS13-2_v2"
J.dev: "Standard_DS13-2_v2"
AKS node VM SKU for TEST/PROD
admin_aks_nodes_dev_override ADMIN_AKS_NODES_DEV_OVERRIDE O Y: 2
J.dev: 2
AKS system node count for DEV
admin_aks_nodes_testProd_override ADMIN_AKS_NODES_TEST_PROD_OVERRIDE O Y: 3
J.dev: 3
AKS node count for TEST/PROD
admin_aks_version_override ADMIN_AKS_VERSION_OVERRIDE O Y: "1.35.7"
J.dev: "1.35.7"
AKS Kubernetes version ensure: version has standard support in your region.
admin_aml_cluster_maxNodes_dev_override ADMIN_AML_CLUSTER_MAX_NODES_DEV_OVERRIDE O Y: 3
J.dev: 3
AML cluster max nodes for DEV
admin_aml_cluster_maxNodes_testProd_override ADMIN_AML_CLUSTER_MAX_NODES_TEST_PROD_OVERRIDE O Y: 5
J.dev: 5
AML cluster max nodes for TEST/PROD
admin_aml_cluster_sku_dev_override ADMIN_AML_CLUSTER_SKU_DEV_OVERRIDE O Y: "Standard_DS3_v2"
J.dev: "Standard_DS3_v2"
AML cluster VM SKU for DEV
admin_aml_cluster_sku_testProd_override ADMIN_AML_CLUSTER_SKU_TEST_PROD_OVERRIDE O Y: "Standard_D13_v2"
J.dev: "Standard_D13_v2"
AML cluster VM SKU for TEST/PROD
admin_aml_computeInstance_dev_sku_override ADMIN_AML_COMPUTE_INSTANCE_DEV_SKU_OVERRIDE O Y: "Standard_DS11_v2"
J.dev: "Standard_DS11_v2"
AML compute instance SKU for DEV
admin_aml_computeInstance_testProd_sku_override ADMIN_AML_COMPUTE_INSTANCE_TEST_PROD_SKU_OVERRIDE O Y: "Standard_ND96amsr_A100_v4"
J.dev: "Standard_ND96amsr_A100_v4"
AML compute instance SKU for TEST/PROD otherwise: change to a lower-cost SKU to save cost.
aksAzureFirewallPrivateIp AKS_AZURE_FIREWALL_PRIVATE_IP C Y: ""
J.dev: ""
AKS Azure Firewall private IP mandatory: if aksOutboundType:'userDefinedRouting' ensure: IP within the Azure Firewall subnet range.
aksEnablePrivateCluster AKS_ENABLE_PRIVATE_CLUSTER O Y: "true"
J.dev: "true"
Enable private AKS cluster otherwise: false for public access.
aksOutboundType AKS_OUTBOUND_TYPE O Y: "loadBalancer"
J.dev: "loadBalancer"
AKS outbound traffic type otherwise: userDefinedRouting, if you have Azure Firewall and UDR configured.
aksPrivateDNSZone AKS_PRIVATE_DNS_ZONE O Y: "system"
J.dev: "system"
AKS private DNS zone otherwise: "none" or full resource ID of a private DNS zone.
aksSkuName AKS_SKU_NAME O Y: "Base"
J.dev: "Base"
AKS SKU name otherwise: "Standard" for production workloads.
skuAISearchDev ADMIN_AISEARCH_TIER, SKU_AISEARCH_DEV O Y: "basic"
J.dev: "basic"
AI Search SKU Dev ['free','basic','standard','standard2','standard3','storage_optimized_l1','storage_optimized_l2'] ('free' not allowed with private endpoints)
skuAISearchDevArray SKU_AI_SEARCH_DEV_ARRAY O Y: "[\"basic\",\"standard\",\"standard2\"]"
J.dev: ["basic","standard","standard2"]
Sku aisearch dev array.
skuAISearchStageProd ADMIN_AISEARCH_TIER, SKU_AISEARCH_STAGEPROD O Y: "standard"
J.dev: "standard"
AI Search SKU Stage/Prod
skuAISearchStageProdArray SKU_AI_SEARCH_STAGE_PROD_ARRAY O Y: "[\"basic\",\"standard\",\"standard2\"]"
J.dev: ["basic","standard","standard2"]
Sku aisearch stage prod array.
skuAIServicesDev SKU_AISERVICES_DEV O Y: "S0"
J.dev: "S0"
Azure AI Services (multi-service account) SKU Dev
skuAIServicesStageProd SKU_AISERVICES_STAGEPROD O Y: "S0"
J.dev: "S0"
Azure AI Services (multi-service account) SKU Stage/Prod
skuAksDev SKU_AKS_DEV O Y: "Standard_D4s_v5"
J.dev: "Standard_D4s_v5"
AKS dev node VM size keep-as-is: empty=template default Standard_B4ms.
skuAksStageProd SKU_AKS_STAGEPROD O Y: ""
J.dev: ""
AKS test/prod node VM size keep-as-is: empty=template default Standard_DS13-2_v2.
skuArrayAISearchDev SKU_ARRAY_AISEARCH_DEV O Y: "basic,standard,standard2"
J.dev: "basic,standard,standard2"
Ordered fallback SKUs; the configured Dev SKU is attempted first.
skuArrayAISearchStageProd SKU_ARRAY_AISEARCH_STAGEPROD O Y: "basic,standard,standard2"
J.dev: "basic,standard,standard2"
Ordered fallback SKUs; the configured Stage/Prod SKU is attempted first.
skuArrayContainerAppsDev SKU_ARRAY_CONTAINER_APPS_DEV O Y: "Consumption,D4,D8"
J.dev: "Consumption,D4,D8"
Ordered capacity fallback profiles; D4/D8 use dedicated pricing.
skuArrayContainerAppsStageProd SKU_ARRAY_CONTAINER_APPS_STAGEPROD O Y: "Consumption,D4,D8"
J.dev: "Consumption,D4,D8"
Ordered capacity fallback profiles; D4/D8 use dedicated pricing.
skuArrayPostgreSQLDev SKU_ARRAY_POSTGRESQL_DEV O Y: "Standard_B1ms,Standard_B2s,Standard_B2ms"
J.dev: "Standard_B1ms,Standard_B2s,Standard_B2ms"
Ordered capacity fallback SKUs; the selected Dev SKU is attempted first.
skuArrayPostgreSQLStageProd SKU_ARRAY_POSTGRESQL_STAGEPROD O Y: "Standard_B1ms,Standard_B2s,Standard_B2ms"
J.dev: "Standard_B1ms,Standard_B2s,Standard_B2ms"
Ordered capacity fallback SKUs; the selected Stage/Prod SKU is attempted first.
skuAzureMLDev SKU_AZUREML_DEV O Y: "basic"
J.dev: "basic"
Azure ML workspace SKU Dev ['basic','standard']
skuAzureMLStageProd SKU_AZUREML_STAGEPROD O Y: "basic"
J.dev: "basic"
Azure ML workspace SKU Stage/Prod
skuBingDev SKU_BING_DEV O Y: "G2"
J.dev: "G2"
Bing Custom Search SKU Dev ['G2']
skuBingStageProd SKU_BING_STAGEPROD O Y: "G2"
J.dev: "G2"
Bing Custom Search SKU Stage/Prod
skuBotServiceDev SKU_BOTSERVICE_DEV O Y: "S1"
J.dev: "S1"
Bot Service SKU Dev ['F0','S1']
skuBotServiceStageProd SKU_BOTSERVICE_STAGEPROD O Y: "S1"
J.dev: "S1"
Bot Service SKU Stage/Prod
skuContainerAppsDev SKU_CONTAINER_APPS_DEV O Y: "Consumption"
J.dev: "Consumption"
Container Apps workload profile Dev ['Consumption','D4','D8']
skuContainerAppsStageProd SKU_CONTAINER_APPS_STAGEPROD O Y: "Consumption"
J.dev: "Consumption"
Container Apps workload profile Stage/Prod
skuContentSafetyDev SKU_CONTENTSAFETY_DEV O Y: "S0"
J.dev: "S0"
Content Safety SKU Dev
skuContentSafetyStageProd SKU_CONTENTSAFETY_STAGEPROD O Y: "S0"
J.dev: "S0"
Content Safety SKU Stage/Prod
skuDatabricksDev SKU_DATABRICKS_DEV O Y: "premium"
J.dev: "premium"
Databricks SKU Dev ['trial','premium']
skuDatabricksStageProd SKU_DATABRICKS_STAGEPROD O Y: "premium"
J.dev: "premium"
Databricks SKU Stage/Prod
skuDocIntelligenceDev SKU_DOCINTELLIGENCE_DEV O Y: "S0"
J.dev: "S0"
Document Intelligence SKU Dev
skuDocIntelligenceStageProd SKU_DOCINTELLIGENCE_STAGEPROD O Y: "S0"
J.dev: "S0"
Document Intelligence SKU Stage/Prod
skuElasticDev ELASTIC_SKU, SKU_ELASTIC_DEV O Y: "ess-consumption-2024_Monthly"
J.dev: "ess-consumption-2024_Monthly"
Elastic Cloud SKU Dev
skuElasticStageProd ELASTIC_SKU, SKU_ELASTIC_STAGEPROD O Y: "ess-consumption-2024_Monthly"
J.dev: "ess-consumption-2024_Monthly"
Elastic Cloud SKU Stage/Prod
skuEventHubsDev SKU_EVENTHUBS_DEV O Y: "Basic"
J.dev: "Basic"
Event Hubs tier Dev ['Basic','Standard','Premium']
skuEventHubsStageProd SKU_EVENTHUBS_STAGEPROD O Y: "Basic"
J.dev: "Basic"
Event Hubs tier Stage/Prod
skuFunctionDev SKU_FUNCTION_DEV O Y: "EP1"
J.dev: "EP1"
Function plan SKU Dev
skuFunctionStageProd SKU_FUNCTION_STAGEPROD O Y: "EP1"
J.dev: "EP1"
Function plan SKU Stage/Prod
skuLogicAppsDev SKU_LOGICAPPS_DEV O Y: "WS1"
J.dev: "WS1"
Logic Apps plan SKU Dev ['WS1','WS2','WS3','EP1','EP2','EP3','P1V2','P2V2','P3V2','P1V3','P2V3','P3V3']
skuLogicAppsStageProd SKU_LOGICAPPS_STAGEPROD O Y: "WS1"
J.dev: "WS1"
Logic Apps plan SKU Stage/Prod
skuOpenAIDev SKU_OPENAI_DEV O Y: "S0"
J.dev: "S0"
Azure OpenAI SKU Dev
skuOpenAIStageProd SKU_OPENAI_STAGEPROD O Y: "S0"
J.dev: "S0"
Azure OpenAI SKU Stage/Prod
skuPostgreSQLDev SKU_POSTGRESQL_DEV O Y: "Standard_B1ms"
J.dev: "Standard_B1ms"
PostgreSQL compute SKU Dev
skuPostgreSQLStageProd SKU_POSTGRESQL_STAGEPROD O Y: "Standard_B1ms"
J.dev: "Standard_B1ms"
PostgreSQL compute SKU Stage/Prod
skuRedisDev SKU_REDIS_DEV O Y: "Standard"
J.dev: "Standard"
Redis SKU Dev ['Basic','Standard','Premium']
skuRedisStageProd SKU_REDIS_STAGEPROD O Y: "Standard"
J.dev: "Standard"
Redis SKU Stage/Prod
skuSQLDatabaseDev SKU_SQLDATABASE_DEV O Y: "S0"
J.dev: "S0"
Azure SQL DB (DTU model) SKU Dev
skuSQLDatabaseStageProd SKU_SQLDATABASE_STAGEPROD O Y: "S0"
J.dev: "S0"
Azure SQL DB (DTU model) SKU Stage/Prod
skuSpeechDev SKU_SPEECH_DEV O Y: "S0"
J.dev: "S0"
Azure AI Speech SKU Dev
skuSpeechStageProd SKU_SPEECH_STAGEPROD O Y: "S0"
J.dev: "S0"
Azure AI Speech SKU Stage/Prod
skuStorageAccountDev SKU_STORAGEACCOUNT_DEV O Y: "Standard_LRS"
J.dev: "Standard_LRS"
Project Storage Account SKU Dev ['Standard_LRS','Standard_GRS','Standard_RAGRS','Standard_ZRS','Premium_LRS','Premium_ZRS','Standard_GZRS','Standard_RAGZRS']
skuStorageAccountStageProd SKU_STORAGEACCOUNT_STAGEPROD O Y: "Standard_LRS"
J.dev: "Standard_LRS"
Project Storage Account SKU Stage/Prod
skuTierAksDev SKU_TIER_AKS_DEV O Y: "Standard"
J.dev: "Standard"
AKS SKU tier Dev
skuTierAksStageProd SKU_TIER_AKS_STAGEPROD O Y: "Standard"
J.dev: "Standard"
AKS SKU tier Stage/Prod
skuTierAzureMLDev SKU_TIER_AZUREML_DEV O Y: "basic"
J.dev: "basic"
Azure ML workspace tier Dev
skuTierAzureMLStageProd SKU_TIER_AZUREML_STAGEPROD O Y: "basic"
J.dev: "basic"
Azure ML workspace tier Stage/Prod
skuTierFunctionDev SKU_TIER_FUNCTION_DEV O Y: "ElasticPremium"
J.dev: "ElasticPremium"
Function plan tier Dev
skuTierFunctionStageProd SKU_TIER_FUNCTION_STAGEPROD O Y: "ElasticPremium"
J.dev: "ElasticPremium"
Function plan tier Stage/Prod
skuTierPostgreSQLDev SKU_TIER_POSTGRESQL_DEV O Y: "Burstable"
J.dev: "Burstable"
PostgreSQL tier Dev ['Burstable','GeneralPurpose','MemoryOptimized']
skuTierPostgreSQLStageProd SKU_TIER_POSTGRESQL_STAGEPROD O Y: "Burstable"
J.dev: "Burstable"
PostgreSQL tier Stage/Prod
skuTierSQLDatabaseDev SKU_TIER_SQLDATABASE_DEV O Y: "Standard"
J.dev: "Standard"
Azure SQL DB tier Dev ['Basic','Standard','Premium']
skuTierSQLDatabaseStageProd SKU_TIER_SQLDATABASE_STAGEPROD O Y: "Standard"
J.dev: "Standard"
Azure SQL DB tier Stage/Prod
skuTierWebAppDev SKU_TIER_WEBAPP_DEV O Y: "PremiumV3"
J.dev: "PremiumV3"
Web App plan tier Dev
skuTierWebAppStageProd SKU_TIER_WEBAPP_STAGEPROD O Y: "PremiumV3"
J.dev: "PremiumV3"
Web App plan tier Stage/Prod
skuVisionDev SKU_VISION_DEV O Y: "S1"
J.dev: "S1"
Azure AI Vision SKU Dev
skuVisionStageProd SKU_VISION_STAGEPROD O Y: "S1"
J.dev: "S1"
Azure AI Vision SKU Stage/Prod
skuWebAppDev SKU_WEBAPP_DEV O Y: "P1v3"
J.dev: "P1v3"
Web App plan SKU Dev
skuWebAppStageProd SKU_WEBAPP_STAGEPROD O Y: "P1v3"
J.dev: "P1v3"
Web App plan SKU Stage/Prod

Identity, access and encryption

YAML / JSON key GHA binding(s) M/C/O Source defaults Description / conditions
apimGatewayManagedIdentityPrincipalId APIM_GATEWAY_MANAGED_IDENTITY_PRINCIPAL_ID C Y: ""
J.dev: ""
APIM system-assigned managed identity object ID. Required when assigning the OpenAI user role to the APIM managed identity.
azureDevOpsTenantId No verified binding M Y: "<todo>_AzureDevOpsTenantId"
J.dev: "<todo>_AzureDevOpsTenantId"
Microsoft Entra tenant ID connected to the Azure DevOps organization. This can differ from tenantId used for Azure deployments. mandatory: Microsoft Entra tenant ID connected to the Azure DevOps organization. This can differ from tenantId used for Azure deployments.
azure_machinelearning_sp_oid AZURE_MACHINELEARNING_SP_OID, TENANT_AZUREML_OID C Y: "<todo>_ObjectID"
J.dev: "<todo>_ObjectID"
Azure ML service principal OID mandatory: Azure ML service principal OID ensure: find in Entra ID as "Azure Machine Learning" app (AppId: 0736f41a-0425-4b46-bdb5-1563eff02385). otherwise: optional if enableAIFoundry:'false'.
cmk CMK O Y: "false"
J.dev: "false"
Customer Managed Key encryption otherwise: true, enable CMK for Key Vault, Storage accounts, etc.
cmkDisableForAISearch CMK_DISABLE_FOR_AI_SEARCH O Y: "true"
J.dev: "true"
Disable CMK for AI Search otherwise: true, disables CMK encryption for Azure AI Search even when cmk:'true'. Reason: Foundry runtime creates indexes without providing CMK info, causing failures.
cmkDisableForFoundry CMK_DISABLE_FOR_FOUNDRY O Y: "true"
J.dev: "true"
Disable CMK for AI Foundry otherwise: true, disables CMK encryption for AI Foundry account even when cmk:'true'. Reason: Foundry does not respect AI Search CMK contract at runtime.
cmkKeyName CMK_KEY_NAME C Y: "<todo>_aifactory-cmk-key"
J.dev: "<todo>_aifactory-cmk-key"
CMK key name in seeding KV mandatory: if cmk:'true' ensure: key name in your Seeding Keyvault to use for CMK encryption.
cmkKeyVersion CMK_KEY_VERSION O Y: ""
J.dev: ""
CMK key version otherwise: pin to a specific GUID version string.
commonServicePrincipleOIDKey COMMON_SERVICE_PRINCIPLE_OID_KEY C Y: "<optional>esml-common-sp-oid"
J.dev: "<optional>esml-common-sp-oid"
Seeding KV secret name for common SP OID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
debug_disable_100_rbac_security DEBUG_DISABLE_100_RBAC_SECURITY O Y: "false"
J.dev: "false"
Skip RBAC and security step otherwise: true, skip RBAC and security step for all services (steps 61-99).
dev_seeding_kv_service_connection No verified binding M Y: "<todo>_ado_service_connection"
J.dev: "<todo>_ado_service_connection"
ADO service connection for DEV seeding KV mandatory: ADO service connection for DEV seeding KV ensure: name matches your service connection for the DEV seeding KV subscription. otherwise: can be same as dev_service_connection.
dev_service_connection No verified binding M Y: "<todo>_ado_service_connection"
J.dev: "<todo>_ado_service_connection"
ADO service connection for DEV mandatory: ADO service connection for DEV ensure: name matches your Azure DevOps service connection for the DEV subscription.
disableContributorAccessForUsers DISABLE_CONTRIBUTOR_ACCESS_FORUSERS, DISABLE_CONTRIBUTOR_ACCESS_FOR_USERS (not in .env template) O Y: "false"
J.dev: "false"
Disable Contributor for project users recommended: false, enables users to create artifacts (managed online endpoints etc). otherwise: true, restrict Contributor access.
disableLocalAuth DISABLE_LOCAL_AUTH O Y: "true"
J.dev: "true"
Disable local API key ("admin account") auth on Cognitive/AI Services & Foundry, AAD-only recommended: true, disables key auth (many orgs forbid keys). otherwise: false, allow local API keys.
disableRBACAdminOnRGForUsers DISABLE_RBAC_ADMIN_ON_RG_FORUSERS, DISABLE_RBAC_ADMIN_ON_RG_FOR_USERS (not in .env template) O Y: "true"
J.dev: "true"
Disable RBAC Admin on RG for project users recommended: true, restricts users from assigning RBAC at resource group scope.
groups_coreteam_members GROUPS_CORETEAM_MEMBERS C Y: "<aif001sdc_coreteam_admin_p080>,<aif001sdc_coreteam_dataops_p081>,<aif001sdc_coreteam_dataops_fabric_p082>"
J.dev: "<aif001sdc_coreteam_admin_p080>,<aif001sdc_coreteam_dataops_p081>,<aif001sdc_coreteam_dataops_fabric_p082>"
Core team AD group ObjectIDs mandatory: if use_ad_groups:'true'
groups_project_members_esml GROUPS_PROJECT_MEMBERS_ESML C Y: "<aif001sdc_prj001_team_lead_p001>,<aif001sdc_prj001_team_member_ds_p002>,<aif001sdc_prj001_team_member_fend_p003>"
J.dev: "<aif001sdc_prj001_team_lead_p001>,<aif001sdc_prj001_team_member_ds_p002>,<aif001sdc_prj001_team_member_fend_p003>"
ESML project team AD group ObjectIDs mandatory: if use_ad_groups:'true'
groups_project_members_genai_1 GROUPS_PROJECT_MEMBERS_GENAI_1 C Y: "<aif001sdc_prj002_team_lead_p011>,<aif001sdc_prj002_genai_team_member_aifoundry_p012>,<aif002sdc_prj001_genai_team_member_agentic_p013>,<aif001sdc_prj001_genai_team_member_dataops_p014>,<aif001sdc_prj001_team_member_fend_p015>"
J.dev: "<aif001sdc_prj002_team_lead_p011>,<aif001sdc_prj002_genai_team_member_aifoundry_p012>,<aif002sdc_prj001_genai_team_member_agentic_p013>,<aif001sdc_prj001_genai_team_member_dataops_p014>,<aif001sdc_prj001_team_member_fend_p015>"
GenAI-1 project team AD group ObjectIDs mandatory: if use_ad_groups:'true'
inputCommonSPIDKey INPUT_COMMON_SPID_KEY C Y: "<optional>esml-common-sp-id"
J.dev: "<optional>esml-common-sp-id"
Seeding KV secret name for common SP App ID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
inputCommonSPSecretKey INPUT_COMMON_SP_SECRET_KEY C Y: "<optional>esml-common-sp-secret"
J.dev: "<optional>esml-common-sp-secret"
Seeding KV secret name for common SP secret ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
personas_core_team PERSONAS_CORE_TEAM O Y: "p080_coreteam_it_admin,coreteam_dataops,p081_coreteam_dataops_fabric, p103_coreteam_team_process_ops"
J.dev: "p080_coreteam_it_admin,coreteam_dataops,p081_coreteam_dataops_fabric, p103_coreteam_team_process_ops"
Core team personas keep-as-is: Mapped to group_coreteam_members.
personas_project_esml PERSONAS_PROJECT_ESML O Y: "p001_esml_team_lead,p002_esml_team_member_datascientist,p003_esml_team_member_front_end,p101_esml_team_process_ops"
J.dev: "p001_esml_team_lead,p002_esml_team_member_datascientist,p003_esml_team_member_front_end,p101_esml_team_process_ops"
ESML project personas keep-as-is: Mapped to groups_project_members_esml and PROJECT_TYPE=esml.
personas_project_genai_1 PERSONAS_PROJECT_GENAI_1 O Y: "p011_genai_team_lead,p012_genai_team_member_aifoundry,p013_genai_team_member_agentic,p014_genai_team_member_dataops,p015_genai_team_member_frontend,p102_esml_team_process_ops"
J.dev: "p011_genai_team_lead,p012_genai_team_member_aifoundry,p013_genai_team_member_agentic,p014_genai_team_member_dataops,p015_genai_team_member_frontend,p102_esml_team_process_ops"
GenAI-1 project personas keep-as-is: Mapped to groups_project_members_genai_1 and PROJECT_TYPE=genai-1.
prod_seeding_kv_service_connection No verified binding C Y: "<todo>_ado_service_connection"
J.dev: "<todo>_ado_service_connection"
ADO service connection for PROD seeding KV mandatory: ADO service connection for PROD seeding KV ensure: name matches your service connection for the PROD seeding KV subscription. otherwise: can be same as prod_service_connection. Required when deploying that environment.
prod_service_connection No verified binding C Y: "<todo>_ado_service_connection"
J.dev: "<todo>_ado_service_connection"
ADO service connection for PROD mandatory: ADO service connection for PROD ensure: name matches your Azure DevOps service connection for the PROD subscription. Required when deploying that environment.
project_service_principal_AppID_seeding_kv_name PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID C Y: "<optional>esml-project001-sp-id"
J.dev: "<optional>esml-project001-sp-id"
Project SP App ID secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
project_service_principal_OID_seeding_kv_name PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_OID C Y: "<optional>esml-project001-sp-oid"
J.dev: "<optional>esml-project001-sp-oid"
Project SP OID secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
project_service_principal_Secret_seeding_kv_name PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_S C Y: "<optional>esml-project001-sp-secret"
J.dev: "<optional>esml-project001-sp-secret"
Project SP secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
technical_admins_ad_object_id PROJECT_MEMBERS M Y: "<todo>_EntraID_ObjectID"
J.dev: "<todo>_EntraID_ObjectID"
Project team Entra ID object ID(s) mandatory: Project team Entra ID object ID(s) ensure: comma-separated ObjectIDs of users or AD groups for the project team.
technical_admins_email PROJECT_MEMBERS_EMAILS O Y: "<todo>_email_or_securitygroup_name"
J.dev: "<todo>_email_or_securitygroup_name"
Project team contact email or group name recommended: set for better project tracking.
tenantId TENANT_ID M Y: "<todo>_TenantId"
J.dev: "<todo>_TenantId"
Azure tenant ID mandatory: Azure tenant ID ensure: find in Azure Portal > Entra ID > Overview (Directory ID).
test_seeding_kv_service_connection No verified binding C Y: "<todo>_ado_service_connection"
J.dev: "<todo>_ado_service_connection"
ADO service connection for STAGE seeding KV mandatory: ADO service connection for STAGE seeding KV ensure: name matches your service connection for the STAGE seeding KV subscription. otherwise: can be same as test_service_connection. Required when deploying that environment.
test_service_connection No verified binding C Y: "<todo>_ado_service_connection"
J.dev: "<todo>_ado_service_connection"
ADO service connection for STAGE mandatory: ADO service connection for STAGE ensure: name matches your Azure DevOps service connection for the STAGE subscription. Required when deploying that environment.
updateKeyvaultRbac UPDATE_KEYVAULT_RBAC O Y: "false"
J.dev: "false"
Update Key Vault RBAC otherwise: true, re-run to update RBAC properties.
use_ad_groups USE_AD_GROUPS O Y: "true"
J.dev: "true"
Use AD groups for project members otherwise: false, use individual ObjectIDs and simple mode Personas.

Models and deployments

YAML / JSON key GHA binding(s) M/C/O Source defaults Description / conditions
default_embedding_capacity DEFAULT_EMBEDDING_CAPACITY O Y: 25
J.dev: 25
Embedding model TPM capacity (K) keep-as-is: 25 = 25K tokens per minute.
default_gpt_4o_version DEFAULT_GPT_4O_VERSION O Y: "2024-11-20"
J.dev: "2024-11-20"
gpt-4o version otherwise: "2024-08-06".
default_gpt_54_mini_version DEFAULT_GPT_54_MINI_VERSION O Y: "2026-03-17"
J.dev: "2026-03-17"
Version for the separately named GPT-5.4-mini deployment toggle.
default_gpt_capacity DEFAULT_GPT_CAPACITY O Y: 40
J.dev: 40
GPT model TPM capacity (K) keep-as-is: 40 = 40K tokens per minute.
default_model_sku DEFAULT_MODEL_SKU O Y: "DataZoneStandard"
J.dev: "DataZoneStandard"
Default model deployment SKU keep-as-is: Keep inference within the selected data zone; confirm model/SKU availability and quota.
deployModel_gpt_4o DEPLOY_MODEL_GPT_4O O Y: "false"
J.dev: "false"
Deploy gpt-4o recommended: for general-purpose AI Foundry scenarios.
deployModel_gpt_54_mini DEPLOY_MODEL_GPT_54_MINI O Y: "false"
J.dev: "false"
Enable the separately named GPT-5.4-mini deployment toggle; inspect its workflow binding alongside deployModel_gpt_X.
deployModel_gpt_X DEPLOY_MODEL_GPT_X O Y: "true"
J.dev: "true"
Deploy custom GPT-X model otherwise: true, deploy the model defined in modelGPTXName.
deployModel_text_embedding_3_large DEPLOY_MODEL_TEXT_EMBEDDING_3_LARGE O Y: "true"
J.dev: "true"
Deploy text-embedding-3-large recommended: for production RAG scenarios.
deployModel_text_embedding_3_small DEPLOY_MODEL_TEXT_EMBEDDING_3_SMALL O Y: "false"
J.dev: "false"
Deploy text-embedding-3-small recommended: for cost-optimized scenarios.
deployModel_text_embedding_ada_002 DEPLOY_MODEL_TEXT_EMBEDDING_ADA_002 O Y: "false"
J.dev: "false"
Deploy text-embedding-ada-002
modelGPTXCapacity MODEL_GPTX_CAPACITY O Y: 30
J.dev: 30
GPT-X TPM capacity (K) keep-as-is: 30 = 30K tokens per minute.
modelGPTXName MODEL_GPTX_NAME O Y: "gpt-5.4-mini"
J.dev: "gpt-5.4-mini"
GPT-X model name ensure: model is available in your Azure region with sufficient quota.
modelGPTXSku MODEL_GPTX_SKU O Y: "DataZoneStandard"
J.dev: "DataZoneStandard"
GPT-X deployment SKU keep-as-is: Keep inference within the selected data zone; confirm model/SKU availability and quota.
modelGPTXVersion MODEL_GPTX_VERSION O Y: "2026-03-17"
J.dev: "2026-03-17"
GPT-X model version ensure: update the version when selecting a different model.

GitHub Actions .env reference

Every unique assignment is included, including orchestrator-only and compatibility names. Values are decoded literals, not expansions; these are template values, not necessarily the workflow's effective fallback. No verified counterpart means no mapping was found in the inspected shared bindings, not proof that a setting is unused.

GHA: Factory, project, naming and orchestration

Exact environment key YAML / JSON counterpart(s) M/C/O Template value Description / conditions
ACA_W_REGISTRY_IMAGE aca_w_registry_image O "mcr.microsoft.com/azuredocs/containerapps-helloworld:latest" Container Apps default registry image
ADMIN_AISEARCH_TIER admin_aiSearchTier, skuAISearchDev, skuAISearchStageProd M "basic" AI Search SKU tier mandatory: AI Search SKU tier ensure: 'free' is not allowed when using private endpoints. ['free','basic','standard','standard2','standard3','storage_optimized_l1','storage_optimized_l2']
ADMIN_AI_SEARCH_TIER No verified counterpart M "basic" AI Search SKU tier mandatory: AI Search SKU tier ensure: 'free' is not allowed when using private endpoints. ['free','basic','standard','standard2','standard3','storage_optimized_l1','storage_optimized_l2']
ADMIN_COMMON_RESOURCE_SUFFIX admin_commonResourceSuffix O "-001" Common resources suffix otherwise: change to reprovision new services in the same common RG while keeping old ones.
ADMIN_HYBRID_BENEFIT admin_hybridBenefit O "true" Azure Hybrid Benefit for VMs otherwise: true, if you have eligible Windows licenses with Software Assurance (pay-as-you-go avoided).
ADMIN_IP_FW admin_ip_fw O "" Admin IP for firewall rules keep-as-is: Used by GHA runner to whitelist its own IP.
ADMIN_PRJ_RESOURCE_SUFFIX admin_prjResourceSuffix O "-001" Project resources suffix otherwise: change to reprovision new services in the same project RG while keeping old ones.
ADMIN_SEMANTIC_SEARCH_TIER admin_semanticSearchTier M "free" Semantic search tier mandatory: Semantic search tier
ADMIN_USERNAME adminUsername O "esmladmin" VM admin username
AIFACTORY_BRANCH_CHOSEN aifactory_branch_chosen O "release/v1.24" Submodule release branch
AIFACTORY_COMMON_ONLY_DEV_ENVIRONMENT No verified counterpart O "true" Create common-DEV environment only otherwise: false, creates Dev, Stage, Prod environments in Azure.
AIFACTORY_DASHBOARD_URL aifactory-dash-01 O "" Existing Azure Portal AI Factory dashboard URL; never deploys a dashboard.
AIFACTORY_LOCATION admin_location M "eastus2" Azure region mandatory: Azure region
AIFACTORY_LOCATION_SHORT admin_locationSuffix M "eus2" Region short name mandatory: Region short name
AIFACTORY_PREFIX admin_aifactoryPrefixRG O "acme-ai" AI Factory resource group prefix keep-as-is: Max 6 chars. otherwise: set your company prefix, e.g. 'acme-ai-', 'contoso-'.
AIFACTORY_SALT aifactory_salt O "<5>" AI Factory deterministic salt (5 chars) ensure: read from COMMON RG resource names, e.g. the 'a4c2b' in 'adf-cmn-weu-dev-a4c2b-001'. Used in project resource naming.
AIFACTORY_SALT_RANDOM aifactory_salt_random O "<10>" Random salt placeholder (10 chars) keep-as-is: Do not change. Placeholder only.
AIFACTORY_SEEDING_KEYVAULT_NAME dev_admin_bicep_kv_fw, prod_admin_bicep_kv_fw, test_admin_bicep_kv_fw M "kv-seeding-sdc-001<todo>" DEV seeding KV name mandatory: DEV seeding KV name ensure: Key Vault name storing secrets mapped to PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID.
AIFACTORY_SEEDING_KEYVAULT_RG dev_admin_bicep_kv_fw_rg, prod_admin_bicep_kv_fw_rg, test_admin_bicep_kv_fw_rg M "rg-seeding-sdc-001<todo>" DEV seeding KV resource group mandatory: DEV seeding KV resource group ensure: resource group where the DEV seeding Key Vault resides.
AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID dev_admin_bicep_input_keyvault_subscription, prod_admin_bicep_input_keyvault_subscription, test_admin_bicep_input_keyvault_subscription M "<todo>" DEV seeding KV subscription ID mandatory: DEV seeding KV subscription ID ensure: subscription where the DEV seeding Key Vault resides.
AIFACTORY_SUFFIX admin_aifactorySuffixRG M "-001" AI Factory scaleset suffix mandatory: AI Factory scaleset suffix keep-as-is: For 1st scaleset. otherwise: increment to '-002', '-003' for additional scalesets.
AIFACTORY_VERSION_MAJOR aifactory_version_major O "1" AI Factory major version keep-as-is: Used to determine which bicep files to use.
AIFACTORY_VERSION_MINOR aifactory_version_minor O "24" AI Factory minor version keep-as-is: 2025-09-20: 24 = release/v1.24
AISEARCH_RETRY_CAPCITY_ARRAY aisearchRetryCapcityArray O "true" Validate every candidate quota and retry only recognized capacity failures after four minutes.
AISEARCH_SEMANTIC_TIER admin_semanticSearchTier M "free" Semantic search tier mandatory: Semantic search tier
AI_SEARCH_LOCATION aiSearchLocation O "" AI Search region override. Empty keeps AIFACTORY_LOCATION.
AML_STUDIO_UI_PRIVATE AMLStudioUIPrivate O "true" AML Studio UI private access otherwise: false, only data plane is private; control plane is public.
ASE_SKU aseSku O "IsolatedV2" App Service Environment SKU
ASE_SKU_CODE aseSkuCode O "I1v2" ASE SKU code
ASE_SKU_WORKERS aseSkuWorkers O "1" ASE number of workers
AZURE_CLIENT_ID AZURE_CLIENT_ID O "" Preferred credentialless deployment identity: client ID of a federated app or user-assigned managed identity. When set, workflows use OIDC instead of AZURE_CREDENTIALS.
BASTION_CUSTOM_NAME bastion_custom_name O "" Bastion name override for common RG RBAC keep-as-is: Empty uses the standard Bastion naming convention.
BASTION_SUBSCRIPTION_RESOURCE_GROUP bastion_subscription_resource_group O "" Bastion resource group override for common RG RBAC keep-as-is: Empty uses the common resource group.
BING_CUSTOM_SEARCH_SKU bingCustomSearchSku O "G2" Bing Custom Search SKU
COMMON_RESOURCE_GROUP_PARAM commonResourceGroup_param O "" BYO common resource group name otherwise: provide a custom name for the common resource group.
CONTAINER_APPS_RETRY_CAPACITY_ARRAY containerAppsRetryCapacityArray O "true" Retry only Container Apps capacity errors, waiting 240 seconds before attempts 2 and 3.
COSMOS_KIND cosmosKind O "GlobalDocumentDB" Cosmos DB kind otherwise: MongoDB.
DATALAKE_NAME_PARAM datalakeName_param O "" BYO data lake storage account name otherwise: provide a custom storage account name.
DEV_SUBSCRIPTION_ID dev_sub_id M "<todo>" DEV subscription ID mandatory: DEV subscription ID
FUNCTION_RUNTIME functionRuntime O "dotnet" Functions runtime stack otherwise: python, node, java.
FUNCTION_VERSION functionVersion O "v7.0" Functions runtime version
GITHUB_NEW_REPO GITHUB_NEW_REPO M "<todo>/<todo>azure-enterprise-scale-aifactory-001" New GitHub repository path mandatory: New GitHub repository path ensure: format:
GITHUB_NEW_REPO_VISIBILITY GITHUB_NEW_REPO_VISIBILITY O "public" New repository visibility otherwise: private or internal.
GITHUB_TEMPLATE_REPO GITHUB_TEMPLATE_REPO O "azure/enterprise-scale-aifactory" GitHub template repository keep-as-is: Leave as-is if BYO repo.
GITHUB_USERNAME GITHUB_USERNAME M "<todo>" GitHub username or org mandatory: GitHub username or org
GITHUB_USE_SSH GITHUB_USE_SSH O "false" Use SSH for git operations otherwise: true, use SSH instead of HTTPS.
KEYVAULT_SOFT_DELETE admin_keyvaultSoftDeleteDays C "7" Key Vault soft delete days mandatory: if CMK:'true' (purge protection required). otherwise: 90 days recommended; 0 to disable.
KV_NAME_FROM_COMMON_PARAM kvNameFromCOMMON_param O "" BYO common Key Vault name otherwise: provide a custom Key Vault name.
LAKE_CONTAINER_NAME lakeContainerName O "lake3" Data lake container name
LAKE_PREFIX commonLakeNamePrefixMax8chars O "xxxyyy" Data lake storage name prefix keep-as-is: Max 8 characters.
LOGIC_APP_TYPE No verified counterpart O "Standard" Logic Apps plan type keep-as-is: Consumption is multi-tenant with NO private endpoints/VNet integration - only valid when ENABLE_PUBLIC_ACCESS_WITH_PERIMETER:'true'. Use Standard for private networking.
MAX_RETRY_ATTEMPTS maxRetryAttempts O "2" Maximum retry attempts keep-as-is: Valid values: 1, 2, or 3.
ORG_DEPARTMENT_ID org-department-id O "" Project organizational department ID keep-as-is: Text, max 128 characters, not necessarily a GUID; identical across environments. No identity or authentication effect.
ORG_DEPARTMENT_NAME org-department-name O "" Project organizational department name keep-as-is: Unicode text, max 200 characters; identical across environments, independent of cost center. No factory inheritance or Azure tag writes.
POSTGRESQL_RETRY_CAPACITY_ARRAY postgreSQLRetryCapacityArray O "true" Retry only PostgreSQL capacity errors, waiting 240 seconds before attempts 2 and 3.
POSTGRES_ADMIN_EMAILS postGresAdminEmails C "" PostgreSQL administrator email(s) mandatory: if ENABLE_POSTGRESQL:'true' ensure: single email address for the PostgreSQL administrator.
PROD_SUBSCRIPTION_ID prod_sub_id C "<todo>" PROD subscription ID recommended: separate subscription from DEV. otherwise: can reuse DEV_SUBSCRIPTION_ID. Required when deploying that environment.
PROJECT_NUMBER project_number_000 M "001" Project number mandatory: Project number keep-as-is: For 1st project. otherwise: increment to '002', '003', etc.
PROJECT_PREFIX projectPrefix O "esml-" Project resource name prefix
PROJECT_SUFFIX projectSuffix O "-rg" Project resource name suffix
PROJECT_TYPE admin_projectType O "all" Project type keep-as-is: Not used anymore. Leave as is.
STAGE_SUBSCRIPTION_ID test_sub_id C "<todo>" STAGE subscription ID recommended: separate subscription from DEV. otherwise: can reuse DEV_SUBSCRIPTION_ID. Required when deploying that environment.
TAGS tags O "{\"CostCenter\":\"9999\",\"Description\":\"AI Factory common\",\"AIF-Repo\":\"aifactory\",\"AIF-Branch\":\"aifactory-001\",\"AIF-Version\":\"1.24\",\"AIF-Submodule-Chosen-Branch\":\"release/v1.24\",\"AIF-Scaleset\":\"-001\",\"AIF-Project Owners\":\"\",\"AIFactory project\":\"001\",\"AIF-Networking\":\"true,true,true\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"true\",\"AIF-disableAgentNetworkInjection\":\"false\",\"AIF-byoASEv3\":\"false\",\"AIF-BYO_subnets\":\"false\"}" Common-level Azure resource tags (JSON) keep-as-is: Update CostCenter, Description, and branch values to match your deployment.
TAGS_PROJECT tagsProject O "{\"CostCenter\":\"1234\",\"Description\":\"RAG Chat 1\",\"AIF-Branch\":\"aifactory-001/project001\",\"AIF-Scaleset\":\"-001\",\"AIF-Environment\":\"dev\",\"AIF-Project Owners\":\"\",\"AIFactory project\":\"001\",\"AIF-Networking\":\"true,true,true\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"true\",\"AIF-disableAgentNetworkInjection\":\"false\",\"AIF-byoASEv3\":\"false\",\"AIF-BYO_subnets\":\"false\"}" Project-level Azure resource tags (JSON) keep-as-is: Update CostCenter, Description, and project values to match your project.
TAG_COSTCENTER tag_costcenter O "1234" Project cost center tag keep-as-is: Metadata for per-project cost tracking.
TAG_COSTCETER_COMMON tag_costceter_common O "9999" Common cost center tag keep-as-is: Metadata for Resource group cost tracking.
TAG_REPOSITORY tag_repository O "aifactory" Repository name tag
TAG_REPOSITORY_BRANCH tag_repository_branch O "aifactory-001" Repository branch tag otherwise: per scaleset 'aifactory-002', or per project 'aifactory-001/project001-main'.
USE_COMMON_ACR_FOR_PROJECTS useCommonACR, useCommonACR_override O "true" Use shared ACR across projects otherwise: false, each project gets its own ACR (higher cost).
USE_COMMON_ACR_OVERRIDE useCommonACR_override O "true" Use shared ACR across projects (override)
USE_SELF_HOSTED_BUILD_AGENT useSelfHostedBuildAgent O "false" Run project deployment jobs on a registered self-hosted runner
WEBAPP_RUNTIME webAppRuntime O "python" Web App runtime stack otherwise: dotnet, node, java.
WEBAPP_RUNTIME_VERSION webAppRuntimeVersion O "3.11" Web App runtime version

GHA: Services and feature switches

Exact environment key YAML / JSON counterpart(s) M/C/O Template value Description / conditions
ACR_ADMIN_USER_ENABLED acr_adminUserEnabled O "false" Enable ACR admin user otherwise: true enables admin user; false is more secure.
ACR_DEDICATED acr_dedicated O "true" Dedicated ACR (Premium only)
ACR_SKU acr_SKU O "Premium" ACR SKU keep-as-is: Premium required for private endpoints or CMK.
ADD_AI_FOUNDRY addAIFoundry O "false" Add new AI Foundry instance otherwise: true, add new Foundry even if one already exists.
ADD_AI_FOUNDRY_HUB addAIFoundryHub O "false" DEPRECATED: Add new legacy Hub v1 keep-as-is: Add new Hub even if one exists. Use ADD_AI_FOUNDRY instead.
ADD_AI_SEARCH addAISearch O "false" Add new AI Search instance otherwise: true, add new instance even if one exists.
ADD_AZURE_MACHINE_LEARNING addAzureMachineLearning O "false" Add new Azure ML workspace
ADD_BASTION_HOST addBastionHost O "false" Add Bastion Host in common RG
APIM_GATEWAY_AGGREGATE_TPM apimGatewayAggregateTpm C "" 80-90% of summed TPM across all Azure OpenAI backends. Required by the separate AI gateway workflow when APIM is enabled.
APIM_GATEWAY_API_ID apimGatewayApiId O "azure-openai-gpt55" Apim gateway api id.
APIM_GATEWAY_API_PATH apimGatewayApiPath O "openai" Apim gateway api path.
APIM_GATEWAY_ASSIGN_OPENAI_USER_ROLE apimGatewayAssignOpenAIUserRole O "false" Apim gateway assign openai user role.
APIM_GATEWAY_BACKENDS_JSON apimGatewayBackendsJson C "[]" Apim gateway backends json. Required by the separate AI gateway workflow when APIM is enabled.
APIM_GATEWAY_BACKEND_POOL_NAME apimGatewayBackendPoolName O "aoai-gpt55-pool" Apim gateway backend pool name.
APIM_GATEWAY_CALLER_TPM apimGatewayCallerTpm O "10000" Apim gateway caller tpm.
APIM_GATEWAY_RESOURCE_GROUP apimGatewayResourceGroup C "" Apim gateway resource group. Required by the separate AI gateway workflow when APIM is enabled.
APIM_GATEWAY_RETRY_COUNT apimGatewayRetryCount O "2" Apim gateway retry count.
APIM_GATEWAY_SERVICE_NAME apimGatewayServiceName C "" Apim gateway service name. Required by the separate AI gateway workflow when APIM is enabled.
APIM_GATEWAY_SKU apimGatewaySku O "StandardV2" BasicV2=dev/test; StandardV2=production default + VNet integration; PremiumV2=full private network isolation, zones, and high scale. Classic Developer/Basic/Standard/Premium cannot migrate to v2 in place. Consumption cannot use backend circuit breakers.
APIM_GATEWAY_SKU_CAPACITY apimGatewaySkuCapacity O "1" BasicV2/StandardV2 support up to 10 units; PremiumV2 supports up to 30.
APIM_GATEWAY_SUBSCRIPTION_ID apimGatewaySubscriptionId O "" Empty uses the GitHub Environment AZURE_SUBSCRIPTION_ID.
CLEAN_FOUNDRY_CAPHOST cleanFoundryCaphost O "true" Clean Foundry capability hosts before redeployment otherwise: true, deletes capability hosts before redeployment (useful when switching caphost configuration).
DATABRICKS_OID databricksOID C "<todo>" Databricks object ID mandatory: if ENABLE_DATABRICKS:'true' ensure: find Databricks object ID in Entra ID.
DATABRICKS_PRIVATE databricksPrivate O "true" Databricks private control plane otherwise: false, only data plane is private; control plane is public.
DISABLE_WHITELISTING_FOR_BUILD_AGENTS disable_whitelisting_for_build_agents O "false" Disable runner IP whitelisting otherwise: true, skip whitelisting (use only if runner already has network access).
ELASTIC_COMPANY_NAME elasticCompanyName C "Organization" Elastic Cloud company name mandatory: if ENABLE_ELASTICSEARCH:'true'
ELASTIC_DEPLOYMENT_SIZE elasticDeploymentSize O "small" Elasticsearch deployment size otherwise: medium or large.
ELASTIC_EMAIL elasticEmail C "admin@example.com" Elastic Cloud account email mandatory: if ENABLE_ELASTICSEARCH:'true' ensure: valid email address.
ELASTIC_FIRST_NAME elasticFirstName C "AI" Elastic Cloud contact first name mandatory: if ENABLE_ELASTICSEARCH:'true'
ELASTIC_LAST_NAME elasticLastName C "Factory" Elastic Cloud contact last name mandatory: if ENABLE_ELASTICSEARCH:'true'
ELASTIC_SKU elasticSku, skuElasticDev, skuElasticStageProd O "ess-consumption-2024_Monthly" Elastic Cloud SKU
ELASTIC_TYPE elasticType O "ElasticCloud" Elasticsearch deployment type otherwise: SelfManagedOnAKS (future support).
ENABLE_ADMIN_VM enableAdminVM O "false" Enable Admin VM in common RG
ENABLE_AIFACTORY_CREATED_DEFAULT_PROJECT_FOR_AIFV2 enableAIFactoryCreatedDefaultProjectForAIFv2 O "true" AI Factory default project for AIFv2
ENABLE_AI_DOC_INTELLIGENCE enableAIDocIntelligence O "false" Enable Azure AI Document Intelligence
ENABLE_AI_FACTORY_HUB enableAIFactoryHub O "false" Own AI Factory Hub intent
ENABLE_AI_FOUNDRY enableAIFoundry C "true" Enable AI Foundry mandatory: Enable AI Foundry recommended: enterprise-grade private networking, BYOvNet. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths.
ENABLE_AI_FOUNDRY_HUB enableAIFoundryHub O "false" DEPRECATED: Legacy AI Foundry Hub v1 keep-as-is: Legacy Hub (v1). Use ENABLE_AI_FOUNDRY instead.
ENABLE_AI_SEARCH enableAISearch C "true" Required capability-host vector store for private Foundry standard agents. mandatory: Required capability-host vector store for private Foundry standard agents. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths.
ENABLE_AI_SEARCH_SHARED_PRIVATE_LINK enableAISearchSharedPrivateLink O "true" Enable AI Search shared private link
ENABLE_AI_SERVICES enableAIServices O "false" DEPRECATED: Standalone AI Services account keep-as-is: Replaced by ENABLE_AI_FOUNDRY. Requires ENABLE_AI_SERVICES:'true' for legacy Hub v1.
ENABLE_AKS enableAKS O "false" Deploy standalone AKS cluster keep-as-is: Independent of Azure ML, for general container workloads.
ENABLE_AMPLS enableAMPLS O "false" Enable AMPLS in Hub otherwise: true, AMPLS created in Hub subscription; AppInsights in private/private mode.
ENABLE_APIM ENABLE_APIM O "false" Enable apim.
ENABLE_APPINSIGHTS_DASHBOARD enableAppInsightsDashboard O "false" Enable Application Insights dashboard
ENABLE_APPLICATION_INSIGHTS enableApplicationInsights O "true" Workspace-based project Application Insights
ENABLE_AZURE_AI_VISION enableAzureAIVision O "false" Enable Azure AI Vision
ENABLE_AZURE_MACHINE_LEARNING enableAzureMachineLearning O "false" Enable Azure Machine Learning
ENABLE_AZURE_MCP_SERVER enableAzureMcpServer O "false" Enable the private, read-only Azure MCP server after its project configuration is prepared
ENABLE_AZURE_OPENAI enableAzureOpenAI O "false" Enable Azure OpenAI standalone account otherwise: true, deploy a standalone Azure OpenAI resource (separate from AI Foundry).
ENABLE_AZURE_SPEECH enableAzureSpeech O "false" Enable Azure AI Speech
ENABLE_BING enableBing O "false" Enable Bing Search
ENABLE_BING_CUSTOM_SEARCH enableBingCustomSearch O "false" Enable Bing Custom Search
ENABLE_BOT_SERVICE enableBotService O "true" Enable Azure Bot Service
ENABLE_CONTAINER_APPS enableContainerApps O "false" Enable Azure Container Apps
ENABLE_CONTENT_SAFETY enableContentSafety O "false" Enable Azure AI Content Safety
ENABLE_COSMOS_DB enableCosmosDB C "true" Required capability-host thread and agent-history store for private Foundry standard agents. mandatory: Required capability-host thread and agent-history store for private Foundry standard agents. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths.
ENABLE_DATABRICKS enableDatabricks O "false" Enable Azure Databricks
ENABLE_DATAFACTORY enableDatafactory O "false" Enable Azure Data Factory
ENABLE_DATAFACTORY_COMMON enableDatafactoryCommon O "false" Enable Data Factory in common RG
ENABLE_DEFENDER_FOR_AI_RESOURCE_LEVEL enableDefenderforAIResourceLevel O "false" Defender for AI at resource level keep-as-is: Per-resource Microsoft Defender for AI protection.
ENABLE_DEFENDER_FOR_AI_SUB_LEVEL enableDefenderforAISubLevel O "false" Defender for AI at subscription level keep-as-is: Subscription-level Microsoft Defender for AI protection.
ENABLE_DELETE_FOR_DISABLED_RESOURCES enableDeleteForDisabledResources O "false" Delete disabled services keep-as-is: true, delete resources that exist but are disabled (ENABLE_* flag = false). otherwise: false, keep all existing resources.
ENABLE_ELASTICSEARCH enableElasticsearch O "false" Enable Elasticsearch (Elastic Cloud)
ENABLE_EVENT_HUBS enableEventHubs O "false" Enable Azure Event Hubs
ENABLE_FOUNDRY_CAPHOST enableAFoundryCaphost C "true" Required for this private Foundry standard-agent architecture. Cannot be disabled; binds Cosmos DB, AI Search, and project Storage. mandatory: Required for this private Foundry standard-agent architecture. Cannot be disabled; binds Cosmos DB, AI Search, and project Storage. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths.
ENABLE_FUNCTION enableFunction O "false" Enable Azure Functions
ENABLE_KONG ENABLE_KONG O "false" Enable kong.
ENABLE_LOGIC_APPS enableLogicApps O "false" Enable Azure Logic Apps
ENABLE_POSTGRESQL enablePostgreSQL O "false" Enable Azure PostgreSQL Flexible Server
ENABLE_REDIS_CACHE enableRedisCache O "false" Enable Azure Cache for Redis
ENABLE_RETRIES enableRetries O "false" Enable automatic job retries otherwise: true, enables retry logic for GenAI services deployment.
ENABLE_SQL_DATABASE enableSQLDatabase O "false" Enable Azure SQL Database
ENABLE_WEBAPP enableWebApp O "false" Enable Azure Web App
FOUNDRY_API_MANAGEMENT_RESOURCE_ID foundryApiManagementResourceId O "" Existing APIM resource ID for AI Foundry integration keep-as-is: Leave empty for no APIM integration. otherwise: provide full resourceId of existing API Management instance.
FOUNDRY_DEPLOYMENT_TYPE foundryDeploymentType O "2" <deprecated>Retained for configuration compatibility. AI Foundry always uses the second-option account deployment.
KONG_CONSUMER_API_KEY No verified counterpart C "" Stored as an environment secret, never a variable. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret.
KONG_GATEWAY_APIM_HOST kongGatewayApimHost C "" Kong gateway apim host. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret.
KONG_GATEWAY_CPU kongGatewayCpu O "2" Kong gateway cpu.
KONG_GATEWAY_IMAGE kongGatewayImage O "kong/kong-gateway:3.9" Kong gateway image.
KONG_GATEWAY_MEMORY_GB kongGatewayMemoryGb O "4" Kong gateway memory gb.
SERVICE_SETTING_DEPLOY_PROJECT_VM serviceSettingDeployProjectVM O "false" Deploy VM in project resource group otherwise: true, deploy a jumpbox VM for use with Azure Bastion.
UPDATE_AI_FOUNDRY updateAIFoundry O "false" Update AI Foundry properties otherwise: true, update existing Foundry properties and RBAC.

GHA: Networking, DNS and existing resources

Exact environment key YAML / JSON counterpart(s) M/C/O Template value Description / conditions
ACR_IP_WHITELIST acr_IP_whitelist O "" ACR IP allowlist for selected networks keep-as-is: comma-separated approved IPv4 addresses/ranges for ACR.
ALLOW_PUBLIC_ACCESS_WHEN_BEHINDVNET No verified counterpart O "true" Public UI access when behind vNet recommended: false to enable fully private networking.
BYO_ASEV3 byoASEv3 O "false" Bring your own ASEv3 otherwise: true, use a pre-existing App Service Environment v3.
BYO_ASE_APP_SERVICE_PLAN_RESOURCE_ID byoAseAppServicePlanResourceId C "" BYO App Service Plan resource ID mandatory: if BYO_ASEV3:'true' and re-using an existing App Service Plan.
BYO_ASE_FULL_RESOURCE_ID byoAseFullResourceId C "/subscriptions/...<todo><todo_if_BYO_ASEV3_is_true>yourASEnameS2" BYO ASEv3 full resource ID mandatory: if BYO_ASEV3:'true' ensure: full resource ID of the existing ASEv3.
BYO_CONTRIBUTOR_ROLE_ID BYOContributorRoleID O "b24988ac-6180-42a0-ab88-20f7382dd24c" Contributor role ID keep-as-is: Built-in Contributor role ID. otherwise: provide a custom role ID for finer-grained access control.
BYO_SUBNETS BYO_subnets O "false" Bring your own subnets otherwise: true, uses pre-existing subnets defined by the BYO subnet variables below.
CENTRAL_DNS_ZONE_BY_POLICY_IN_HUB centralDnsZoneByPolicyInHub O "false" Centralized DNS via Hub policy otherwise: true, uses central private DNS zones in HUB resource group managed by Azure Policy.
COMMON_BASTION_SUBNET_CIDR common_bastion_subnet_cidr O "172.16.XX.192/26" Bastion subnet CIDR template
COMMON_BASTION_SUBNET_NAME common_bastion_subnet_name O "AzureBastionSubnet" Bastion subnet name keep-as-is: Must be exactly 'AzureBastionSubnet'.
COMMON_PBI_SUBNET_CIDR common_pbi_subnet_cidr O "172.16.XX.128/26" Power BI subnet CIDR template
COMMON_PBI_SUBNET_NAME common_pbi_subnet_name O "snet-esml-cmn-pbi-001" Power BI subnet name
COMMON_SUBNET_CIDR common_subnet_cidr O "172.16.XX.0/26" Common subnet CIDR template keep-as-is: XX is replaced by the environment CIDR range value.
COMMON_SUBNET_SCORING_CIDR common_subnet_scoring_cidr O "172.16.XX.64/26" Common scoring subnet CIDR template
COMMON_VNET_CIDR common_vnet_cidr O "172.16.XX.0/18" Common vNet CIDR keep-as-is: XX must be network-aligned; environments must not overlap. Address intent only, not actual peering.
DEV_CIDR_RANGE dev_cidr_range M "0" DEV network-aligned XX value mandatory: DEV network-aligned XX value keep-as-is: VNet 172.16.0.0/18.
DEV_NETWORK_ENV network_env_dev O "dev-" DEV environment prefix for BYO subnets otherwise: set to empty string if not using environment-prefixed naming.
DISABLE_AGENT_NETWORK_INJECTION disableAgentNetworkInjection O "false" Disable agent network injection otherwise: true, disables network injection. Requires Class B/C network ranges (172.16/12 or 192.168/16).
DISABLE_SUBNET_JOIN_ACTION disableSubnetJoinAction O "false" Disable VNet subnet join RBAC recommended: false, grants Network Contributor role for subnet join actions (required for APIM, Container Apps, AKS). otherwise: true, skip if subnet permissions managed externally.
ENABLE_PUBLIC_ACCESS_WITH_PERIMETER enablePublicAccessWithPerimeter O "true" Public access with network perimeter recommended: false to enable fully private networking.
ENABLE_PUBLIC_GENAI_ACCESS enablePublicGenAIAccess O "true" Public GenAI access (control plane) recommended: false to enable fully private networking.
KONG_GATEWAY_SUBNET_CIDR kongGatewaySubnetCidr C "" Kong gateway subnet cidr. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret.
KONG_GATEWAY_SUBNET_NAME kongGatewaySubnetName O "snet-kong-001" Kong gateway subnet name.
KONG_GATEWAY_VNET_NAME kongGatewayVnetName C "" Kong gateway vnet name. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret.
KONG_GATEWAY_VNET_RESOURCE_GROUP kongGatewayVnetResourceGroup C "" Kong gateway vnet resource group. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret.
PRIV_DNS_RESOURCE_GROUP_PARAM privDnsResourceGroup_param C "<todo>" Hub DNS resource group mandatory: if CENTRAL_DNS_ZONE_BY_POLICY_IN_HUB:'true' ensure: Hub connectivity resource group.
PRIV_DNS_SUBSCRIPTION_PARAM privDnsSubscription_param C "<todo>" Hub DNS subscription ID mandatory: if CENTRAL_DNS_ZONE_BY_POLICY_IN_HUB:'true' ensure: Hub connectivity subscription ID.
PROD_CIDR_RANGE prod_cidr_range M "128" PROD network-aligned XX value mandatory: PROD network-aligned XX value keep-as-is: VNet 172.16.128.0/18.
PROD_NETWORK_ENV network_env_prod O "prod-" PROD environment prefix for BYO subnets otherwise: 'pr-', or empty string.
PROJECT_MEMBERS_IP_ADDRESS project_IP_whitelist C "-" Project UI IP allowlist mandatory: if using IP-whitelisting networking mode ensure: comma-separated IPv4 addresses without spaces.
RUN_JOB1_NETWORKING runNetworkingVar M "true" Run networking module mandatory: Run networking module keep-as-is: true when creating or updating a project. otherwise: false, to skip networking on service-only updates.
SCALING_MODE scaling-mode O "shared-subscriptions" Address-planning preset: own-subscriptions or shared-subscriptions; no subscription provisioning, network resizing, or peering.
STAGE_CIDR_RANGE test_cidr_range M "64" STAGE network-aligned XX value mandatory: STAGE network-aligned XX value keep-as-is: VNet 172.16.64.0/18.
STAGE_NETWORK_ENV network_env_stage O "stage-" STAGE environment prefix for BYO subnets otherwise: 'tst-', 'test-', or empty string.
SUBNET_COMMON subnetCommon C "" BYO common subnet name mandatory: if BYO_SUBNETS:'true'
SUBNET_COMMON_BASE common_subnet_name O "snet-esml-cmn-001" Common subnet base name
SUBNET_COMMON_POWERBI_GW subnetCommonPowerbiGw O "" BYO Power BI gateway subnet name
SUBNET_COMMON_SCORING subnetCommonScoring C "" BYO common scoring subnet name mandatory: if BYO_SUBNETS:'true'
SUBNET_PROJ_ACA subnetProjACA C "" BYO Container Apps project subnet name mandatory: if ENABLE_CONTAINER_APPS:'true' and BYO_SUBNETS:'true'
SUBNET_PROJ_ACA2 subnetProjACA2 O "" BYO Container Apps secondary project subnet name
SUBNET_PROJ_AKS subnetProjAKS C "" BYO AKS project subnet name mandatory: if ENABLE_AKS_FOR_AZURE_ML:'true' and BYO_SUBNETS:'true'
SUBNET_PROJ_AKS2 subnetProjAKS2 O "" BYO AKS secondary project subnet name
SUBNET_PROJ_DATABRICKS_PRIVATE subnetProjDatabricksPrivate C "" BYO Databricks private subnet name mandatory: if ENABLE_DATABRICKS:'true' and BYO_SUBNETS:'true'
SUBNET_PROJ_DATABRICKS_PUBLIC subnetProjDatabricksPublic C "" BYO Databricks public subnet name mandatory: if ENABLE_DATABRICKS:'true' and BYO_SUBNETS:'true'
SUBNET_PROJ_GENAI subnetProjGenAI C "" BYO GenAI project subnet name mandatory: if BYO_SUBNETS:'true'
SUBNET_PROJ_WEBAPP subnetProjWebapp C "" BYO App Service/Function VNet-integration project subnet name mandatory: if (ENABLE_WEB_APP:'true' OR ENABLE_FUNCTION:'true') and BYO_SUBNETS:'true'
VNET_NAME_BASE vnetNameBase O "vnt-esmlcmn" Common vNet base name keep-as-is: Base name of the common virtual network.
VNET_NAME_FULL_PARAM vnetNameFull_param C "" BYO vNet full name mandatory: if BYO_SUBNETS:'true' ensure: full name of the existing virtual network.
VNET_RESOURCE_GROUP_BASE vnetResourceGroupBase O "esml-common" Common vNet resource group base name keep-as-is: Base name of the common vNet's resource group (used when not BYOvNet).
VNET_RESOURCE_GROUP_PARAM vnetResourceGroup_param C "" BYO vNet resource group mandatory: if BYO_SUBNETS:'true' ensure: resource group of the existing vNet.

GHA: Per-environment SKUs and compute sizing

Exact environment key YAML / JSON counterpart(s) M/C/O Template value Description / conditions
ADMIN_AKS_GPU_SKU_DEV_OVERRIDE admin_aks_gpu_sku_dev_override O "Standard_D4s_v5" AKS system node VM SKU for DEV ensure: use an AKS-supported system-pool SKU; configure GPU workloads in a separate user pool.
ADMIN_AKS_GPU_SKU_TEST_PROD_OVERRIDE admin_aks_gpu_sku_test_prod_override O "Standard_DS13-2_v2" AKS GPU SKU for TEST/PROD
ADMIN_AKS_NODES_DEV_OVERRIDE admin_aks_nodes_dev_override O "2" AKS system node count for DEV
ADMIN_AKS_NODES_TEST_PROD_OVERRIDE admin_aks_nodes_testProd_override O "3" AKS node count for TEST/PROD
ADMIN_AKS_VERSION_OVERRIDE admin_aks_version_override O "1.35.7" AKS Kubernetes version ensure: version has standard support in your region.
ADMIN_AML_CLUSTER_MAX_NODES_DEV_OVERRIDE admin_aml_cluster_maxNodes_dev_override O "3" AML cluster max nodes for DEV
ADMIN_AML_CLUSTER_MAX_NODES_TEST_PROD_OVERRIDE admin_aml_cluster_maxNodes_testProd_override O "5" AML cluster max nodes for TEST/PROD
ADMIN_AML_CLUSTER_SKU_DEV_OVERRIDE admin_aml_cluster_sku_dev_override O "Standard_DS3_v2" AML cluster VM SKU for DEV
ADMIN_AML_CLUSTER_SKU_TEST_PROD_OVERRIDE admin_aml_cluster_sku_testProd_override O "Standard_D13_v2" AML cluster VM SKU for TEST/PROD
ADMIN_AML_COMPUTE_INSTANCE_DEV_SKU_OVERRIDE admin_aml_computeInstance_dev_sku_override O "Standard_DS11_v2" AML compute instance SKU for DEV
ADMIN_AML_COMPUTE_INSTANCE_TEST_PROD_SKU_OVERRIDE admin_aml_computeInstance_testProd_sku_override O "Standard_ND96amsr_A100_v4" AML compute instance SKU for TEST/PROD
ADMIN_VM_SIZE adminVMSize O "Standard_D2s_v5" Admin VM size keep-as-is: Override when the regional SKU is unavailable.
AKS_AZURE_FIREWALL_PRIVATE_IP aksAzureFirewallPrivateIp C "" Azure Firewall private IP for AKS mandatory: if AKS_OUTBOUND_TYPE:'userDefinedRouting'
AKS_ENABLE_PRIVATE_CLUSTER aksEnablePrivateCluster O "true" Enable private AKS cluster
AKS_OUTBOUND_TYPE aksOutboundType O "loadBalancer" AKS outbound network type otherwise: userDefinedRouting for firewall/UDR scenarios.
AKS_PRIVATE_DNS_ZONE aksPrivateDNSZone O "system" AKS private DNS zone otherwise: none, or full resourceId of an existing private DNS zone.
AKS_SKU_NAME aksSkuName O "Base" AKS SKU name otherwise: Standard for production.
AKS_SKU_TIER No verified counterpart O "Standard" AKS SKU tier otherwise: Free or Premium.
ENABLE_AKS_FOR_AZURE_ML enableAksForAzureML C "true" Enable AKS for Azure ML inference mandatory: if ENABLE_AZURE_MACHINE_LEARNING:'true'
SKU_AISEARCH_DEV skuAISearchDev O "basic" AI Search SKU for Dev. Must be included in SKU_ARRAY_AISEARCH_DEV when retry is enabled.
SKU_AISEARCH_STAGEPROD skuAISearchStageProd O "standard" AI Search SKU for Stage and Prod. Must be included in SKU_ARRAY_AISEARCH_STAGEPROD when retry is enabled.
SKU_AISERVICES_DEV skuAIServicesDev O "S0" Azure AI Services (multi-service account) SKU Dev
SKU_AISERVICES_STAGEPROD skuAIServicesStageProd O "S0" Azure AI Services SKU Stage/Prod
SKU_AI_SEARCH_DEV_ARRAY skuAISearchDevArray O "[\"basic\",\"standard\",\"standard2\"]" Sku ai search dev array.
SKU_AI_SEARCH_STAGE_PROD_ARRAY skuAISearchStageProdArray O "[\"basic\",\"standard\",\"standard2\"]" Sku ai search stage prod array.
SKU_AKS_DEV skuAksDev O "" AKS SKU Dev keep-as-is: Leave empty for managed/auto SKU.
SKU_AKS_STAGEPROD skuAksStageProd O "" AKS SKU Stage/Prod
SKU_ARRAY_AISEARCH_DEV skuArrayAISearchDev O "basic,standard,standard2" Ordered Azure AI Search capacity fallback candidates (one to three SKUs).
SKU_ARRAY_AISEARCH_STAGEPROD skuArrayAISearchStageProd O "basic,standard,standard2" Ordered Azure AI Search capacity fallback candidates (one to three SKUs).
SKU_ARRAY_CONTAINER_APPS_DEV skuArrayContainerAppsDev O "Consumption,D4,D8" Ordered capacity fallback profiles; D4/D8 have dedicated pricing.
SKU_ARRAY_CONTAINER_APPS_STAGEPROD skuArrayContainerAppsStageProd O "Consumption,D4,D8" Ordered capacity fallback profiles; D4/D8 have dedicated pricing.
SKU_ARRAY_POSTGRESQL_DEV skuArrayPostgreSQLDev O "Standard_B1ms,Standard_B2s,Standard_B2ms" Ordered regional/SKU capacity fallback candidates; selected Dev SKU first.
SKU_ARRAY_POSTGRESQL_STAGEPROD skuArrayPostgreSQLStageProd O "Standard_B1ms,Standard_B2s,Standard_B2ms" Ordered regional/SKU capacity fallback candidates; selected Stage/Prod SKU first.
SKU_AZUREML_DEV skuAzureMLDev O "basic" Azure ML workspace SKU Dev
SKU_AZUREML_STAGEPROD skuAzureMLStageProd O "basic" Azure ML workspace SKU Stage/Prod
SKU_BING_DEV skuBingDev O "G2" Bing Custom Search SKU Dev keep-as-is: ['G2']
SKU_BING_STAGEPROD skuBingStageProd O "G2" Bing Custom Search SKU Stage/Prod
SKU_BOTSERVICE_DEV skuBotServiceDev O "S1" Bot Service SKU Dev keep-as-is: ['F0','S1']
SKU_BOTSERVICE_STAGEPROD skuBotServiceStageProd O "S1" Bot Service SKU Stage/Prod
SKU_CONTAINER_APPS_DEV skuContainerAppsDev O "Consumption" Container Apps workload profile Dev ['Consumption','D4','D8'].
SKU_CONTAINER_APPS_STAGEPROD skuContainerAppsStageProd O "Consumption" Container Apps workload profile Stage/Prod.
SKU_CONTENTSAFETY_DEV skuContentSafetyDev O "S0" Content Safety SKU Dev
SKU_CONTENTSAFETY_STAGEPROD skuContentSafetyStageProd O "S0" Content Safety SKU Stage/Prod
SKU_DATABRICKS_DEV skuDatabricksDev O "premium" Databricks workspace SKU Dev keep-as-is: ['standard','premium','trial']
SKU_DATABRICKS_STAGEPROD skuDatabricksStageProd O "premium" Databricks workspace SKU Stage/Prod
SKU_DOCINTELLIGENCE_DEV skuDocIntelligenceDev O "S0" Document Intelligence SKU Dev
SKU_DOCINTELLIGENCE_STAGEPROD skuDocIntelligenceStageProd O "S0" Document Intelligence SKU Stage/Prod
SKU_ELASTIC_DEV skuElasticDev O "ess-consumption-2024_Monthly" Elastic Cloud SKU Dev
SKU_ELASTIC_STAGEPROD skuElasticStageProd O "ess-consumption-2024_Monthly" Elastic Cloud SKU Stage/Prod
SKU_EVENTHUBS_DEV skuEventHubsDev O "Basic" Event Hubs namespace SKU Dev keep-as-is: ['Basic','Standard','Premium']
SKU_EVENTHUBS_STAGEPROD skuEventHubsStageProd O "Basic" Event Hubs namespace SKU Stage/Prod
SKU_FUNCTION_DEV skuFunctionDev O "EP1" Function plan SKU Dev
SKU_FUNCTION_STAGEPROD skuFunctionStageProd O "EP1" Function plan SKU Stage/Prod
SKU_LOGICAPPS_DEV skuLogicAppsDev O "WS1" Logic Apps (Standard) SKU Dev
SKU_LOGICAPPS_STAGEPROD skuLogicAppsStageProd O "WS1" Logic Apps (Standard) SKU Stage/Prod
SKU_OPENAI_DEV skuOpenAIDev O "S0" Azure OpenAI SKU Dev
SKU_OPENAI_STAGEPROD skuOpenAIStageProd O "S0" Azure OpenAI SKU Stage/Prod
SKU_POSTGRESQL_DEV skuPostgreSQLDev O "Standard_B1ms" PostgreSQL compute SKU Dev
SKU_POSTGRESQL_STAGEPROD skuPostgreSQLStageProd O "Standard_B1ms" PostgreSQL compute SKU Stage/Prod
SKU_REDIS_DEV skuRedisDev O "Standard" Redis SKU Dev keep-as-is: ['Basic','Standard','Premium']
SKU_REDIS_STAGEPROD skuRedisStageProd O "Standard" Redis SKU Stage/Prod
SKU_SPEECH_DEV skuSpeechDev O "S0" Azure AI Speech SKU Dev
SKU_SPEECH_STAGEPROD skuSpeechStageProd O "S0" Azure AI Speech SKU Stage/Prod
SKU_SQLDATABASE_DEV skuSQLDatabaseDev O "S0" Azure SQL DB (DTU model) SKU Dev
SKU_SQLDATABASE_STAGEPROD skuSQLDatabaseStageProd O "S0" Azure SQL DB (DTU model) SKU Stage/Prod
SKU_STORAGEACCOUNT_DEV skuStorageAccountDev O "Standard_LRS" Project Storage Account SKU Dev keep-as-is: ['Standard_LRS','Standard_GRS','Standard_RAGRS','Standard_ZRS','Premium_LRS','Premium_ZRS','Standard_GZRS','Standard_RAGZRS']
SKU_STORAGEACCOUNT_STAGEPROD skuStorageAccountStageProd O "Standard_LRS" Project Storage Account SKU Stage/Prod
SKU_TIER_AKS_DEV skuTierAksDev O "Standard" AKS tier Dev keep-as-is: ['Free','Standard','Premium']
SKU_TIER_AKS_STAGEPROD skuTierAksStageProd O "Standard" AKS tier Stage/Prod
SKU_TIER_AZUREML_DEV skuTierAzureMLDev O "basic" Azure ML workspace tier Dev
SKU_TIER_AZUREML_STAGEPROD skuTierAzureMLStageProd O "basic" Azure ML workspace tier Stage/Prod
SKU_TIER_FUNCTION_DEV skuTierFunctionDev O "ElasticPremium" Function plan tier Dev
SKU_TIER_FUNCTION_STAGEPROD skuTierFunctionStageProd O "ElasticPremium" Function plan tier Stage/Prod
SKU_TIER_POSTGRESQL_DEV skuTierPostgreSQLDev O "Burstable" PostgreSQL tier Dev keep-as-is: ['Burstable','GeneralPurpose','MemoryOptimized']
SKU_TIER_POSTGRESQL_STAGEPROD skuTierPostgreSQLStageProd O "Burstable" PostgreSQL tier Stage/Prod
SKU_TIER_SQLDATABASE_DEV skuTierSQLDatabaseDev O "Standard" Azure SQL DB tier Dev keep-as-is: ['Basic','Standard','Premium']
SKU_TIER_SQLDATABASE_STAGEPROD skuTierSQLDatabaseStageProd O "Standard" Azure SQL DB tier Stage/Prod
SKU_TIER_WEBAPP_DEV skuTierWebAppDev O "PremiumV3" Web App plan tier Dev
SKU_TIER_WEBAPP_STAGEPROD skuTierWebAppStageProd O "PremiumV3" Web App plan tier Stage/Prod
SKU_VISION_DEV skuVisionDev O "S1" Azure AI Vision SKU Dev
SKU_VISION_STAGEPROD skuVisionStageProd O "S1" Azure AI Vision SKU Stage/Prod
SKU_WEBAPP_DEV skuWebAppDev O "P1v3" Web App plan SKU Dev
SKU_WEBAPP_STAGEPROD skuWebAppStageProd O "P1v3" Web App plan SKU Stage/Prod

GHA: Identity, access and encryption

Exact environment key YAML / JSON counterpart(s) M/C/O Template value Description / conditions
APIM_GATEWAY_MANAGED_IDENTITY_PRINCIPAL_ID apimGatewayManagedIdentityPrincipalId C "" Apim gateway managed identity principal id. Required when assigning the OpenAI user role to the APIM managed identity.
AZURE_MACHINELEARNING_SP_OID azure_machinelearning_sp_oid C "<todo>" Azure ML service principal OID mandatory: Azure ML service principal OID ensure: find in Entra ID as 'Azure Machine Learning' app. otherwise: optional if ENABLE_AI_FOUNDRY:'false'.
CMK cmk O "false" Customer Managed Key encryption otherwise: true enables CMEK where supported. Requires KEYVAULT_SOFT_DELETE > 7 days.
CMK_DISABLE_FOR_AI_SEARCH cmkDisableForAISearch O "true" Disable CMK for AI Search otherwise: false, enables CMK encryption for AI Search even when CMK:'true'.
CMK_DISABLE_FOR_FOUNDRY cmkDisableForFoundry O "true" Disable CMK for AI Foundry otherwise: false, enables CMK encryption for AI Foundry even when CMK:'true'.
CMK_KEY_NAME cmkKeyName C "<todo>aifactory-cmk-key" CMK key name in seeding KV mandatory: if CMK:'true' ensure: key must exist in seeding Key Vault.
CMK_KEY_VERSION cmkKeyVersion O "" CMK key version keep-as-is: Leave empty to always use the latest key version.
COMMON_SERVICE_PRINCIPAL_KV_S_NAME_APPID No verified counterpart C "<optional>esml-common-bicep-sp-id" Seeding KV secret name for common SP App ID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
COMMON_SERVICE_PRINCIPAL_KV_S_NAME_SECRET No verified counterpart C "<optional>esml-common-bicep-sp-secret" Seeding KV secret name for common SP secret ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
COMMON_SERVICE_PRINCIPLE_OID_KEY commonServicePrincipleOIDKey C "<todo>esml-common-sp-oid" Seeding KV secret name for common SP OID mandatory: Seeding KV secret name for common SP OID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
DEBUG_DISABLE_100_RBAC_SECURITY debug_disable_100_rbac_security O "false" Disable step 100: RBAC & Security keep-as-is: RBAC assignments for steps 61-99.
DISABLE_CONTRIBUTOR_ACCESS_FORUSERS disableContributorAccessForUsers O "false" Disable Contributor for project users recommended: true, restrict direct Contributor for better governance.
DISABLE_LOCAL_AUTH disableLocalAuth O "true" Disable local API key ("admin account") auth on Cognitive/AI Services & Foundry, AAD-only recommended: true, disables key auth (many orgs forbid keys). otherwise: false, allow local API keys.
DISABLE_RBAC_ADMIN_ON_RG_FORUSERS disableRBACAdminOnRGForUsers O "false" Disable RBAC Admin on RG for project users recommended: true, restrict RBAC Admin on resource group for better governance.
GROUPS_CORETEAM_MEMBERS groups_coreteam_members M "<aif001sdc_coreteam_admin_p080>,<aif001sdc_coreteam_dataops_p081>,<aif001sdc_coreteam_dataops_fabric_p082>" Core team Entra ID group OIDs mandatory: Core team Entra ID group OIDs ensure: 3 comma-separated AD group ObjectIDs matching personas in PERSONAS_CORE_TEAM.
GROUPS_PROJECT_MEMBERS_ESML groups_project_members_esml M "<aif001sdc_prj001_team_lead_p001>,<aif001sdc_prj001_team_member_ds_p002>,<aif001sdc_prj001_team_member_fend_p003>" ESML project team Entra ID group OIDs mandatory: ESML project team Entra ID group OIDs ensure: 3 comma-separated AD group ObjectIDs matching personas in PERSONAS_PROJECT_ESML.
GROUPS_PROJECT_MEMBERS_GENAI_1 groups_project_members_genai_1 M "<aif001sdc_prj002_team_lead_p011>,<aif001sdc_prj002_genai_team_member_aifoundry_p012>,<aif002sdc_prj001_genai_team_member_agentic_p013>,<aif001sdc_prj001_genai_team_member_dataops_p014>,<aif001sdc_prj001_team_member_fend_p015>" GenAI-1 project team Entra ID group OIDs mandatory: GenAI-1 project team Entra ID group OIDs ensure: 5 comma-separated AD group ObjectIDs matching personas in PERSONAS_PROJECT_GENAI_1.
INPUT_COMMON_SPID_KEY inputCommonSPIDKey C "<todo>esml-common-sp-id" Seeding KV secret name for common SP App ID mandatory: Seeding KV secret name for common SP App ID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
INPUT_COMMON_SP_SECRET_KEY inputCommonSPSecretKey C "<todo>esml-common-sp-secret" Seeding KV secret name for common SP secret mandatory: Seeding KV secret name for common SP secret ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
PERSONAS_CORE_TEAM personas_core_team O "p080_coreteam_it_admin,coreteam_dataops,p081_coreteam_dataops_fabric, p103_coreteam_team_process_ops" Core team persona list keep-as-is: 4 personas (3 user, 1 SP). Mapped to GROUPS_CORETEAM_MEMBERS.
PERSONAS_PROJECT_ESML personas_project_esml O "p001_esml_team_lead,p002_esml_team_member_datascientist,p003_esml_team_member_front_end,p101_esml_team_process_ops" ESML project persona list keep-as-is: 4 personas (3 user, 1 SP). Mapped to GROUPS_PROJECT_MEMBERS_ESML.
PERSONAS_PROJECT_GENAI_1 personas_project_genai_1 O "p011_genai_team_lead,p012_genai_team_member_aifoundry,p013_genai_team_member_agentic,p014_genai_team_member_dataops,p015_genai_team_member_frontend,p102_esml_team_process_ops" GenAI-1 project persona list keep-as-is: 6 personas (5 user, 1 SP). Mapped to GROUPS_PROJECT_MEMBERS_GENAI_1.
PROJECT_MEMBERS technical_admins_ad_object_id M "<todo>_object_id" Project team Entra ID object ID(s) mandatory: Project team Entra ID object ID(s) ensure: comma-separated ObjectIDs of users or AD groups (when USE_AD_GROUPS:'true').
PROJECT_MEMBERS_EMAILS technical_admins_email O "<todo>_EntraID-Security-Group-Name" Project team contact email or group name recommended: set for better project tracking.
PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID project_service_principal_AppID_seeding_kv_name C "<optional>esml-project001-sp-id" Project SP App ID secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_OID project_service_principal_OID_seeding_kv_name C "<optional>esml-project001-sp-oid" Project SP OID secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_S project_service_principal_Secret_seeding_kv_name C "<optional>esml-project001-sp-secret" Project SP secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value.
TENANT_AZUREML_OID azure_machinelearning_sp_oid C "<todo>" Azure ML service principal OID mandatory: Azure ML service principal OID ensure: find in Entra ID as 'Azure Machine Learning' app (AppId: 0736f41a-0425-4b46-bdb5-1563eff02385). otherwise: optional if ENABLE_AI_FOUNDRY:'false'.
TENANT_ID tenantId M "<todo>" Azure tenant ID mandatory: Azure tenant ID ensure: find in Azure Portal > Entra ID > Overview (Directory ID).
UPDATE_KEYVAULT_RBAC updateKeyvaultRbac O "false" Update Key Vault RBAC otherwise: true enables updating KV RBAC by rerunning the pipeline.
USE_AD_GROUPS use_ad_groups O "true" Use AD groups for project members otherwise: false, use individual ObjectIDs and simple mode Personas.

GHA: Operations, diagnostics and lifecycle

Exact environment key YAML / JSON counterpart(s) M/C/O Template value Description / conditions
DEBUG_DISABLE_05_BUILD_ACR_IMAGE debug_disable_05_build_acr_image O "false" Disable ACR image build step keep-as-is: Cannot be disabled if ContainerApps is enabled (requires ACR networking with runner IP allowlist).
DEBUG_DISABLE_10_AIFACTORY_DASHBOARDS debug_disable_10_aifactory_dashboards O "true" Disable AI Factory Dashboards step
DEBUG_DISABLE_61_FOUNDATION debug_disable_61_foundation O "false" Disable step 61: Foundation keep-as-is: Resource groups, UAMIs, VMs.
DEBUG_DISABLE_62_CORE_INFRASTRUCTURE debug_disable_62_core_infrastructure O "false" Disable step 62: Core infrastructure keep-as-is: Application Insights, Key Vault, Storage, ACR.
DEBUG_DISABLE_63_COGNITIVE_SERVICES debug_disable_63_cognitive_services O "false" Disable step 63: Cognitive Services keep-as-is: AI Search, OpenAI Standalone, Vision, Speech.
DEBUG_DISABLE_64_DATABASES debug_disable_64_databases O "false" Disable step 64: Databases keep-as-is: CosmosDB, SQL Database.
DEBUG_DISABLE_65_COMPUTE_SERVICES debug_disable_65_compute_services O "false" Disable step 65: Compute services keep-as-is: Container Apps, WebApp, FunctionApp.
DEBUG_DISABLE_66_AI_PLATFORM debug_disable_66_ai_platform O "false" Disable step 66: AI Platform keep-as-is: AI Foundry Hub (V1) with default project and connections.
DEBUG_DISABLE_67_ML_PLATFORM debug_disable_67_data_ml_platform O "false" Disable step 67: ML Platform keep-as-is: Azure Machine Learning, Datafactory, Databricks.
DEBUG_DISABLE_68_INTEGRATION debug_disable_68_integration O "false" Disable step 68: Integration keep-as-is: Logic Apps, Event Hubs.
DEBUG_DISABLE_69_AIFOUNDRY_2025 debug_disable_69_aifoundry_2025 O "false" Disable step 69: AI Foundry V2 keep-as-is: AI Foundry V2 including RBAC and default project (CosmosDB, Storage).
DEBUG_DISABLE_VALIDATION_TASKS debug_disable_validation_tasks O "false" Disable validation tasks otherwise: true, skip subnet, submodule, and DNS checks.
DEBUG_ENABLE_CLEANING debugEnableCleaning O "false" Enable error cleanup tasks otherwise: true, enables cleanup tasks (71-73) that delete resources on deployment failures.
DELETE_ALL_FOR_PROJECT deleteAllForProject O "false" Delete EVERYTHING for project otherwise: true, deletes ALL resources in project RG including KV, Storage, AppInsights, and networking resources (subnets, NSGs) in common RG. Use with extreme caution!
DELETE_ALL_SERVICES_FOR_PROJECT deleteAllServicesForProject O "false" Delete all project services otherwise: true, delete ALL services in the project RG (except KV, Storage, AppInsights) before redeploy.
DELETE_KEYVAULT_ALSO deleteKeyvaultAlso O "false" Also delete Key Vault when DELETE_ALL_SERVICES_FOR_PROJECT:'true' recommended: false, retains Key Vault as a safety net (secrets, CMK keys, RBAC). otherwise: true, also deletes the project Key Vault.
DIAGNOSTIC_SETTING_LEVEL diagnosticSettingLevel O "gold" Diagnostics level otherwise: silver or bronze for less verbose (lower cost) logging.
POLICY_EXEMPTION_ASSIGNMENT_IDS policyExemptionAssignmentIds O "[]" JSON array of policy assignment IDs (deployIfNotExists or auditIfNotExists) scoped to the VNet RG keep-as-is: Prevents DINE remediation race conditions during AI Foundry Standard Agent network injection. Leave as '[]' in greenfield/non-ALZ. otherwise: e.g. '["/subscriptions/
POLICY_EXEMPTION_DEFINITION_REFERENCE_IDS policyExemptionDefinitionReferenceIds O "[]" JSON array of policyDefinitionReferenceIds to narrow exemption to specific DINE members within an initiative keep-as-is: Leave as '[]' to exempt the full assignment.
RETRY_MINUTES retryMinutes O "5" Minutes between 1st and 2nd retry attempt
RETRY_MINUTES_EXTENDED retryMinutesExtended O "15" Minutes between 2nd and 3rd retry attempt
SELF_HOSTED_RUNNER_LABEL selfHostedRunnerLabel O "aifactory-admin-vm" Custom label assigned to the GitHub self-hosted runner

GHA: Models and deployments

Exact environment key YAML / JSON counterpart(s) M/C/O Template value Description / conditions
DEFAULT_EMBEDDING_CAPACITY default_embedding_capacity O "25" Embedding model capacity (TPM in K)
DEFAULT_GPT_4O_VERSION default_gpt_4o_version O "2024-11-20" GPT-4o version
DEFAULT_GPT_54_MINI_VERSION default_gpt_54_mini_version O "2026-03-17" Version for the separately named GPT-5.4-mini deployment toggle.
DEFAULT_GPT_CAPACITY default_gpt_capacity O "40" GPT model capacity (TPM in K) keep-as-is: 40 = 40K tokens per minute.
DEFAULT_MODEL_SKU default_model_sku O "DataZoneStandard" Default model deployment SKU keep-as-is: Keep inference within the selected data zone; confirm model/SKU availability and quota.
DEPLOY_MODEL_GPT_4O deployModel_gpt_4o O "false" Deploy GPT-4o model
DEPLOY_MODEL_GPT_54_MINI deployModel_gpt_54_mini O "false" Enable the separately named GPT-5.4-mini deployment toggle.
DEPLOY_MODEL_GPT_X deployModel_gpt_X O "true" Deploy custom GPT-X model otherwise: true, deploys the model defined in MODEL_GPTX_NAME.
DEPLOY_MODEL_TEXT_EMBEDDING_3_LARGE deployModel_text_embedding_3_large O "true" Deploy text-embedding-3-large
DEPLOY_MODEL_TEXT_EMBEDDING_3_SMALL deployModel_text_embedding_3_small O "false" Deploy text-embedding-3-small
DEPLOY_MODEL_TEXT_EMBEDDING_ADA_002 deployModel_text_embedding_ada_002 O "false" Deploy text-embedding-ada-002
MODEL_GPTX_CAPACITY modelGPTXCapacity O "30" Custom GPT-X model capacity (TPM in K) keep-as-is: 30 = 30K tokens per minute.
MODEL_GPTX_NAME modelGPTXName O "gpt-5.4-mini" Custom GPT-X model name
MODEL_GPTX_SKU modelGPTXSku O "DataZoneStandard" Custom GPT-X model SKU keep-as-is: Keep inference within the selected data zone; confirm model/SKU availability and quota.
MODEL_GPTX_VERSION modelGPTXVersion O "2026-03-17" Custom GPT-X model version keep-as-is: Update the version when selecting a different model.

Shared-binding collisions

These GHA names occur against multiple YAML/JSON keys. Follow the relevant workflow/environment rather than treating this as a one-to-one rename. All source defaults remain separate above.

GHA binding / fallback YAML / JSON keys
ADMIN_AISEARCH_TIER admin_aiSearchTier, skuAISearchDev, skuAISearchStageProd
AIFACTORY_SEEDING_KEYVAULT_NAME dev_admin_bicep_kv_fw, prod_admin_bicep_kv_fw, test_admin_bicep_kv_fw
AIFACTORY_SEEDING_KEYVAULT_RG dev_admin_bicep_kv_fw_rg, prod_admin_bicep_kv_fw_rg, test_admin_bicep_kv_fw_rg
AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID dev_admin_bicep_input_keyvault_subscription, prod_admin_bicep_input_keyvault_subscription, test_admin_bicep_input_keyvault_subscription
ELASTIC_SKU elasticSku, skuElasticDev, skuElasticStageProd
USE_COMMON_ACR_FOR_PROJECTS useCommonACR, useCommonACR_override

Bootstrap environment inputs

Inputs are read by the create launchers, with version selectors also used by update. M means a value must resolve (an authenticated-context default may supply it); C means route/mode-specific; O means a default or optional override. $... defaults below are literal source expressions, not values discovered on this machine. Blank means no literal default at that point. Prompts, simple-mode fixed values, and validation can narrow them further.

Input M/C/O Source default / expression Description
ADO_AGENT_NAME C "dsvm-cmn-${AIF_LOCATION_SHORT}-dev-001" Ado agent name override; see create launcher.
ADO_AGENT_POOL C "Default" Azure DevOps agent pool
ADO_AUTH_METHOD C "aad" Azure DevOps authentication: Microsoft Entra (aad) or PAT (pat); allowed: aad pat
ADO_BRANCH C "main" ADO update branch; reviewed project dispatch requires main.
ADO_ORGANIZATION C "" Azure DevOps organization name or URL
ADO_PIPELINE_NAME C "infra-project-genai" ADO legacy update pipeline name.
ADO_PROJECT C "" Azure DevOps project name
ADO_REPOSITORY_NAME C "${AIF_PREFIX%-}aifactory-${AIF_SCALESET_SUFFIX}" Azure DevOps repository name
ADO_RUNNER_MODE C "$runner_default" Project build agent: self-hosted admin VM (s, recommended for private access) or Microsoft-hosted (h); allowed: s h
ADO_RUNNER_SELECTION C "from-config" ADO legacy update runner selection.
ADO_SERVICE_CONNECTION_NAME C "sc-${AIF_PREFIX%-}dev-${AIF_SCALESET_SUFFIX}" Azure DevOps service connection name
ADO_SETTINGS_FILE C "$HOME/.aifactory-ado-settings.json" ADO saved organization/project context path; generator never reads this file.
ADO_TENANT C "$AIF_TENANT_ID" Azure DevOps connected tenant ID
AIFACTORY_COMMIT_CHANGES O "" Update confirmation y/yes or n/no; default No. Choosing Yes authorizes the launcher's commit/continue path.
AIFACTORY_PROJECT_CONFIG C "" Reviewed project JSON file; required together with explicit target environment, project number and repository root.
AIFACTORY_PROJECT_DEPLOYMENT_SCOPE O "project" ADO update scope: project or azure-mcp.
AIFACTORY_PROJECT_NUMBER C "" Reviewed update/project target number; required together with target environment, project configuration and repository root.
AIFACTORY_PROJECT_ONLY O "false" Update launcher equivalent of --project-only.
AIFACTORY_REPO_ROOT O "" Repository root; --repo-root overrides it.
AIFACTORY_TARGET_ENVIRONMENT C "dev" Update target: dev, test/stage, or prod; verify route/environment naming.
AIFACTORY_UPDATE_GITHUB_VARIABLES O "" GHA update confirmation y/yes or n/no for synchronization from .env; default No.
AIFACTORY_USE_JSON_OVERRIDE O "" y/yes enables variables.json overrides; blank/n/no disables. Explicit reviewed project inputs force this to yes.
AIFACTORY_VERSION O "" Explicit template release; omitted Create uses 124 and Update inherits the installed version. --aifactory-version takes precedence.
AIF_ACCESS_HUB_MODE C "i" Standalone access hub: integrated in DEV common network (i) or external connectivity subscription (e); allowed: i e
AIF_ACCESS_HUB_RESOURCE_GROUP C "aifactory-connectivity" External access-hub and private-DNS resource group
AIF_ACCESS_HUB_SUBSCRIPTION_ID C "" External access-hub subscription ID
AIF_ACCESS_HUB_VNET_CIDR C "10.240.0.0/22" External access-hub vNet CIDR
AIF_ACCESS_HUB_VNET_NAME C "" Aif access hub vnet name override; see create launcher.
AIF_ADD_BASTION O "" Compatibility input; collection resets this to false. Access-hub Bastion is controlled separately.
AIF_ADMIN_GROUP_ID O "" Existing administrators group object ID (blank to create/ensure by name)
AIF_ADMIN_GROUP_MODE O "$admin_group_default" Technical administrators: reuse initial team (team) or separate Entra group (separate); allowed: team separate
AIF_ADMIN_GROUP_NAME O "${AIF_PREFIX%-}-admins" Entra administrators security group
AIF_ADMIN_MEMBER_EMAIL O "$current_user" Initial administrators group member
AIF_ADMIN_VM_SIZE O "$([[ \"$AIF_RUNNER_VM_OS\" == linux ]] && echo Standard_D4s_v5 &#124;&#124; echo Standard_D2s_v5)" Self-hosted admin VM size
AIF_APP_GATEWAY_BACKEND_FQDN C "" Simple-mode distinct private HTTPS backend; trusted TLS and unauthenticated GET / returning 200-399.
AIF_APP_GATEWAY_CERT_SECRET_ID C "" Simple-mode versionless Key Vault PFX certificate-secret URI, not a secret value.
AIF_APP_GATEWAY_HOSTNAME C "" Simple-mode custom frontend FQDN covered by certificate DNS SAN.
AIF_AZURE_ML_PRINCIPAL_ID O "" Existing Azure Machine Learning enterprise-application object ID; otherwise discovered/ensured.
AIF_BOOTSTRAP_RESOURCE_GROUP O "rg-${AIF_PREFIX%-}-bootstrap-${AIF_LOCATION_SHORT}-${AIF_SCALESET_SUFFIX}" Aif bootstrap resource group override; see create launcher.
AIF_CONFIGURE_VPN_CLIENT O "$configure_vpn_client_default" Install and configure Azure VPN Client on this computer? (Y/n)
AIF_COST_CENTER O "123456" Simple-mode common and project cost-center tag.
AIF_CREATE_DEFAULT_VERSION O "124" Legacy Create launcher default when no explicit version selector is supplied.
AIF_DATABRICKS_PRINCIPAL_ID O "" Existing Databricks enterprise-application object ID; otherwise discovered/ensured when needed.
AIF_DEPLOYMENT_IDENTITY_NAME O "id-${AIF_PREFIX%-}-deploy-${AIF_LOCATION_SHORT}-${AIF_SCALESET_SUFFIX}" Aif deployment identity name override; see create launcher.
AIF_DEV_SUBSCRIPTION_ID M "$current_subscription" DEV subscription ID
AIF_DEV_VNET_CIDR O "172.16.0.0/18" DEV vNet CIDR used to derive aligned XX templates for all environments (/18, /19 or /20; no XX placeholder)
AIF_DRY_RUN O "false" Aif dry run override; see create launcher.
AIF_HUB_RESOURCE_GROUP C "" Hub private-DNS resource group
AIF_HUB_SUBSCRIPTION_ID C "" Hub subscription ID
AIF_HUB_VNET_NAME C "" Hub vNet name
AIF_HUB_VNET_RESOURCE_GROUP C "$AIF_HUB_RESOURCE_GROUP" Hub vNet resource group
AIF_IDENTITY_MODE O "c" Deployment identity: create managed identity (c), existing managed identity (mi), or existing service principal (sp); allowed: c mi sp
AIF_IP_ALLOWLIST O "" IPv4 allowlist input; the current create prompt accepts private networking only.
AIF_LOCATION O "swedencentral" Azure region (swedencentral, westeurope, northeurope, eastus, eastus2, uksouth, westgermany)
AIF_MI_RESOURCE_ID C "" Existing user-assigned managed identity resource ID
AIF_NETWORK_MODE O "priv" Networking: private-only (priv; enforced by policy); allowed: priv
AIF_NON_INTERACTIVE O "false" Aif non interactive override; see create launcher.
AIF_NO_WAIT O "false" Aif no wait override; see create launcher.
AIF_PREFIX O "aif-" AI Factory naming prefix
AIF_PREPARE_ONLY O "false" Aif prepare only override; see create launcher.
AIF_PROD_SUBSCRIPTION_ID O "$AIF_DEV_SUBSCRIPTION_ID" Aif prod subscription id override; see create launcher.
AIF_PROJECT_NUMBER O "001" First project number (001-999)
AIF_RUNNER_MODE O "$runner_default" Project runner: self-hosted (recommended for private access) or github-hosted; allowed: self-hosted github-hosted
AIF_RUNNER_VM_NAME O "$default_name" Aif runner vm name override; see create launcher.
AIF_RUNNER_VM_OS O "$([[ \"$AIF_ROUTE\" == gha ]] && echo linux &#124;&#124; echo windows)" Aif runner vm os override; see create launcher.
AIF_RUNNER_VM_RESOURCE_GROUP O "${AIF_PREFIX}esml-common-${AIF_LOCATION_SHORT}-dev${AIF_SCALESET_SUFFIX_DASH}" Aif runner vm resource group override; see create launcher.
AIF_SCALESET_SUFFIX O "001" Scale-set number (001-999)
AIF_SEEDING_KEYVAULT_NAME C "kv${prefix_compact}${AIF_LOCATION_SHORT}${AIF_SCALESET_SUFFIX}" Existing seeding Key Vault name
AIF_SEEDING_MODE O "c" Seeding Key Vault: create/ensure (c) or use existing (e); allowed: c e
AIF_SEEDING_RESOURCE_GROUP C "$AIF_BOOTSTRAP_RESOURCE_GROUP" Existing seeding Key Vault resource group
AIF_SEED_PROJECT_SP O "n" Create and seed an optional project automation service principal? (y/N)
AIF_SETUP_HUB_ACCESS O "y" Set up Azure VPN Gateway in the hub and Bastion Developer for DEV? (Y/n)
AIF_SIMPLE_MODE O "false" Opt in to the GHA Dev private foundation contract.
AIF_SIMPLE_PROJECT_RESOURCES_JSON O "[\"foundry\",\"foundry-capability-host\",\"ai-search\",\"cosmos-db\",\"application-insights\"]" Simple-mode JSON resource-ID selection. Required project dependencies cannot be removed; [] removes only optional selections.
AIF_SP_CLIENT_ID C "" Existing service-principal client ID
AIF_SP_CLIENT_SECRET C "" Existing service-principal client secret
AIF_STAGE_SUBSCRIPTION_ID O "$AIF_DEV_SUBSCRIPTION_ID" Aif stage subscription id override; see create launcher.
AIF_SUBMODULE_BRANCH O "" Legacy explicit branch selector consumed by release-version resolution.
AIF_SUBMODULE_REF C "" Exact published commit SHA; required for the simple-mode source verification contract.
AIF_TEAM_GROUP_ID O "" Reuse an existing team group by object ID; otherwise resolve/create from group name.
AIF_TEAM_GROUP_NAME O "${AIF_PREFIX%-}prj${AIF_PROJECT_NUMBER}-team" Entra security group for the initial team
AIF_TEAM_MEMBER_EMAIL M "$current_user" Initial team member
AIF_TENANT_ID M "$current_tenant" Azure tenant ID
AIF_TOPOLOGY O "s" Topology: standalone (s) or hub/spoke with central DNS (hs); allowed: s hs
AIF_UPDATE_DEFAULT_VERSION O "" Optional Update override; omission inherits the installed factory version.
AIF_VPN_CLIENT_CIDR O "172.31.240.0/24" Point-to-site VPN client address pool
AIF_YES O "false" Aif yes override; see create launcher.
AZURE_DEVOPS_EXT_PAT C "" Azure DevOps PAT
GITHUB_REPOSITORY C "$current_repo" GitHub repository (owner/name)
GITHUB_REPOSITORY_VISIBILITY O "private" Simple-mode repository visibility: private or public; independent of Azure networking.

Configuration helper CLI inputs

bootstrap/lib/aifactory_scaleset_config.py is a local configuration API, not an HTTP endpoint. --route, --repo-root, and --state-file are required together for the default write operation. Other switches select independent inspection/validation operations. Unspecified argparse values are null; boolean switches default to false.

Exact option M/C/O Parser default Meaning / choices
--app-gateway-backend-fqdn C "" App gateway backend fqdn
--app-gateway-certificate-secret-id C "" App gateway certificate secret id
--app-gateway-hostname C "" App gateway hostname
--certificate-metadata C null Local certificate metadata JSON; validates metadata only, not private key material.
--enable-application-gateway C null Enable application gateway; choices: true, false
--gateway-health C null Local gateway backend-health JSON; exit status indicates health.
--project-resources C null JSON array of simple-mode project resource IDs; required dependencies are retained.
--repo-root C null Consumer root containing the generated .env/YAML/JSON configuration.
--repository-visibility C "private" Repository visibility
--route C null Route; choices: ado, gha
--simple-gateway-inputs C false Validate gateway input strings and print normalized JSON; no deployment.
--simple-mode-hub-subnets C null Validate existing subnet JSON and print reserved simple-mode subnets.
--simple-mode-manifest C false Offline read-only contract/preset preview.
--simple-project-providers C false Simple project providers
--simple-project-selected C null Simple project selected; choices: storage, key-vault, managed-identities, foundry, foundry-capability-host, ai-search, cosmos-db, application-insights, azure-machine-learning, aks-for-azure-ml, aks, databricks, datafactory, event-hubs, postgresql, container-apps
--state-file C null Bootstrap state JSON, not variables.json; consumed by the selected route writer.
--verify-simple-mode-source C null Compare supplied checkout with the required shared source trees.

Bootstrap state JSON fields

These exact fields are consumed by the Python helper's local --state-file API. Normally the shell bootstrap writes this state after resolving identities and scope; it is not the persistent deployment variables.json. C below means required in the named function/route when invoked; O denotes only guarded .get() reads. Missing required keys are not defaulted. project_sp_secret_names contains the nested secret-name keys app_id, object_id, and secret, not secret values.

Exact state field M/C/O Missing-key behavior Consumer / meaning
access_hub_mode O null apply_gha, common_values; Access hub mode
add_bastion C Required lookup apply_gha, common_values; Add bastion
admin_group_id O null common_values; Admin group id
admin_member_email O null common_values; Admin member email
admin_vm_size O "Standard_D2s_v5" apply_gha, common_values; Admin vm size
ado_agent_name O "" common_values; Ado agent name
ado_agent_pool O "Default" common_values; Ado agent pool
ado_tenant_id C Required lookup apply_ado; Ado tenant id
allow_public_access_behind_vnet C Required lookup apply_gha, common_values; Allow public access behind vnet
azure_ml_principal_id O "" apply_gha, common_values; Azure ml principal id
cost_center C Required lookup common_values; Cost center
databricks_principal_id O "" apply_gha, common_values; Databricks principal id
dev_service_connection C Required lookup apply_ado; Dev service connection
dev_subscription_id C Required lookup apply_gha, common_values; Dev subscription id
dev_vnet_cidr C Required lookup common_values; Dev vnet cidr
enable_public_genai_access C Required lookup apply_gha, common_values; Enable public genai access
enable_public_perimeter C Required lookup apply_gha, common_values; Enable public perimeter
github_repository C Required lookup apply_gha; Github repository
github_repository_visibility O null common_values; Github repository visibility
github_runner_label C Required lookup apply_gha; Github runner label
hub_resource_group O "" apply_gha, common_values; Hub resource group
hub_subscription_id O "" apply_gha, common_values; Hub subscription id
ip_allowlist O "", null apply_gha, common_values; Ip allowlist
location C Required lookup apply_gha, common_values; Location
location_short C Required lookup apply_gha, common_values; Location short
oidc_client_id O "" apply_gha; Oidc client id
prefix C Required lookup apply_gha, common_values; Prefix
prod_service_connection C Required lookup apply_ado; Prod service connection
prod_subscription_id C Required lookup apply_gha, common_values; Prod subscription id
project_number C Required lookup apply_gha, common_values, selected_project_organization; Project number
project_sp_secret_names O null apply_gha, common_values; Project sp secret names
runner_mode O null apply_gha, common_values; Runner mode
runner_vm_os O "windows", "linux" apply_gha, common_values; Runner vm os
scaleset_suffix C Required lookup apply_gha, common_values; Scaleset suffix
seeding_keyvault_name C Required lookup apply_gha, common_values; Seeding keyvault name
seeding_resource_group C Required lookup apply_gha, common_values; Seeding resource group
seeding_subscription_id C Required lookup apply_gha, common_values; Seeding subscription id
simple_mode O "false" simple_mode_enabled; Simple mode
simple_project_resources_json O null common_values; Simple project resources json
stage_service_connection C Required lookup apply_ado; Stage service connection
stage_subscription_id C Required lookup apply_gha, common_values; Stage subscription id
team_group_id C Required lookup apply_gha, common_values; Team group id
team_group_name C Required lookup apply_gha, common_values; Team group name
team_member_email O null apply_gha, common_values; Team member email
tenant_id C Required lookup apply_gha, common_values; Tenant id
topology C Required lookup apply_gha, common_values; Topology