Parameters — Advanced reference¶
Use Standard parameters for the initial checklist. This reference covers the public configuration surface, not every Bash local or internal Bicep/ARM module parameter.
Scope and authoritative sources¶
The generated tables include every unique key in these shared templates:
environment_setup/aifactory/bicep/copy_to_local_settings/github-actions/.env.templateenvironment_setup/aifactory/bicep/copy_to_local_settings/azure-devops/esml-yaml-pipelines/variables/variables.yamlenvironment_setup/aifactory/variables.json— every section and key, including all Dev and Stage/Prod SKU fields.
They also cover external create-bootstrap environment inputs and the configuration
helper's CLI options, from bootstrap/lib/create-new-aifactory-scaleset.sh,
bootstrap/lib/release_version.sh, the GH/ADO update launchers, and
bootstrap/lib/aifactory_scaleset_config.py. Public Bash command switches are
documented below. Internal resume flags, generated state, shell implementation
locals, external service API schemas, and module-internal ARM inputs are excluded.
There is no separate checked-in bootstrap .env template in these sources:
bootstrap reads process environment inputs, then writes the selected route's files.
Do not confuse that input environment with the generated GitHub .env.
Two distinct JSON contracts
The raw checked-in consumer template environment_setup/aifactory/variables.json
currently has a dev section only.
Stage/Prod SKU pairs such as dev.skuAISearchStageProd are present inside it;
there is no checked-in top-level stage_prod section. The legacy bootstrap
helper's update_json() updates dev. The generated inventory below reports
that shared template exactly; it is not the Azure Factory v2 output schema.
Each backend-generated Azure Factory v2 project has one variables.json
with direct top-level dev and stage_prod sections, stored at
factories/<key>/scalesets/<immutable storage_suffix>/projects/projectNNN/variables.json.
Both sections retain the full configuration, with separate subscription and
SKU values. They are not nested inside a wrapper or split across per-environment
files. Review the selected project's two sections before CLI/API dispatch.
Reading defaults and requirements¶
- M — mandatory in the source template's deployment context. A supplied default can satisfy the input; it does not mean you must edit every M row.
- C — conditionally required. Applies only to the selected environment, identity route, service or networking mode. For example, Stage service connections are not prerequisites for a Dev-only run.
- O — optional override or feature switch. O does not mean safe to enable without its dependencies. Optional switches remain O even if a preset fixes them on; the required private-agent service bundle is C for that architecture.
- Values are actual assignments, not the sometimes stale
<default>text in comments. Empty strings and<todo>/<optional>placeholders are shown literally and are not usable credentials or resource IDs. - YAML and GHA marker annotations occasionally differ. Each GHA row retains its own annotation; a JSON key inherits the YAML annotation where available. Untagged settings default to O, with route/service conditions described in text.
- Binding names come from shared workflow expressions, preflight
getvalmappings, bootstrap writers and explicitly reviewed template correspondences. No automatic case conversion is used. A binding may be a workflow fallback rather than an equivalent standalone input.
Important cross-format semantics¶
Networking and DNS¶
The shared template default is shared-subscriptions with
common_vnet_cidr=172.16.XX.0/18 and network-aligned Dev/Stage/Prod selectors
0 / 64 / 128. Own-subscription /20 planning uses 0 / 16 / 32.
XX replaces the third octet in the VNet and subnet templates. Environments,
VPN client pools and existing networks must not overlap. Address intent does
not create peering or resize existing networks.
centralDnsZoneByPolicyInHub |
enableAIFactoryHub |
Meaning |
|---|---|---|
false |
false |
Standalone DNS/network intent |
false |
true |
Own AI Factory hub intent |
true |
Either | External central-DNS hub takes precedence; supply its subscription/resource group |
The hub flag alone is configuration intent, not a deployment operation. JSON
stores these flags as booleans while YAML/GHA templates use string values.
The three public-access flags govern service access, not repository visibility
and not every telemetry endpoint. enableAMPLS=false does not provide
private-only Application Insights/Log Analytics ingestion.
Models, SKUs and aliases¶
modelGPTXSku / MODEL_GPTX_SKU and
default_model_sku / DEFAULT_MODEL_SKU default to DataZoneStandard.
Model availability, version support, capacity and quota must be checked for
the selected region/subscription; a template value is not a capacity reservation.
Dev and Stage/Prod service SKUs remain separate fields.
AI Search has a particularly important fallback:
skuAISearchDev reads SKU_AISEARCH_DEV, then ADMIN_AISEARCH_TIER;
skuAISearchStageProd reads SKU_AISEARCH_STAGEPROD, then
ADMIN_AISEARCH_TIER. The shared ADMIN_AISEARCH_TIER=basic can therefore
override the workflow's final Stage/Prod standard fallback.
ADMIN_AI_SEARCH_TIER is another spelling consumed by preflight, not a
safe rename of every workflow input. Likewise, semantic tier and Azure ML
principal-ID compatibility spellings coexist in the template.
Capacity-only service fallbacks¶
Both ADO and GitHub Actions isolate AI Search, PostgreSQL Flexible Server and
Container Apps from their cognitive/database/compute batches. Each has three
separately visible attempt steps immediately after its batch. Only recognized
regional/SKU capacity failures schedule another attempt; unrelated errors fail
immediately, and exhausted candidates fail the pipeline before downstream
deployments. Attempts 2 and 3 wait 240 seconds at their start when scheduled.
Successful attempts export the effective SKU (and PostgreSQL tier) for later steps.
The existing JSON-array names skuAISearchDevArray and
skuAISearchStageProdArray remain supported alongside the comma-separated
skuArrayAISearchDev / skuArrayAISearchStageProd names. A customized spelling
takes precedence over the unchanged default; differing custom values fail
validation rather than silently discarding either configuration.
Container Apps detected before the run retain their existing application images
and configuration. Retry reconciliation uses the original existence flags, so
only resources absent at the start are reapplied unless explicitly opted in.
The selected Dev or Stage/Prod SKU is tried first, followed by the remaining configured candidates in array order. Defaults are:
| Service | Selected defaults (Dev / Stage/Prod) | Candidate arrays (both environments) | Retry switch |
|---|---|---|---|
| AI Search | basic / standard |
basic,standard,standard2 |
aisearchRetryCapcityArray |
| PostgreSQL | Standard_B1ms / Standard_B1ms |
Standard_B1ms,Standard_B2s,Standard_B2ms |
postgreSQLRetryCapacityArray |
| Container Apps | Consumption / Consumption |
Consumption,D4,D8 |
containerAppsRetryCapacityArray |
Configure skuArray<Service>Dev / skuArray<Service>StageProd alongside
sku<Service>Dev / sku<Service>StageProd. All retry switches default to true;
false attempts only the selected SKU and fails on its first error. Keep the
existing Capcity spelling in the AI Search switch. The generated inventory
below lists the corresponding GitHub uppercase variable names.
Attempts honor the infra phase, deletion and service/debug switches, retaining
the cognitive/database capability-host debug override used by ADO. AI Search
also runs when private Foundry requires it (enableAIFoundry=true and
enablePublicGenAIAccess!=true), even if enableAISearch=false. Preflight quota
headroom checks are not a capacity guarantee. Container Apps fallback from
Consumption to D4 or D8 changes to dedicated workload-profile pricing;
review costs before enabling these candidates.
ADO has separate Dev/Stage/Prod seeding-vault coordinates and service connections. GHA commonly uses one seeding-vault variable name with environment-specific overrides. Review the collision table rather than copying one value into all environments. Some source defaults genuinely differ, including resource naming, Hybrid Benefit, user RBAC restrictions, placeholders and tag macros.
Identity, secrets and lifecycle¶
Secret-name inputs identify entries in the seeding Key Vault; they are not secret values. Federated managed-identity/OIDC bootstrap can leave legacy service-principal secret-name fields empty. A seeding-vault shell may still be required. Existing-SP and PAT routes require secrets only when selected; keep them out of committed files, logs and command history.
Deletion and debug switches are public template inputs and therefore included. Their presence is not a recommendation to enable them. Review the exact target, backups, policy/RBAC permissions, network reachability and the deployment plan. A complete configuration reference is not a guarantee of deployment success.
Bash create and update contract¶
Run these entrypoints from the generated consumer checkout, using Bash/Git Bash. They use the existing deployment engine and route configuration.
| Entrypoint | Public switch | Meaning |
|---|---|---|
GHA-create-new-aifactory-scaleset.sh, ADO-create-new-aifactory-scaleset.sh |
--repo-root PATH |
Explicit legacy consumer root |
| Create | --aifactory-version VERSION |
Explicit source version, e.g. main, 124, 125, 1.100, 10.2 |
| Create | --dry-run |
Collect/validate without mutation; not an offline preview or supported simple-mode launch |
| Create | --prepare-only |
Prepare Azure, identity, configuration and automation without completing deployment |
| Create | --no-wait |
Dispatch without waiting; incompatible with the simple-mode dependent chain |
| Create | --non-interactive |
Read answers from process environment |
| Create | --yes |
Accept the execution summary |
| Create/update | --help, -h |
Show entrypoint help |
ALL-create-new-aifactory-scaleset.sh |
--orchestrator ado\|gha |
Select one route, then forward create options |
GH-update-aifactory-and-run-project.sh, GHA-update-aifactory-and-run-project.sh, ADO-update-aifactory-and-run-project.sh |
--project-only |
Dispatch project only; skip factory/template updates |
| Update | --aifactory-env dev\|stage\|prod |
Dispatch only the selected environment; conflicts with a different AIFACTORY_TARGET_ENVIRONMENT. |
| Update | --aifactory-version VERSION |
Choose update source version explicitly |
Create and update default to main unless an explicit version selector is
provided; project-only is not an upgrade operation. Current create validation
accepts AIF_NETWORK_MODE=priv only, despite legacy help also mentioning
h/pub. Its general region prompt defaults to swedencentral, whereas
the shared configuration templates default to eastus2.
Initial legacy bootstrap deploys Dev only and seeds Stage/Prod subscription
values from Dev; that is not a reviewed multi-environment network plan.
Register-managed targets are a distinct contract: these legacy launchers do
not initialize or modify azurefactory/register.json. Use the corresponding
lifecycle CLI/API with an explicit, reviewed target manifest instead.
Legacy create explicitly rejects AIF_CREATE_PROJECTS and AIF_PROJECT_MODE;
they are not supported substitutes for a scoped lifecycle manifest.
Simple-mode technical contract¶
AIF_SIMPLE_MODE=true opts the GHA create entrypoint into contract v2,
private-ai-foundation-v2. Use --non-interactive --yes --repo-root PATH and
wait for the full common → access hub → project chain, followed by the private
HTTPS gateway only when its deployment is enabled.
Use the following offline, read-only preview instead of a deployment dry run:
python bootstrap/lib/aifactory_scaleset_config.py --simple-mode-manifest
python bootstrap/lib/aifactory_scaleset_config.py --simple-mode-manifest --enable-application-gateway false
Provide tenant/subscription, region, prefix, repository and initial team identity
inputs, plus a published AIF_SUBMODULE_REF. Existing Azure/GitHub authentication
is required. Prefix validation accepts 2–16 lowercase letters, digits or hyphens.
The default suffix is 001; the cost-center default is 123456.
Fixed settings are AIF_TOPOLOGY=s, AIF_NETWORK_MODE=priv,
AIF_ACCESS_HUB_MODE=i, AIF_IDENTITY_MODE=c, AIF_SEEDING_MODE=c,
AIF_SEED_PROJECT_SP=false, AIF_SETUP_HUB_ACCESS=true,
AIF_CONFIGURE_VPN_CLIENT=false, AIF_DEV_VNET_CIDR=172.16.0.0/20,
and AIF_PROJECT_NUMBER=001.
Only project Storage, Key Vault and managed identities are always required.
Foundry is optional and selected by default, together with its capability host,
Basic AI Search, Cosmos DB and Application Insights. Selecting Foundry requires
all three dependencies; its capability host cannot be selected without Foundry.
The UI clears those three when Foundry is unchecked, after which Search and Cosmos DB
can be selected independently. Explicit AIF_SIMPLE_PROJECT_RESOURCES_JSON=[]
deploys only the baseline project foundation. Omitting the selection preserves the
default Foundry bundle. Explicit incomplete dependencies are rejected before Azure
mutations, not silently re-enabled; valid selections are ordered by the catalog.
Additional optional IDs are azure-machine-learning, aks-for-azure-ml, aks,
databricks, datafactory, event-hubs, postgresql and container-apps.
aks-for-azure-ml requires azure-machine-learning; standalone aks is independent.
AML and Container Apps also require their linked Application Insights; this is a
conditional dependency, not a globally required service. Include that dependency
in explicit CLI selections (for example ["azure-machine-learning","application-insights"]).
All selected services map to the existing pipeline flags, with canonical baseline
SKUs (Event Hubs Standard is required for Private Link). Resource-provider
registration follows the selection. ML/Databricks materialize only their selected
first-party enterprise applications, never temporary public workspaces; a tenant
administrator may need to provision those applications or supply their object IDs.
Foundry-specific deployment and capability-host checks skip when Foundry is off;
agent network injection is disabled, while the common, networking, project, data
and ML phases still run.
The additive literal projectResourceSelection manifest contract has version 1
and strict dependency validation. Publish the matching source before using it.
All model deployment toggles remain off and model SKU defaults stay
DataZoneStandard. This is not a preloaded-model or runnable-agent guarantee.
Deploying a new Application Gateway is optional, not a prerequisite for private
Foundry agents. New UI selections default off. Set
AIF_ENABLE_APPLICATION_GATEWAY=false to avoid deploying a second billable gateway
when a customer already has a central gateway, or when no application ingress is
needed. This does not adopt, integrate with, or modify that existing gateway.
The environment accepts only lowercase true or false; empty/noncanonical
values fail before cloud operations. Omitting it preserves legacy enabled
behavior for existing automation.
When false, gateway hostname/backend/certificate inputs may be blank and all gateway-specific feature/certificate checks, subnet reservation, NSG, identity, certificate role grant/private endpoint, frontend DNS, deployment and backend health checks are skipped. VPN, DNS Private Resolver, required private DNS zones and the selected project workloads remain enabled. No environment, including Prod, universally requires a new Application Gateway.
This is an additive v2 capability (AIF_SIMPLE_OPTIONAL_GATEWAY_CONTRACT=1), not
a replacement for v2. The manifest's literal appGatewayDeployment advertises
default: false, omittedDefault: true, and supported: [false, true].
Publish the matching bootstrap and infrastructure source together and use the
verified published commit before deploying; updating only the UI/API is insufficient.
Gateway inputs below are required only when deploying a new gateway:
| Environment input | Helper/API input | Constraint |
|---|---|---|
AIF_ENABLE_APPLICATION_GATEWAY |
--enable-application-gateway / enable_application_gateway |
true or false; new UI false, omitted legacy true |
AIF_APP_GATEWAY_HOSTNAME |
--app-gateway-hostname / app_gateway_hostname |
Custom frontend FQDN covered by certificate DNS SAN |
AIF_APP_GATEWAY_BACKEND_FQDN |
--app-gateway-backend-fqdn / app_gateway_backend_fqdn |
Distinct private RFC1918 HTTPS backend, reachable from the new VNet, trusted TLS, unauthenticated GET / returns 200–399 |
AIF_APP_GATEWAY_CERT_SECRET_ID |
--app-gateway-certificate-secret-id / app_gateway_certificate_secret_id |
Versionless https://<vault>.vault.azure.net/secrets/<name> URI of an enabled, valid, exportable PFX certificate in an RBAC-enabled Dev-subscription vault |
No certificate secret value is embedded in these inputs. When gateway deployment
is enabled, the private-network Application Gateway subscription feature must
already be registered; existing secure HTTPS validation and readiness checks remain.
VPN gateway/resolver subnets are reserved before project allocation:
172.16.1.0/27, 172.16.1.32/28. The Application Gateway block 172.16.2.0/24
is reserved only when its deployment is enabled. Conflicting existing
allocations are rejected, not moved or deleted.
The access hub includes billable VPN Gateway and DNS Private Resolver resources. VPN transport uses a public IP; Azure service access remains independently controlled. The exported VPN profile is a sensitive connection artifact; connect the client manually. Bastion Developer requires regional support, has no automatic paid-SKU fallback, and does not create an admin VM.
GITHUB_REPOSITORY_VISIBILITY=private|public defaults to private for this
contract, unlike the generic .env.template repository default. An existing
repository must be empty and match the requested visibility. Review generated
code and non-secret metadata before publication. Ignore rules for .env,
populated configuration, certificates and VPN files are not a general-purpose
secret sanitizer.
Maintaining the reference¶
The generator reads only the named shared sources. It has no dependency on a separate configuration application or consumer workspace. From repository root:
python documentation/gh-io/tools/generate_parameters.py
python documentation/gh-io/tools/generate_parameters.py --check
The check compares the exact source-qualified union with generated row markers, rejects duplicate JSON keys/reference rows and detects stale defaults, descriptions, aliases and inventory counts. Repeated source assignments are reported, not silently represented as multiple settings.
Targeted regression tests:
python -m unittest discover -s environment_setup/unit-tests/test-bicep/unit -p test_parameter_documentation.py -v
Source coverage¶
| Source | Unique public keys |
|---|---|
yaml |
357 |
env |
357 |
bootstrap |
90 |
helper |
17 |
state |
46 |
json.dev |
361 |
Counts are source-qualified: a spelling present in YAML and JSON is covered in each source, not counted as two settings. Repeated template assignments are consolidated below (last assignment wins).
- Source duplicate:
env:ADMIN_COMMON_RESOURCE_SUFFIX, lines 135, 380; one reference row. - Source duplicate:
env:ADMIN_PRJ_RESOURCE_SUFFIX, lines 136, 381; one reference row. - Source duplicate:
env:USE_COMMON_ACR_OVERRIDE, lines 382, 406; one reference row.
YAML and variables.json reference¶
Exact YAML keys are under variables:; JSON paths are <section>.<key>. Y = YAML assignment; J.section = JSON value. JSON quoting and scalar types are preserved. A missing source is explicitly marked. GHA names include workflow bindings/fallbacks and explicitly reviewed template counterparts; they are not automatically interchangeable and inclusion does not guarantee every workflow consumes them.
Services and feature switches¶
| YAML / JSON key | GHA binding(s) | M/C/O | Source defaults | Description / conditions |
|---|---|---|---|---|
AMLStudioUIPrivate |
AML_STUDIO_UI_PRIVATE |
O | Y: "true"J.dev: "true" |
AML Studio UI private access otherwise: false, only data plane is private; control plane is public. |
ENABLE_APIM |
ENABLE_APIM |
O | Y: "false"J.dev: "false" |
Deploy APIM Azure OpenAI pool, token guard, 429-aware backend circuit breakers, and API policy. |
ENABLE_KONG |
ENABLE_KONG |
O | Y: "false"J.dev: "false" |
Deploys Kong as an optional private edge proxy to APIM. |
acr_SKU |
ACR_SKU |
M | Y: "Premium"J.dev: "Premium" |
ACR SKU mandatory: ACR SKU ensure: Premium required for private endpoints and CMK support. |
acr_adminUserEnabled |
ACR_ADMIN_USER_ENABLED |
O | Y: "false"J.dev: "false" |
ACR admin user enabled recommended: false, disable admin user for security. otherwise: true, enable for simpler dev access. |
acr_dedicated |
ACR_DEDICATED |
M | Y: "true"J.dev: "true" |
ACR dedicated (Premium tier) mandatory: ACR dedicated (Premium tier) ensure: must be true when using private endpoints or CMK. |
addAIFoundry |
ADD_AI_FOUNDRY |
O | Y: "false"J.dev: "false" |
Add new AI Foundry instance with new name otherwise: true, provisions a new AI Foundry with a new random name (for debugging or re-run) to get a fresh start. Still you should delete the old instance. |
addAIFoundryHub |
ADD_AI_FOUNDRY_HUB |
O | Y: "false"J.dev: "false" |
DEPRECATED. Do not enable. keep-as-is: DEPRECATED. Do not enable. |
addAISearch |
ADD_AI_SEARCH |
O | Y: "false"J.dev: "false" |
Add new AI Search instance otherwise: false, CreateIfNotExists logic. |
addAzureMachineLearning |
ADD_AZURE_MACHINE_LEARNING |
O | Y: "false"J.dev: "false" |
Add new Azure ML workspace |
addBastionHost |
ADD_BASTION_HOST |
O | Y: "false"J.dev: "false" |
Add Bastion Host in common RG |
apimGatewayAggregateTpm |
APIM_GATEWAY_AGGREGATE_TPM |
C | Y: ""J.dev: "" |
80-90% of the summed TPM across all GPT-5.5 backends. Required by the separate AI gateway workflow when APIM is enabled. |
apimGatewayApiId |
APIM_GATEWAY_API_ID |
O | Y: "azure-openai-gpt55"J.dev: "azure-openai-gpt55" |
Apim gateway api id. |
apimGatewayApiPath |
APIM_GATEWAY_API_PATH |
O | Y: "openai"J.dev: "openai" |
Apim gateway api path. |
apimGatewayAssignOpenAIUserRole |
APIM_GATEWAY_ASSIGN_OPENAI_USER_ROLE |
O | Y: "false"J.dev: "false" |
Requires roleAssignments/write in every backend subscription. |
apimGatewayBackendPoolName |
APIM_GATEWAY_BACKEND_POOL_NAME |
O | Y: "aoai-gpt55-pool"J.dev: "aoai-gpt55-pool" |
Apim gateway backend pool name. |
apimGatewayBackendsJson |
APIM_GATEWAY_BACKENDS_JSON |
C | Y: "[]"J.dev: "[]" |
JSON array; see esml-common/ai-gateway/apim/README.md. Required by the separate AI gateway workflow when APIM is enabled. |
apimGatewayCallerTpm |
APIM_GATEWAY_CALLER_TPM |
O | Y: "10000"J.dev: "10000" |
Fair-use TPM allocation per APIM subscription. |
apimGatewayResourceGroup |
APIM_GATEWAY_RESOURCE_GROUP |
C | Y: ""J.dev: "" |
Resource group containing the existing APIM service. Required by the separate AI gateway workflow when APIM is enabled. |
apimGatewayRetryCount |
APIM_GATEWAY_RETRY_COUNT |
O | Y: "2"J.dev: "2" |
Apim gateway retry count. |
apimGatewayServiceName |
APIM_GATEWAY_SERVICE_NAME |
C | Y: ""J.dev: "" |
Existing APIM service with system-assigned managed identity enabled. Required by the separate AI gateway workflow when APIM is enabled. |
apimGatewaySku |
APIM_GATEWAY_SKU |
O | Y: "StandardV2"J.dev: "StandardV2" |
AI gateway SKU: BasicV2=dev/test; StandardV2=production default with VNet integration; PremiumV2=private inbound/outbound, zones, and high scale. Classic Developer/Basic/Standard/Premium are supported but cannot be migrated to v2 in place. Consumption is unsupported because APIM backend circuit breakers are unavailable. |
apimGatewaySkuCapacity |
APIM_GATEWAY_SKU_CAPACITY |
O | Y: 1J.dev: 1 |
BasicV2/StandardV2 scale to 10 units; PremiumV2 scales to 30 units. Set capacity based on APIM gateway CPU/memory metrics. |
apimGatewaySubscriptionId |
APIM_GATEWAY_SUBSCRIPTION_ID |
O | Y: ""J.dev: "" |
Subscription containing APIM. Empty uses the environment subscription. |
cleanFoundryCaphost |
CLEAN_FOUNDRY_CAPHOST |
O | Y: "false"J.dev: "false" |
Clean up capability host on deletion otherwise: false, leaves capability host and its resources (such as VMs) in place when deleting the Foundry project. |
databricksOID |
DATABRICKS_OID |
C | Y: "<optional>_ObjectID"J.dev: "<optional>_ObjectID" |
Databricks object ID mandatory: if enableDatabricks:'true' ensure: find Databricks object ID in Entra ID. |
databricksPrivate |
DATABRICKS_PRIVATE |
O | Y: "true"J.dev: "true" |
Databricks private control plane otherwise: false, only data plane is private; control plane is public. |
disable_whitelisting_for_build_agents |
DISABLE_WHITELISTING_FOR_BUILD_AGENTS |
O | Y: "false"J.dev: "false" |
Disable runner IP whitelisting otherwise: true, skip whitelisting (use only if runner already has network access). |
elasticCompanyName |
ELASTIC_COMPANY_NAME |
C | Y: "Organization"J.dev: "Organization" |
Elastic Cloud company name mandatory: if enableElasticsearch:'true' |
elasticDeploymentSize |
ELASTIC_DEPLOYMENT_SIZE |
O | Y: "small"J.dev: "small" |
Elasticsearch deployment size otherwise: "medium" or "large". |
elasticEmail |
ELASTIC_EMAIL |
C | Y: "admin@example.com"J.dev: "admin@example.com" |
Elastic Cloud account email mandatory: if enableElasticsearch:'true' ensure: valid email address. |
elasticFirstName |
ELASTIC_FIRST_NAME |
C | Y: "AI"J.dev: "AI" |
Elastic Cloud contact first name mandatory: if enableElasticsearch:'true' |
elasticLastName |
ELASTIC_LAST_NAME |
C | Y: "Factory"J.dev: "Factory" |
Elastic Cloud contact last name mandatory: if enableElasticsearch:'true' |
elasticSku |
ELASTIC_SKU |
O | Y: "ess-consumption-2024_Monthly"J.dev: "ess-consumption-2024_Monthly" |
Elastic Cloud SKU |
elasticType |
ELASTIC_TYPE |
O | Y: "ElasticCloud"J.dev: "ElasticCloud" |
Elasticsearch deployment type otherwise: "SelfManagedOnAKS" (future support). |
enableAFoundryCaphost |
ENABLE_FOUNDRY_CAPHOST |
C | Y: "true"J.dev: "true" |
Required for this private Foundry standard-agent architecture. Cannot be disabled; binds Cosmos DB thread storage, AI Search vector storage, and project Storage. mandatory: Required for this private Foundry standard-agent architecture. Cannot be disabled; binds Cosmos DB thread storage, AI Search vector storage, and project Storage. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths. |
enableAIDocIntelligence |
ENABLE_AI_DOC_INTELLIGENCE |
O | Y: "false"J.dev: "false" |
Deploy Azure AI Document Intelligence |
enableAIFactoryCreatedDefaultProjectForAIFv2 |
ENABLE_AIFACTORY_CREATED_DEFAULT_PROJECT_FOR_AIFV2 |
O | Y: "true"J.dev: "true" |
AI Factory default project for AIFv2 otherwise: false, Azure creates a default project with additional CosmosDB, Storage, AI Search, and connections. |
enableAIFactoryHub |
ENABLE_AI_FACTORY_HUB |
O | Y: "false"J.dev: false |
Own AI Factory Hub intent |
enableAIFoundry |
ENABLE_AI_FOUNDRY |
C | Y: "true"J.dev: "true" |
Enable AI Foundry mandatory: Enable AI Foundry recommended: AI Foundry with default project; enterprise-grade private networking, BYOvNet, existing infra. GA. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths. |
enableAIFoundryHub |
ENABLE_AI_FOUNDRY_HUB |
O | Y: "false"J.dev: "false" |
DEPRECATED. AI Foundry Hub (V1) service. Do not enable. Use enableAIFoundry instead. keep-as-is: DEPRECATED. AI Foundry Hub (V1) service. Do not enable. Use enableAIFoundry instead. |
enableAISearch |
ENABLE_AI_SEARCH |
C | Y: "true"J.dev: "true" |
Required capability-host vector store for private Foundry standard agents. mandatory: Required capability-host vector store for private Foundry standard agents. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths. |
enableAISearchSharedPrivateLink |
ENABLE_AI_SEARCH_SHARED_PRIVATE_LINK |
O | Y: "true"J.dev: "true" |
AI Search shared private link otherwise: false, creates a private endpoint in the project vNet. |
enableAIServices |
ENABLE_AI_SERVICES |
O | Y: "false"J.dev: "false" |
DEPRECATED. Standalone AI Services account with Azure OpenAI endpoint. Do not enable. Use enableAIFoundry instead. keep-as-is: DEPRECATED. Standalone AI Services account with Azure OpenAI endpoint. Do not enable. Use enableAIFoundry instead. |
enableAKS |
ENABLE_AKS |
O | Y: "false"J.dev: "false" |
Deploy standalone AKS cluster in project RG |
enableAMPLS |
ENABLE_AMPLS |
O | Y: "false"J.dev: "false" |
Enable AMPLS in Hub otherwise: true, AMPLS created in Hub subscription; AppInsights in private/private mode. |
enableAdminVM |
ENABLE_ADMIN_VM |
O | Y: "false"J.dev: "false" |
Enable Admin VM in common RG |
enableAksForAzureML |
ENABLE_AKS_FOR_AZURE_ML |
O | Y: "false"J.dev: "false" |
Deploy AKS for Azure ML inference |
enableAppInsightsDashboard |
ENABLE_APPINSIGHTS_DASHBOARD |
O | Y: "false"J.dev: "false" |
Deploy Application Insights dashboard |
enableApplicationInsights |
ENABLE_APPLICATION_INSIGHTS |
O | Y: "true"J.dev: "true" |
Deploy project Application Insights |
enableAzureAIVision |
ENABLE_AZURE_AI_VISION |
O | Y: "false"J.dev: "false" |
Deploy Azure AI Vision |
enableAzureMachineLearning |
ENABLE_AZURE_MACHINE_LEARNING |
O | Y: "false"J.dev: "false" |
Deploy Azure ML workspace |
enableAzureMcpServer |
ENABLE_AZURE_MCP_SERVER |
O | Y: "false"J.dev: absent |
Private, read-only MCP deployment; requires prepared project-scoped configuration. |
enableAzureOpenAI |
ENABLE_AZURE_OPENAI |
O | Y: "false"J.dev: "false" |
Deploy standalone Azure OpenAI |
enableAzureSpeech |
ENABLE_AZURE_SPEECH |
O | Y: "false"J.dev: "false" |
Deploy Azure AI Speech |
enableBing |
ENABLE_BING |
O | Y: "false"J.dev: "false" |
Deploy Bing Search |
enableBingCustomSearch |
ENABLE_BING_CUSTOM_SEARCH |
O | Y: "false"J.dev: "false" |
Deploy Bing Custom Search |
enableBotService |
ENABLE_BOT_SERVICE |
O | Y: "true"J.dev: "true" |
Deploy Azure Bot Service keep-as-is: Required for Microsoft Foundry agent scenarios. |
enableContainerApps |
ENABLE_CONTAINER_APPS |
O | Y: "false"J.dev: "false" |
Deploy Azure Container Apps |
enableContentSafety |
ENABLE_CONTENT_SAFETY |
O | Y: "false"J.dev: "false" |
Deploy Azure AI Content Safety |
enableCosmosDB |
ENABLE_COSMOS_DB |
C | Y: "true"J.dev: "true" |
Required capability-host thread and agent-history store for private Foundry standard agents. mandatory: Required capability-host thread and agent-history store for private Foundry standard agents. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths. |
enableDatabricks |
ENABLE_DATABRICKS |
O | Y: "false"J.dev: "false" |
Deploy Databricks workspace |
enableDatafactory |
ENABLE_DATAFACTORY |
O | Y: "false"J.dev: "false" |
Deploy Azure Data Factory in project RG |
enableDatafactoryCommon |
ENABLE_DATAFACTORY_COMMON |
O | Y: "false"J.dev: "false" |
Deploy Azure Data Factory in common RG |
enableDefenderforAIResourceLevel |
ENABLE_DEFENDER_FOR_AI_RESOURCE_LEVEL |
O | Y: "false"J.dev: "false" |
Defender for AI at resource level otherwise: true, enable Microsoft Defender for AI at per-resource level. |
enableDefenderforAISubLevel |
ENABLE_DEFENDER_FOR_AI_SUB_LEVEL |
O | Y: "false"J.dev: "false" |
Defender for AI at subscription level otherwise: true, enable Microsoft Defender for AI at subscription level. |
enableDeleteForDisabledResources |
ENABLE_DELETE_FOR_DISABLED_RESOURCES |
O | Y: "false"J.dev: "false" |
Delete disabled services otherwise: false, keeps all existing resources regardless of ENABLE_* flags. |
enableElasticsearch |
ENABLE_ELASTICSEARCH |
O | Y: "false"J.dev: "false" |
Deploy Elasticsearch keep-as-is: Elastic Cloud managed service. |
enableEventHubs |
ENABLE_EVENT_HUBS |
O | Y: "false"J.dev: "false" |
Deploy Azure Event Hubs |
enableFunction |
ENABLE_FUNCTION |
O | Y: "false"J.dev: "false" |
Deploy Azure Function App |
enableLogicApps |
ENABLE_LOGIC_APPS |
O | Y: "false"J.dev: "false" |
Deploy Azure Logic Apps |
enablePostgreSQL |
ENABLE_POSTGRESQL |
O | Y: "false"J.dev: "false" |
Deploy Azure PostgreSQL |
enableRedisCache |
ENABLE_REDIS_CACHE |
O | Y: "false"J.dev: "false" |
Deploy Azure Cache for Redis |
enableRetries |
ENABLE_RETRIES |
O | Y: "false"J.dev: "false" |
Enable automatic job retries otherwise: true, enable automatic retries on failure for GenAI services deployment. |
enableSQLDatabase |
ENABLE_SQL_DATABASE |
O | Y: "false"J.dev: "false" |
Deploy Azure SQL Database |
enableWebApp |
ENABLE_WEBAPP, ENABLE_WEB_APP (not in .env template) |
O | Y: "false"J.dev: "false" |
Deploy Azure Web App |
foundryApiManagementResourceId |
FOUNDRY_API_MANAGEMENT_RESOURCE_ID |
O | Y: ""J.dev: "" |
APIM resource ID for Foundry integration otherwise: provide existing API Management resource ID to integrate with Microsoft Foundry. |
foundryDeploymentType |
FOUNDRY_DEPLOYMENT_TYPE |
O | Y: "2"J.dev: "2" |
<deprecated>Retained for configuration compatibility. AI Foundry now always uses the second-option account deployment. |
kongGatewayApimHost |
KONG_GATEWAY_APIM_HOST |
C | Y: ""J.dev: "" |
APIM gateway hostname without protocol/path. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret. |
kongGatewayCpu |
KONG_GATEWAY_CPU |
O | Y: 2J.dev: 2 |
Kong gateway cpu. |
kongGatewayImage |
KONG_GATEWAY_IMAGE |
O | Y: "kong/kong-gateway:3.9"J.dev: "kong/kong-gateway:3.9" |
Kong gateway image. |
kongGatewayMemoryGb |
KONG_GATEWAY_MEMORY_GB |
O | Y: 4J.dev: 4 |
Kong gateway memory gb. |
serviceSettingDeployProjectVM |
SERVICE_SETTING_DEPLOY_PROJECT_VM |
O | Y: "false"J.dev: "false" |
Deploy VM in project resource group otherwise: true, deploy a jumpbox VM for use with Azure Bastion. |
updateAIFoundry |
UPDATE_AI_FOUNDRY |
O | Y: "false"J.dev: "false" |
Update AI Foundry properties otherwise: true, re-run to update AI Foundry properties and RBAC. |
Factory, project, naming and orchestration¶
| YAML / JSON key | GHA binding(s) | M/C/O | Source defaults | Description / conditions |
|---|---|---|---|---|
AZURE_CLIENT_ID |
AZURE_CLIENT_ID |
O | Y: absent J.dev: "" |
Preferred credentialless deployment identity: client ID of a federated app or user-assigned managed identity. When set, workflows use OIDC instead of AZURE_CREDENTIALS. |
GITHUB_NEW_REPO |
GITHUB_NEW_REPO |
M | Y: absent J.dev: "" |
New GitHub repository path mandatory: New GitHub repository path ensure: format: |
GITHUB_NEW_REPO_VISIBILITY |
GITHUB_NEW_REPO_VISIBILITY |
O | Y: absent J.dev: "public" |
New repository visibility otherwise: private or internal. |
GITHUB_TEMPLATE_REPO |
GITHUB_TEMPLATE_REPO |
O | Y: absent J.dev: "azure/enterprise-scale-aifactory" |
GitHub template repository keep-as-is: Leave as-is if BYO repo. |
GITHUB_USERNAME |
GITHUB_USERNAME |
M | Y: absent J.dev: "" |
GitHub username or org mandatory: GitHub username or org |
GITHUB_USE_SSH |
GITHUB_USE_SSH |
O | Y: absent J.dev: "false" |
Use SSH for git operations otherwise: true, use SSH instead of HTTPS. |
aca_w_registry_image |
ACA_W_REGISTRY_IMAGE |
O | Y: "mcr.microsoft.com/azuredocs/containerapps-helloworld:latest"J.dev: "mcr.microsoft.com/azuredocs/containerapps-helloworld:latest" |
Container Apps default image otherwise: replace with your own ACR image. |
adminUsername |
ADMIN_USERNAME |
O | Y: "esmladmin"J.dev: "esmladmin" |
VM admin username |
admin_aiSearchTier |
ADMIN_AISEARCH_TIER |
M | Y: "basic"J.dev: "basic" |
AI Search SKU tier mandatory: AI Search SKU tier ensure: 'free' is not allowed when using private endpoints. ['free', 'basic', 'standard', 'standard2', 'standard3', 'storage_optimized_l1', 'storage_optimized_l2'] |
admin_aifactoryPrefixRG |
AIFACTORY_PREFIX |
O | Y: "mrvel-1-"J.dev: "mrvel-1-" |
AI Factory resource group prefix keep-as-is: Max 6 chars. otherwise: set your company prefix, e.g. "acme-ai-", "contoso-". |
admin_aifactorySuffixRG |
AIFACTORY_SUFFIX |
M | Y: "-001"J.dev: "-001" |
AI Factory scaleset suffix mandatory: AI Factory scaleset suffix keep-as-is: For 1st scaleset. otherwise: increment to '-002', '-003' for additional scalesets. |
admin_commonResourceSuffix |
ADMIN_COMMON_RESOURCE_SUFFIX |
O | Y: "-001"J.dev: "-001" |
Common resources suffix otherwise: change to reprovision new services in the same common RG while keeping old ones. |
admin_hybridBenefit |
ADMIN_HYBRID_BENEFIT |
O | Y: "false"J.dev: "false" |
Azure Hybrid Benefit for VMs otherwise: true, if you have eligible Windows licenses with Software Assurance (pay-as-you-go avoided). |
admin_ip_fw |
ADMIN_IP_FW |
O | Y: ""J.dev: "" |
Leave empty. Will be automatically set by the pipeline to the build agent IP. keep-as-is: Leave empty. Will be automatically set by the pipeline to the build agent IP. |
admin_keyvaultSoftDeleteDays |
KEYVAULT_SOFT_DELETE |
C | Y: 7J.dev: 7 |
Key Vault soft delete days mandatory: if cmk:'true' (purge protection required). otherwise: 90 days recommended; 0 to disable. |
admin_location |
AIFACTORY_LOCATION |
M | Y: "eastus2"J.dev: "eastus2" |
Azure region mandatory: Azure region |
admin_locationSuffix |
AIFACTORY_LOCATION_SHORT |
M | Y: "eus2"J.dev: "eus2" |
Region short name mandatory: Region short name |
admin_prjResourceSuffix |
ADMIN_PRJ_RESOURCE_SUFFIX |
O | Y: "-001"J.dev: "-001" |
Project resources suffix otherwise: change to reprovision new services in the same project RG while keeping old ones. |
admin_projectType |
PROJECT_TYPE |
M | Y: "all"J.dev: "all" |
|
admin_semanticSearchTier |
ADMIN_SEMANTIC_SEARCH_TIER, AISEARCH_SEMANTIC_TIER |
M | Y: "free"J.dev: "free" |
Semantic search tier mandatory: Semantic search tier |
aiSearchLocation |
AI_SEARCH_LOCATION |
O | Y: ""J.dev: "" |
AI Search region override. Empty keeps the project region; use another supported region only when regional Search capacity is unavailable. |
aifactory-dash-01 |
AIFACTORY_DASHBOARD_URL |
O | Y: ""J.dev: "" |
Existing Azure Portal AI Factory dashboard URL; never deploys a dashboard. |
aifactory_branch_chosen |
AIFACTORY_BRANCH_CHOSEN |
O | Y: "release/v1.24"J.dev: "release/v1.24" |
Submodule release branch |
aifactory_salt |
AIFACTORY_SALT |
O | Y: ""J.dev: "" |
Leave empty, 5 characters. A deteministic unique value, from COMMON RG |
aifactory_salt_random |
AIFACTORY_SALT_RANDOM |
O | Y: ""J.dev: "" |
Leave empty. 10-character unique random value derived from User-Assigned Managed Identity. Auto-populated by the pipeline. keep-as-is: Leave empty. 10-character unique random value derived from User-Assigned Managed Identity. Auto-populated by the pipeline. |
aifactory_version_major |
AIFACTORY_VERSION_MAJOR |
O | Y: "1"J.dev: "1" |
AI Factory major version keep-as-is: Used to determine which bicep files to use. |
aifactory_version_minor |
AIFACTORY_VERSION_MINOR |
O | Y: "24"J.dev: "24" |
AI Factory minor version keep-as-is: 2025-09-20: 24 = release/v1.24 |
aisearchRetryCapcityArray |
AISEARCH_RETRY_CAPCITY_ARRAY |
O | Y: "true"J.dev: "true" |
Validate all candidates' quota headroom and retry only Azure AI Search capacity failures. |
aseSku |
ASE_SKU |
O | Y: "IsolatedV2"J.dev: "IsolatedV2" |
App Service Environment SKU keep-as-is: Used only if byoASEv3:'true' or a dedicated ASE is provisioned. |
aseSkuCode |
ASE_SKU_CODE |
O | Y: "I1v2"J.dev: "I1v2" |
App Service Environment SKU code |
aseSkuWorkers |
ASE_SKU_WORKERS |
O | Y: 1J.dev: 1 |
App Service Environment worker count |
bastion_custom_name |
BASTION_CUSTOM_NAME |
O | Y: ""J.dev: "" |
Bastion name override for common RG RBAC keep-as-is: Empty uses the standard Bastion naming convention. |
bastion_subscription_resource_group |
BASTION_SUBSCRIPTION_RESOURCE_GROUP |
O | Y: ""J.dev: "" |
Bastion resource group override for common RG RBAC keep-as-is: Empty uses the common resource group. |
bingCustomSearchSku |
BING_CUSTOM_SEARCH_SKU |
O | Y: "G2"J.dev: "G2" |
Bing Custom Search SKU keep-as-is: ['G2'] G2 is custom search with grounding. |
commonLakeNamePrefixMax8chars |
COMMON_LAKE_NAME_PREFIX_MAX8CHARS (not in .env template), LAKE_PREFIX |
O | Y: "mrvel"J.dev: "mrvel" |
Data lake storage name prefix keep-as-is: Max 8 characters. |
commonResourceGroup_param |
COMMON_RESOURCE_GROUP_PARAM |
O | Y: ""J.dev: "" |
BYO common resource group name otherwise: provide a custom name for the common resource group. |
containerAppsRetryCapacityArray |
CONTAINER_APPS_RETRY_CAPACITY_ARRAY |
O | Y: "true"J.dev: "true" |
Retry only Container Apps capacity failures, with 240 seconds before attempts 2 and 3. |
cosmosKind |
COSMOS_KIND |
O | Y: "GlobalDocumentDB"J.dev: "GlobalDocumentDB" |
Cosmos DB kind otherwise: "MongoDB". |
datalakeName_param |
DATALAKE_NAME_PARAM |
O | Y: ""J.dev: "" |
BYO data lake storage account name otherwise: provide a custom storage account name. |
dev_admin_bicep_input_keyvault_subscription |
AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID |
M | Y: "<todo>_SubID"J.dev: "<todo>_SubID" |
DEV seeding KV subscription ID mandatory: DEV seeding KV subscription ID ensure: subscription where the DEV seeding Key Vault resides. |
dev_admin_bicep_kv_fw |
AIFACTORY_SEEDING_KEYVAULT_NAME |
M | Y: "<todo>_Name_Dev"J.dev: "<todo>_Name_Dev" |
DEV seeding KV name mandatory: DEV seeding KV name ensure: Key Vault name storing secrets mapped to PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID. |
dev_admin_bicep_kv_fw_rg |
AIFACTORY_SEEDING_KEYVAULT_RG |
M | Y: "<todo>_ResourceGroup_DEV"J.dev: "<todo>_ResourceGroup_DEV" |
DEV seeding KV resource group mandatory: DEV seeding KV resource group ensure: resource group where the DEV seeding Key Vault resides. |
dev_sub_id |
DEV_SUBSCRIPTION_ID |
M | Y: "<todo>_SubID"J.dev: "<todo>_SubID" |
DEV subscription ID mandatory: DEV subscription ID |
functionRuntime |
FUNCTION_RUNTIME |
O | Y: "dotnet"J.dev: "dotnet" |
Azure Function runtime otherwise: "python", "node", "java", "powershell". |
functionVersion |
FUNCTION_VERSION |
O | Y: "v7.0"J.dev: "v7.0" |
Azure Function runtime version |
kvNameFromCOMMON_param |
KV_NAME_FROM_COMMON_PARAM |
O | Y: ""J.dev: "" |
BYO common Key Vault name otherwise: provide a custom Key Vault name. |
lakeContainerName |
LAKE_CONTAINER_NAME |
O | Y: "lake3"J.dev: "lake3" |
Data lake container name |
org-department-id |
ORG_DEPARTMENT_ID |
O | Y: ""J.dev: "" |
Project organizational department ID keep-as-is: Text, max 128 characters, not necessarily a GUID; identical across environments. No identity or authentication effect. |
org-department-name |
ORG_DEPARTMENT_NAME |
O | Y: ""J.dev: "" |
Project organizational department name keep-as-is: Unicode text, max 200 characters; identical across environments, independent of cost center. No factory inheritance or Azure tag writes. |
postGresAdminEmails |
POSTGRES_ADMIN_EMAILS |
C | Y: "email_adress_only"J.dev: "email_adress_only" |
PostgreSQL admin emails mandatory: if enablePostgreSQL:'true' ensure: valid comma-separated email addresses. |
postgreSQLRetryCapacityArray |
POSTGRESQL_RETRY_CAPACITY_ARRAY |
O | Y: "true"J.dev: "true" |
Retry only PostgreSQL regional/SKU capacity failures, with 240 seconds before attempts 2 and 3. |
prod_admin_bicep_input_keyvault_subscription |
AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID |
C | Y: "<todo>_SubID"J.dev: "<todo>_SubID" |
PROD seeding KV subscription ID mandatory: PROD seeding KV subscription ID ensure: subscription where the PROD seeding Key Vault resides. Required when deploying that environment. |
prod_admin_bicep_kv_fw |
AIFACTORY_SEEDING_KEYVAULT_NAME |
C | Y: "<todo>_Name_Prod"J.dev: "<todo>_Name_Prod" |
PROD seeding KV name mandatory: PROD seeding KV name ensure: Key Vault name storing secrets mapped to PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID. Required when deploying that environment. |
prod_admin_bicep_kv_fw_rg |
AIFACTORY_SEEDING_KEYVAULT_RG |
C | Y: "<todo>_ResourceGroup_Prod"J.dev: "<todo>_ResourceGroup_Prod" |
PROD seeding KV resource group mandatory: PROD seeding KV resource group ensure: resource group where the PROD seeding Key Vault resides. Required when deploying that environment. |
prod_sub_id |
PROD_SUBSCRIPTION_ID |
C | Y: "<todo>_SubID"J.dev: "<todo>_SubID" |
PROD subscription ID recommended: separate subscription from DEV. otherwise: can reuse dev_sub_id. Required when deploying that environment. |
projectPrefix |
PROJECT_PREFIX |
O | Y: "esml-"J.dev: "esml-" |
Project resource group prefix |
projectSuffix |
PROJECT_SUFFIX |
O | Y: "-rg"J.dev: "-rg" |
Project resource group suffix |
project_number_000 |
PROJECT_NUMBER |
M | Y: "001"J.dev: "001" |
Project number mandatory: Project number keep-as-is: For 1st project. otherwise: increment to '002', '003', etc. |
tag_costcenter |
CostCenter (not in .env template), TAG_COSTCENTER |
O | Y: "1234"J.dev: "1234" |
Project cost center tag keep-as-is: Metadata for per-project cost tracking on resource group level. |
tag_costceter_common |
TAG_COSTCETER_COMMON |
O | Y: "9999"J.dev: "9999" |
Common cost center tag keep-as-is: Metadata for Resource group cost tracking. |
tag_repository |
TAG_REPOSITORY |
O | Y: "aifactory"J.dev: "aifactory" |
Repository name tag |
tag_repository_branch |
TAG_REPOSITORY_BRANCH |
O | Y: "aifactory-001"J.dev: "aifactory-001" |
Repository branch tag otherwise: per scaleset 'aifactory-002', or per project 'aifactory-001/project001-main'. |
tags |
TAGS |
O | Y: "{\"CostCenter\":\"$(tag_costceter_common)\",\"Description\":\"AI Factory common\",\"AIF-Repo\":\"$(tag_repository)\",\"AIF-Branch\":\"$(tag_repository_branch)\",\"AIF-Version\":\"$(aifactory_version_major).$(aifactory_version_minor)\",\"AIF-Submodule-Chosen-Branch\":\"$(aifactory_branch_chosen)\",\"AIF-Scaleset\":\"$(admin_aifactorySuffixRG)\",\"AIF-Environment\":\"$(dev_test_prod)\",\"AIF-Project Owners\":\"$(technical_admins_email)\",\"AIFactory project\":\"$(project_number_000)\",\"AIF-Networking\":\"$(allowPublicAccessWhenBehindVnet),$(enablePublicGenAIAccess),$(enablePublicAccessWithPerimeter)\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"$(enableAIFactoryCreatedDefaultProjectForAIFv2)\",\"AIF-disableAgentNetworkInjection\":\"$(disableAgentNetworkInjection)\",\"AIF-byoASEv3\":\"$(byoASEv3)\",\"AIF-BYO_subnets\":\"$(BYO_subnets)\"}"J.dev: "{\"CostCenter\":\"$(tag_costceter_common)\",\"Description\":\"AI Factory common\",\"AIF-Repo\":\"$(tag_repository)\",\"AIF-Branch\":\"$(tag_repository_branch)\",\"AIF-Version\":\"$(aifactory_version_major).$(aifactory_version_minor)\",\"AIF-Submodule-Chosen-Branch\":\"$(aifactory_branch_chosen)\",\"AIF-Scaleset\":\"$(admin_aifactorySuffixRG)\",\"AIF-Environment\":\"$(dev_test_prod)\",\"AIF-Project Owners\":\"$(technical_admins_email)\",\"AIFactory project\":\"$(project_number_000)\",\"AIF-Networking\":\"$(allowPublicAccessWhenBehindVnet),$(enablePublicGenAIAccess),$(enablePublicAccessWithPerimeter)\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"$(enableAIFactoryCreatedDefaultProjectForAIFv2)\",\"AIF-disableAgentNetworkInjection\":\"$(disableAgentNetworkInjection)\",\"AIF-byoASEv3\":\"$(byoASEv3)\",\"AIF-BYO_subnets\":\"$(BYO_subnets)\"}" |
Common resource tags as a JSON string; Azure DevOps macro expressions are preserved. |
tagsProject |
TAGS_PROJECT |
O | Y: "{\"CostCenter\":\"$(tag_costcenter)\",\"Description\":\"RAG Chat 1\",\"AIF-Branch\":\"$(tag_repository_branch)/project$(project_number_000)\",\"AIF-Scaleset\":\"$(admin_aifactorySuffixRG)\",\"AIF-Environment\":\"$(dev_test_prod)\",\"AIF-Project Owners\":\"$(technical_admins_email)\",\"AIFactory project\":\"$(project_number_000)\",\"AIF-Networking\":\"$(allowPublicAccessWhenBehindVnet),$(enablePublicGenAIAccess),$(enablePublicAccessWithPerimeter)\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"$(enableAIFactoryCreatedDefaultProjectForAIFv2)\",\"AIF-disableAgentNetworkInjection\":\"$(disableAgentNetworkInjection)\",\"AIF-byoASEv3\":\"$(byoASEv3)\",\"AIF-BYO_subnets\":\"$(BYO_subnets)\"}"J.dev: "{\"CostCenter\":\"$(tag_costcenter)\",\"Description\":\"RAG Chat 1\",\"AIF-Branch\":\"$(tag_repository_branch)/project$(project_number_000)\",\"AIF-Scaleset\":\"$(admin_aifactorySuffixRG)\",\"AIF-Environment\":\"$(dev_test_prod)\",\"AIF-Project Owners\":\"$(technical_admins_email)\",\"AIFactory project\":\"$(project_number_000)\",\"AIF-Networking\":\"$(allowPublicAccessWhenBehindVnet),$(enablePublicGenAIAccess),$(enablePublicAccessWithPerimeter)\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"$(enableAIFactoryCreatedDefaultProjectForAIFv2)\",\"AIF-disableAgentNetworkInjection\":\"$(disableAgentNetworkInjection)\",\"AIF-byoASEv3\":\"$(byoASEv3)\",\"AIF-BYO_subnets\":\"$(BYO_subnets)\"}" |
Project resource tags as a JSON string; Azure DevOps macro expressions are preserved. |
test_admin_bicep_input_keyvault_subscription |
AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID |
C | Y: "<todo>_SubID"J.dev: "<todo>_SubID" |
STAGE seeding KV subscription ID mandatory: STAGE seeding KV subscription ID ensure: subscription where the STAGE seeding Key Vault resides. Required when deploying that environment. |
test_admin_bicep_kv_fw |
AIFACTORY_SEEDING_KEYVAULT_NAME |
C | Y: "<todo>_Name_Test"J.dev: "<todo>_Name_Test" |
STAGE seeding KV name mandatory: STAGE seeding KV name ensure: Key Vault name storing secrets mapped to PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID. Required when deploying that environment. |
test_admin_bicep_kv_fw_rg |
AIFACTORY_SEEDING_KEYVAULT_RG |
C | Y: "<todo>_ResourceGroup_Test"J.dev: "<todo>_ResourceGroup_Test" |
STAGE seeding KV resource group mandatory: STAGE seeding KV resource group ensure: resource group where the STAGE seeding Key Vault resides. Required when deploying that environment. |
test_sub_id |
STAGE_SUBSCRIPTION_ID |
C | Y: "<todo>_SubID"J.dev: "<todo>_SubID" |
STAGE subscription ID recommended: separate subscription from DEV. otherwise: can reuse dev_sub_id. Required when deploying that environment. |
useCommonACR |
USE_COMMON_ACR_FOR_PROJECTS |
O | Y: "true"J.dev: "true" |
Use shared ACR across projects otherwise: false, each project gets its own ACR (higher cost). |
useCommonACR_override |
USE_COMMON_ACR_FOR_PROJECTS, USE_COMMON_ACR_OVERRIDE |
O | Y: "true"J.dev: "true" |
Use shared ACR override otherwise: false, each project gets its own ACR (higher cost). |
webAppRuntime |
WEBAPP_RUNTIME |
O | Y: "python"J.dev: "python" |
Azure Web App runtime otherwise: "dotnet", "node", "java". |
webAppRuntimeVersion |
WEBAPP_RUNTIME_VERSION |
O | Y: "3.11"J.dev: "3.11" |
Azure Web App runtime version |
Networking, DNS and existing resources¶
| YAML / JSON key | GHA binding(s) | M/C/O | Source defaults | Description / conditions |
|---|---|---|---|---|
BYOContributorRoleID |
BYO_CONTRIBUTOR_ROLE_ID |
O | Y: "b24988ac-6180-42a0-ab88-20f7382dd24c"J.dev: "b24988ac-6180-42a0-ab88-20f7382dd24c" |
Contributor role ID keep-as-is: Azure built-in Contributor. otherwise: provide a custom role ID for finer-grained access control. |
BYO_subnets |
BYO_SUBNETS |
O | Y: "false"J.dev: "false" |
Bring your own subnets otherwise: true, uses pre-existing subnets defined by the BYO subnet variables below. |
acr_IP_whitelist |
ACR_IP_WHITELIST |
O | Y: ""J.dev: "" |
ACR IP allowlist otherwise: provide comma-separated IPv4 addresses if ACR network restrictions are needed. |
allowPublicAccessWhenBehindVnet |
ALLOW_PUBLIC_ACCESS_WHEN_BEHIND_VNET (not in .env template) |
O | Y: "true"J.dev: "true" |
Public UI access when behind vNet recommended: false to enable fully private networking. |
byoASEv3 |
BYO_ASEV3 |
O | Y: "false"J.dev: "false" |
Use BYO App Service Environment v3 otherwise: true, use an existing ASEv3 specified in byoAseFullResourceId. |
byoAseAppServicePlanResourceId |
BYO_ASE_APP_SERVICE_PLAN_RESOURCE_ID |
O | Y: ""J.dev: "" |
BYO App Service Plan resource ID otherwise: provide full ARM resource ID of an existing App Service Plan within the ASEv3. |
byoAseFullResourceId |
BYO_ASE_FULL_RESOURCE_ID |
C | Y: "subscriptions/...yourASEnameS2"J.dev: "subscriptions/...yourASEnameS2" |
BYO ASEv3 ARM resource ID. Note - remove leading slash / in Resource ID mandatory: if byoASEv3:'true' ensure: full ARM resource ID of the existing ASEv3. |
centralDnsZoneByPolicyInHub |
CENTRAL_DNS_ZONE_BY_POLICY_IN_HUB |
O | Y: "false"J.dev: false |
Centralized DNS via Hub policy otherwise: true, uses central private DNS zones in HUB resource group managed by Azure Policy. |
common_bastion_subnet_cidr |
COMMON_BASTION_SUBNET_CIDR |
M | Y: "172.16.XX.192/26"J.dev: "172.16.XX.192/26" |
Bastion subnet CIDR mandatory: Bastion subnet CIDR keep-as-is: XX replaced by the selected environment range. ensure: within common_vnet_cidr. |
common_bastion_subnet_name |
COMMON_BASTION_SUBNET_NAME |
M | Y: "AzureBastionSubnet"J.dev: "AzureBastionSubnet" |
Bastion subnet name mandatory: Bastion subnet name keep-as-is: Required name for Azure Bastion. ensure: within common_vnet_cidr. |
common_pbi_subnet_cidr |
COMMON_PBI_SUBNET_CIDR |
M | Y: "172.16.XX.128/26"J.dev: "172.16.XX.128/26" |
Power BI gateway subnet CIDR mandatory: Power BI gateway subnet CIDR keep-as-is: XX replaced by the selected environment range. ensure: within common_vnet_cidr. |
common_pbi_subnet_name |
COMMON_PBI_SUBNET_NAME |
M | Y: "snet-esml-cmn-pbi-001"J.dev: "snet-esml-cmn-pbi-001" |
Power BI gateway subnet name mandatory: Power BI gateway subnet name ensure: within common_vnet_cidr. |
common_subnet_cidr |
COMMON_SUBNET_CIDR |
M | Y: "172.16.XX.0/26"J.dev: "172.16.XX.0/26" |
Common subnet CIDR mandatory: Common subnet CIDR keep-as-is: XX replaced by the selected environment range. ensure: within common_vnet_cidr. |
common_subnet_name |
COMMON_SUBNET_NAME (not in .env template), SUBNET_COMMON_BASE |
O | Y: "snet-esml-cmn-001"J.dev: "snet-esml-cmn-001" |
Common subnet name |
common_subnet_scoring_cidr |
COMMON_SUBNET_SCORING_CIDR |
M | Y: "172.16.XX.64/26"J.dev: "172.16.XX.64/26" |
Scoring subnet CIDR mandatory: Scoring subnet CIDR keep-as-is: XX replaced by the selected environment range. ensure: within common_vnet_cidr. |
common_vnet_cidr |
COMMON_VNET_CIDR |
M | Y: "172.16.XX.0/18"J.dev: "172.16.XX.0/18" |
Common vNet CIDR mandatory: Common vNet CIDR keep-as-is: XX is the network-aligned per-environment octet; Dev/Stage/Prod must not overlap. Address intent only, not actual peering. |
dev_cidr_range |
DEV_CIDR_RANGE |
M | Y: "0"J.dev: "0" |
DEV network-aligned XX value mandatory: DEV network-aligned XX value keep-as-is: VNet 172.16.0.0/18. |
disableAgentNetworkInjection |
DISABLE_AGENT_NETWORK_INJECTION |
O | Y: "false"J.dev: "false" |
Disable agent network injection keep-as-is: false, requires Container Apps subnet in 172.16.0.0/12 or 192.168.0.0/16. otherwise: true, disables network injection. |
disableSubnetJoinAction |
DISABLE_SUBNET_JOIN_ACTION |
O | Y: "false"J.dev: "false" |
Disable VNet subnet join RBAC recommended: false, grants Network Contributor role for subnet join actions (required for APIM, Container Apps, AKS). otherwise: true, skip if subnet permissions managed externally. |
enablePublicAccessWithPerimeter |
ENABLE_PUBLIC_ACCESS_WITH_PERIMETER |
O | Y: "true"J.dev: "true" |
Public access with network perimeter recommended: false to enable fully private networking. |
enablePublicGenAIAccess |
ENABLE_PUBLIC_GENAI_ACCESS |
O | Y: "true"J.dev: "true" |
Public GenAI access (control plane) recommended: false to enable fully private networking. |
kongGatewaySubnetCidr |
KONG_GATEWAY_SUBNET_CIDR |
C | Y: ""J.dev: "" |
Dedicated, unused /28 or larger subnet. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret. |
kongGatewaySubnetName |
KONG_GATEWAY_SUBNET_NAME |
O | Y: "snet-kong-001"J.dev: "snet-kong-001" |
Kong gateway subnet name. |
kongGatewayVnetName |
KONG_GATEWAY_VNET_NAME |
C | Y: ""J.dev: "" |
Kong gateway vnet name. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret. |
kongGatewayVnetResourceGroup |
KONG_GATEWAY_VNET_RESOURCE_GROUP |
C | Y: ""J.dev: "" |
Kong gateway vnet resource group. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret. |
network_env_dev |
DEV_NETWORK_ENV |
O | Y: "dev-"J.dev: "dev-" |
DEV environment prefix for BYO subnets otherwise: set to empty string if not using environment-prefixed naming. |
network_env_prod |
PROD_NETWORK_ENV |
O | Y: "prd-"J.dev: "prd-" |
PROD environment prefix for BYO subnets otherwise: "prod-", "pr-", or empty string. |
network_env_stage |
STAGE_NETWORK_ENV |
O | Y: "tst2-"J.dev: "tst2-" |
STAGE environment prefix for BYO subnets otherwise: "test-", "tst-", or empty string. |
privDnsResourceGroup_param |
PRIV_DNS_RESOURCE_GROUP_PARAM |
C | Y: "<todo>_ResourceGroup_name"J.dev: "<todo>_ResourceGroup_name" |
Hub DNS resource group mandatory: if centralDnsZoneByPolicyInHub:'true' ensure: Hub connectivity resource group where central private DNS zones are deployed. |
privDnsSubscription_param |
PRIV_DNS_SUBSCRIPTION_PARAM |
C | Y: "<todo>_SubscriptionID"J.dev: "<todo>_SubscriptionID" |
Hub DNS subscription ID mandatory: if centralDnsZoneByPolicyInHub:'true' ensure: Hub connectivity subscription ID where central private DNS zones are deployed. |
prod_cidr_range |
PROD_CIDR_RANGE |
M | Y: "128"J.dev: "128" |
PROD network-aligned XX value mandatory: PROD network-aligned XX value keep-as-is: VNet 172.16.128.0/18. |
project_IP_whitelist |
PROJECT_IP_WHITELIST (not in .env template), PROJECT_MEMBERS_IP_ADDRESS |
C | Y: ""J.dev: "" |
Project UI IP allowlist mandatory: if using IP-whitelisting networking mode ensure: comma-separated IPv4 addresses without spaces, e.g. "10.123.456.10,124.56.78.0/24". |
runNetworkingVar |
RUN_JOB1_NETWORKING |
M | Y: "true"J.dev: "true" |
Run networking module mandatory: Run networking module keep-as-is: true when creating or updating a project. otherwise: false, to skip networking on service-only updates. |
scaling-mode |
SCALING_MODE |
O | Y: "shared-subscriptions"J.dev: "shared-subscriptions" |
Address-planning preset: own-subscriptions or shared-subscriptions. Does not create subscriptions, resize networks, or establish peering. |
subnetCommon |
SUBNET_COMMON |
C | Y: "snet-dev-esml-cmn-001"J.dev: "snet-dev-esml-cmn-001" |
BYO common subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists in your vNet. |
subnetCommonPowerbiGw |
SUBNET_COMMON_POWERBI_GW |
C | Y: "snet-esml-cmn-pbi-001"J.dev: "snet-esml-cmn-pbi-001" |
BYO Power BI gateway subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists. |
subnetCommonScoring |
SUBNET_COMMON_SCORING |
C | Y: "snet-<network_env>esml-cmn-001-scoring"J.dev: "snet-<network_env>esml-cmn-001-scoring" |
BYO scoring subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists. |
subnetProjACA |
SUBNET_PROJ_ACA |
C | Y: "snt-prj<xxx>-aca"J.dev: "snt-prj<xxx>-aca" |
ContainerApps subnet. BYO project Container Apps subnet mandatory: if BYO_subnets:'true' ensure: subnet exists and CIDR is in 172.16.0.0/12 or 192.168.0.0/16 if disableAgentNetworkInjection:'false'. |
subnetProjACA2 |
SUBNET_PROJ_ACA2 |
C | Y: "snt-prj<xxx>-aca-002"J.dev: "snt-prj<xxx>-aca-002" |
Agent subnet. BYO project secondary Container Apps subnet mandatory: if BYO_subnets:'true' AND enableAIFoundry:'true' AND disableAgentNetworkInjection is 'false' |
subnetProjAKS |
SUBNET_PROJ_AKS |
C | Y: "snt-prj<xxx>-aks"J.dev: "snt-prj<xxx>-aks" |
BYO project AKS subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists. |
subnetProjAKS2 |
SUBNET_PROJ_AKS2 |
C | Y: "snt-<network_env>prj<xxx>-aks2"J.dev: "snt-<network_env>prj<xxx>-aks2" |
BYO project secondary AKS subnet mandatory: if BYO_subnets:'true' ensure: subnet exists. |
subnetProjDatabricksPrivate |
SUBNET_PROJ_DATABRICKS_PRIVATE, SUBNET_PROJ_DBX_PRIVATE (not in .env template) |
C | Y: "snt-prj<xxx>-dbxpriv"J.dev: "snt-prj<xxx>-dbxpriv" |
BYO Databricks private subnet mandatory: if BYO_subnets:'true' and enableDatabricks:'true'. |
subnetProjDatabricksPublic |
SUBNET_PROJ_DATABRICKS_PUBLIC, SUBNET_PROJ_DBX_PUBLIC (not in .env template) |
C | Y: "snt-prj001-dbxpub"J.dev: "snt-prj001-dbxpub" |
BYO Databricks public subnet mandatory: if BYO_subnets:'true' and enableDatabricks:'true'. |
subnetProjGenAI |
SUBNET_PROJ_GENAI |
C | Y: "snt-dev-prj<xxx>-genai"J.dev: "snt-dev-prj<xxx>-genai" |
BYO project GenAI subnet name mandatory: if BYO_subnets:'true' ensure: subnet exists. |
subnetProjWebapp |
SUBNET_PROJ_WEBAPP |
C | Y: "snt-prj<xxx>-webapp"J.dev: "snt-prj<xxx>-webapp" |
App Service/Function VNet integration subnet (delegated to Microsoft.Web/serverFarms) mandatory: if BYO_subnets:'true' AND (enableWebApp:'true' OR enableFunction:'true') ensure: subnet exists. |
test_cidr_range |
STAGE_CIDR_RANGE |
M | Y: "64"J.dev: "64" |
STAGE network-aligned XX value mandatory: STAGE network-aligned XX value keep-as-is: VNet 172.16.64.0/18. |
vnetNameBase |
VNET_NAME_BASE |
O | Y: "vnt-esmlcmn"J.dev: "vnt-esmlcmn" |
Common vNet base name otherwise: ignored if vnetNameFull_param is set (BYOvNet). |
vnetNameFull_param |
VNET_NAME_FULL_PARAM |
O | Y: ""J.dev: "" |
BYO vNet full name otherwise: provide the full name of your existing vNet. |
vnetResourceGroupBase |
VNET_RESOURCE_GROUP_BASE |
O | Y: "esml-common"J.dev: "esml-common" |
Common vNet resource group base otherwise: ignored if vnetResourceGroup_param is set (BYOvNet). |
vnetResourceGroup_param |
VNET_RESOURCE_GROUP_PARAM |
O | Y: ""J.dev: "" |
BYO vNet resource group otherwise: provide the full RG name of your existing vNet. |
Operations, diagnostics and lifecycle¶
| YAML / JSON key | GHA binding(s) | M/C/O | Source defaults | Description / conditions |
|---|---|---|---|---|
adminVMBuildAgentName |
No verified binding | O | Y: ""J.dev: "" |
Azure DevOps agent name override keep-as-is: Leave empty for the Bicep-generated admin VM name; set to an existing VM agent name such as vm-test when reusing one. |
adminVMBuildAgentPool |
No verified binding | O | Y: "Default"J.dev: "Default" |
Azure DevOps pool hosting the admin VM agent keep-as-is: Change only when the agent is registered in a custom pool. |
debugEnableCleaning |
DEBUG_ENABLE_CLEANING |
O | Y: "false"J.dev: "false" |
Enable error cleanup tasks otherwise: true, enables cleanup tasks (71-73) that delete resources on deployment failures. Use only when debugging. |
debug_disable_05_build_acr_image |
DEBUG_DISABLE_05_BUILD_ACR_IMAGE |
O | Y: "false"J.dev: "false" |
Skip ACR image build step otherwise: true, skip. Cannot be disabled if enableContainerApps:'true'. |
debug_disable_10_aifactory_dashboards |
DEBUG_DISABLE_10_AIFACTORY_DASHBOARDS |
O | Y: "true"J.dev: "true" |
Skip AI Factory dashboards step |
debug_disable_61_foundation |
DEBUG_DISABLE_61_FOUNDATION |
O | Y: "false"J.dev: "false" |
Skip foundation step otherwise: true, skip: Resource groups, User-Assigned Managed Identities, VMs. |
debug_disable_62_core_infrastructure |
DEBUG_DISABLE_62_CORE_INFRASTRUCTURE |
O | Y: "false"J.dev: "false" |
Skip core infrastructure step otherwise: true, skip: Application Insights, Key Vault, Storage, ACR. |
debug_disable_63_cognitive_services |
DEBUG_DISABLE_63_COGNITIVE_SERVICES |
O | Y: "false"J.dev: "false" |
Skip cognitive services step otherwise: true, skip: AI Search, OpenAI, Vision, Speech, etc. |
debug_disable_64_databases |
DEBUG_DISABLE_64_DATABASES |
O | Y: "false"J.dev: "false" |
Skip databases step otherwise: true, skip: Cosmos DB, SQL Database, etc. |
debug_disable_65_compute_services |
DEBUG_DISABLE_65_COMPUTE_SERVICES |
O | Y: "false"J.dev: "false" |
Skip compute services step otherwise: true, skip: Container Apps, Web App, Function App. |
debug_disable_66_ai_platform |
DEBUG_DISABLE_66_AI_PLATFORM |
O | Y: "false"J.dev: "false" |
Skip AI platform step otherwise: true, skip: AI Foundry Hub (V1) with default project and connections. |
debug_disable_67_data_ml_platform |
DEBUG_DISABLE_67_ML_PLATFORM |
O | Y: "false"J.dev: "false" |
Skip ML platform step otherwise: true, skip: Azure Machine Learning, Data Factory, Databricks. |
debug_disable_68_integration |
DEBUG_DISABLE_68_INTEGRATION |
O | Y: "false"J.dev: "false" |
Skip integration step otherwise: true, skip: Logic Apps, Event Hubs. |
debug_disable_69_aifoundry_2025 |
DEBUG_DISABLE_69_AIFOUNDRY_2025 |
O | Y: "false"J.dev: "false" |
Skip AI Foundry V2 step otherwise: true, skip: AI Foundry V2 including RBAC and default project. |
debug_disable_validation_tasks |
DEBUG_DISABLE_VALIDATION_TASKS |
O | Y: "false"J.dev: "false" |
Disable validation tasks otherwise: true, skip subnet validation, submodule check, DNS zones check to speed up re-runs. |
deleteAllForProject |
DELETE_ALL_FOR_PROJECT |
O | Y: "false"J.dev: "false" |
ULTRA DELETE MODE - Delete ALL resources in project RG and networking resources (subnets, NSGs) in common RG. Use with extreme caution! |
deleteAllServicesForProject |
DELETE_ALL_SERVICES_FOR_PROJECT |
O | Y: "false"J.dev: "false" |
Delete all project services otherwise: true, deletes all services in project RG in step 04 then quits pipeline (Key Vault retained by default; set deleteKeyvaultAlso:'true' to also delete it). |
deleteKeyvaultAlso |
DELETE_KEYVAULT_ALSO |
O | Y: "false"J.dev: "false" |
Also delete Key Vault when deleteAllServicesForProject:'true' recommended: false, retains Key Vault as a safety net (secrets, CMK keys, RBAC). otherwise: true, also deletes the project Key Vault. |
diagnosticSettingLevel |
DIAGNOSTIC_SETTING_LEVEL |
O | Y: "gold"J.dev: "gold" |
Diagnostics level otherwise: silver or bronze for less verbose (lower cost) logging. |
maxRetryAttempts |
MAX_RETRY_ATTEMPTS |
O | Y: "2"J.dev: "2" |
Max total retry attempts keep-as-is: Total attempts (1 original + N retries). Valid values: 1, 2, or 3. |
policyExemptionAssignmentIds |
POLICY_EXEMPTION_ASSIGNMENT_IDS |
O | Y: "[]"J.dev: "[]" |
JSON array of policy assignment IDs (deployIfNotExists or auditIfNotExists) to exempt on the VNet RG otherwise: e.g. '["/subscriptions/ |
policyExemptionDefinitionReferenceIds |
POLICY_EXEMPTION_DEFINITION_REFERENCE_IDS |
O | Y: "[]"J.dev: "[]" |
JSON array of policyDefinitionReferenceIds within an initiative to narrow the exemption keep-as-is: Leave empty to exempt the full assignment. |
retryMinutes |
RETRY_MINUTES |
O | Y: "5"J.dev: "5" |
Retry wait (minutes) 1st attempt keep-as-is: Minutes between 1st and 2nd retry. |
retryMinutesExtended |
RETRY_MINUTES_EXTENDED |
O | Y: "15"J.dev: "15" |
Retry wait (minutes) 2nd attempt keep-as-is: Minutes between 2nd and 3rd retry. |
selfHostedRunnerLabel |
SELF_HOSTED_RUNNER_LABEL |
O | Y: "aifactory-admin-vm"J.dev: "aifactory-admin-vm" |
GitHub self-hosted runner label |
useSelfHostedBuildAgent |
USE_SELF_HOSTED_BUILD_AGENT |
O | Y: "false"J.dev: "false" |
Use a self-hosted build agent/runner keep-as-is: ADO uses adminVMBuildAgentPool/adminVMBuildAgentName; GHA uses selfHostedRunnerLabel. |
Per-environment SKUs and compute sizing¶
| YAML / JSON key | GHA binding(s) | M/C/O | Source defaults | Description / conditions |
|---|---|---|---|---|
adminVMSize |
ADMIN_VM_SIZE |
O | Y: "Standard_D2s_v5"J.dev: absent |
Admin VM size keep-as-is: Override when the regional SKU is unavailable. |
admin_aks_gpu_sku_dev_override |
ADMIN_AKS_GPU_SKU_DEV_OVERRIDE |
O | Y: "Standard_D4s_v5"J.dev: "Standard_D4s_v5" |
AKS system node VM SKU for DEV ensure: use an AKS-supported system-pool SKU; configure GPU workloads in a separate user pool. |
admin_aks_gpu_sku_test_prod_override |
ADMIN_AKS_GPU_SKU_TEST_PROD_OVERRIDE |
O | Y: "Standard_DS13-2_v2"J.dev: "Standard_DS13-2_v2" |
AKS node VM SKU for TEST/PROD |
admin_aks_nodes_dev_override |
ADMIN_AKS_NODES_DEV_OVERRIDE |
O | Y: 2J.dev: 2 |
AKS system node count for DEV |
admin_aks_nodes_testProd_override |
ADMIN_AKS_NODES_TEST_PROD_OVERRIDE |
O | Y: 3J.dev: 3 |
AKS node count for TEST/PROD |
admin_aks_version_override |
ADMIN_AKS_VERSION_OVERRIDE |
O | Y: "1.35.7"J.dev: "1.35.7" |
AKS Kubernetes version ensure: version has standard support in your region. |
admin_aml_cluster_maxNodes_dev_override |
ADMIN_AML_CLUSTER_MAX_NODES_DEV_OVERRIDE |
O | Y: 3J.dev: 3 |
AML cluster max nodes for DEV |
admin_aml_cluster_maxNodes_testProd_override |
ADMIN_AML_CLUSTER_MAX_NODES_TEST_PROD_OVERRIDE |
O | Y: 5J.dev: 5 |
AML cluster max nodes for TEST/PROD |
admin_aml_cluster_sku_dev_override |
ADMIN_AML_CLUSTER_SKU_DEV_OVERRIDE |
O | Y: "Standard_DS3_v2"J.dev: "Standard_DS3_v2" |
AML cluster VM SKU for DEV |
admin_aml_cluster_sku_testProd_override |
ADMIN_AML_CLUSTER_SKU_TEST_PROD_OVERRIDE |
O | Y: "Standard_D13_v2"J.dev: "Standard_D13_v2" |
AML cluster VM SKU for TEST/PROD |
admin_aml_computeInstance_dev_sku_override |
ADMIN_AML_COMPUTE_INSTANCE_DEV_SKU_OVERRIDE |
O | Y: "Standard_DS11_v2"J.dev: "Standard_DS11_v2" |
AML compute instance SKU for DEV |
admin_aml_computeInstance_testProd_sku_override |
ADMIN_AML_COMPUTE_INSTANCE_TEST_PROD_SKU_OVERRIDE |
O | Y: "Standard_ND96amsr_A100_v4"J.dev: "Standard_ND96amsr_A100_v4" |
AML compute instance SKU for TEST/PROD otherwise: change to a lower-cost SKU to save cost. |
aksAzureFirewallPrivateIp |
AKS_AZURE_FIREWALL_PRIVATE_IP |
C | Y: ""J.dev: "" |
AKS Azure Firewall private IP mandatory: if aksOutboundType:'userDefinedRouting' ensure: IP within the Azure Firewall subnet range. |
aksEnablePrivateCluster |
AKS_ENABLE_PRIVATE_CLUSTER |
O | Y: "true"J.dev: "true" |
Enable private AKS cluster otherwise: false for public access. |
aksOutboundType |
AKS_OUTBOUND_TYPE |
O | Y: "loadBalancer"J.dev: "loadBalancer" |
AKS outbound traffic type otherwise: userDefinedRouting, if you have Azure Firewall and UDR configured. |
aksPrivateDNSZone |
AKS_PRIVATE_DNS_ZONE |
O | Y: "system"J.dev: "system" |
AKS private DNS zone otherwise: "none" or full resource ID of a private DNS zone. |
aksSkuName |
AKS_SKU_NAME |
O | Y: "Base"J.dev: "Base" |
AKS SKU name otherwise: "Standard" for production workloads. |
skuAISearchDev |
ADMIN_AISEARCH_TIER, SKU_AISEARCH_DEV |
O | Y: "basic"J.dev: "basic" |
AI Search SKU Dev ['free','basic','standard','standard2','standard3','storage_optimized_l1','storage_optimized_l2'] ('free' not allowed with private endpoints) |
skuAISearchDevArray |
SKU_AI_SEARCH_DEV_ARRAY |
O | Y: "[\"basic\",\"standard\",\"standard2\"]"J.dev: ["basic","standard","standard2"] |
Sku aisearch dev array. |
skuAISearchStageProd |
ADMIN_AISEARCH_TIER, SKU_AISEARCH_STAGEPROD |
O | Y: "standard"J.dev: "standard" |
AI Search SKU Stage/Prod |
skuAISearchStageProdArray |
SKU_AI_SEARCH_STAGE_PROD_ARRAY |
O | Y: "[\"basic\",\"standard\",\"standard2\"]"J.dev: ["basic","standard","standard2"] |
Sku aisearch stage prod array. |
skuAIServicesDev |
SKU_AISERVICES_DEV |
O | Y: "S0"J.dev: "S0" |
Azure AI Services (multi-service account) SKU Dev |
skuAIServicesStageProd |
SKU_AISERVICES_STAGEPROD |
O | Y: "S0"J.dev: "S0" |
Azure AI Services (multi-service account) SKU Stage/Prod |
skuAksDev |
SKU_AKS_DEV |
O | Y: "Standard_D4s_v5"J.dev: "Standard_D4s_v5" |
AKS dev node VM size keep-as-is: empty=template default Standard_B4ms. |
skuAksStageProd |
SKU_AKS_STAGEPROD |
O | Y: ""J.dev: "" |
AKS test/prod node VM size keep-as-is: empty=template default Standard_DS13-2_v2. |
skuArrayAISearchDev |
SKU_ARRAY_AISEARCH_DEV |
O | Y: "basic,standard,standard2"J.dev: "basic,standard,standard2" |
Ordered fallback SKUs; the configured Dev SKU is attempted first. |
skuArrayAISearchStageProd |
SKU_ARRAY_AISEARCH_STAGEPROD |
O | Y: "basic,standard,standard2"J.dev: "basic,standard,standard2" |
Ordered fallback SKUs; the configured Stage/Prod SKU is attempted first. |
skuArrayContainerAppsDev |
SKU_ARRAY_CONTAINER_APPS_DEV |
O | Y: "Consumption,D4,D8"J.dev: "Consumption,D4,D8" |
Ordered capacity fallback profiles; D4/D8 use dedicated pricing. |
skuArrayContainerAppsStageProd |
SKU_ARRAY_CONTAINER_APPS_STAGEPROD |
O | Y: "Consumption,D4,D8"J.dev: "Consumption,D4,D8" |
Ordered capacity fallback profiles; D4/D8 use dedicated pricing. |
skuArrayPostgreSQLDev |
SKU_ARRAY_POSTGRESQL_DEV |
O | Y: "Standard_B1ms,Standard_B2s,Standard_B2ms"J.dev: "Standard_B1ms,Standard_B2s,Standard_B2ms" |
Ordered capacity fallback SKUs; the selected Dev SKU is attempted first. |
skuArrayPostgreSQLStageProd |
SKU_ARRAY_POSTGRESQL_STAGEPROD |
O | Y: "Standard_B1ms,Standard_B2s,Standard_B2ms"J.dev: "Standard_B1ms,Standard_B2s,Standard_B2ms" |
Ordered capacity fallback SKUs; the selected Stage/Prod SKU is attempted first. |
skuAzureMLDev |
SKU_AZUREML_DEV |
O | Y: "basic"J.dev: "basic" |
Azure ML workspace SKU Dev ['basic','standard'] |
skuAzureMLStageProd |
SKU_AZUREML_STAGEPROD |
O | Y: "basic"J.dev: "basic" |
Azure ML workspace SKU Stage/Prod |
skuBingDev |
SKU_BING_DEV |
O | Y: "G2"J.dev: "G2" |
Bing Custom Search SKU Dev ['G2'] |
skuBingStageProd |
SKU_BING_STAGEPROD |
O | Y: "G2"J.dev: "G2" |
Bing Custom Search SKU Stage/Prod |
skuBotServiceDev |
SKU_BOTSERVICE_DEV |
O | Y: "S1"J.dev: "S1" |
Bot Service SKU Dev ['F0','S1'] |
skuBotServiceStageProd |
SKU_BOTSERVICE_STAGEPROD |
O | Y: "S1"J.dev: "S1" |
Bot Service SKU Stage/Prod |
skuContainerAppsDev |
SKU_CONTAINER_APPS_DEV |
O | Y: "Consumption"J.dev: "Consumption" |
Container Apps workload profile Dev ['Consumption','D4','D8'] |
skuContainerAppsStageProd |
SKU_CONTAINER_APPS_STAGEPROD |
O | Y: "Consumption"J.dev: "Consumption" |
Container Apps workload profile Stage/Prod |
skuContentSafetyDev |
SKU_CONTENTSAFETY_DEV |
O | Y: "S0"J.dev: "S0" |
Content Safety SKU Dev |
skuContentSafetyStageProd |
SKU_CONTENTSAFETY_STAGEPROD |
O | Y: "S0"J.dev: "S0" |
Content Safety SKU Stage/Prod |
skuDatabricksDev |
SKU_DATABRICKS_DEV |
O | Y: "premium"J.dev: "premium" |
Databricks SKU Dev ['trial','premium'] |
skuDatabricksStageProd |
SKU_DATABRICKS_STAGEPROD |
O | Y: "premium"J.dev: "premium" |
Databricks SKU Stage/Prod |
skuDocIntelligenceDev |
SKU_DOCINTELLIGENCE_DEV |
O | Y: "S0"J.dev: "S0" |
Document Intelligence SKU Dev |
skuDocIntelligenceStageProd |
SKU_DOCINTELLIGENCE_STAGEPROD |
O | Y: "S0"J.dev: "S0" |
Document Intelligence SKU Stage/Prod |
skuElasticDev |
ELASTIC_SKU, SKU_ELASTIC_DEV |
O | Y: "ess-consumption-2024_Monthly"J.dev: "ess-consumption-2024_Monthly" |
Elastic Cloud SKU Dev |
skuElasticStageProd |
ELASTIC_SKU, SKU_ELASTIC_STAGEPROD |
O | Y: "ess-consumption-2024_Monthly"J.dev: "ess-consumption-2024_Monthly" |
Elastic Cloud SKU Stage/Prod |
skuEventHubsDev |
SKU_EVENTHUBS_DEV |
O | Y: "Basic"J.dev: "Basic" |
Event Hubs tier Dev ['Basic','Standard','Premium'] |
skuEventHubsStageProd |
SKU_EVENTHUBS_STAGEPROD |
O | Y: "Basic"J.dev: "Basic" |
Event Hubs tier Stage/Prod |
skuFunctionDev |
SKU_FUNCTION_DEV |
O | Y: "EP1"J.dev: "EP1" |
Function plan SKU Dev |
skuFunctionStageProd |
SKU_FUNCTION_STAGEPROD |
O | Y: "EP1"J.dev: "EP1" |
Function plan SKU Stage/Prod |
skuLogicAppsDev |
SKU_LOGICAPPS_DEV |
O | Y: "WS1"J.dev: "WS1" |
Logic Apps plan SKU Dev ['WS1','WS2','WS3','EP1','EP2','EP3','P1V2','P2V2','P3V2','P1V3','P2V3','P3V3'] |
skuLogicAppsStageProd |
SKU_LOGICAPPS_STAGEPROD |
O | Y: "WS1"J.dev: "WS1" |
Logic Apps plan SKU Stage/Prod |
skuOpenAIDev |
SKU_OPENAI_DEV |
O | Y: "S0"J.dev: "S0" |
Azure OpenAI SKU Dev |
skuOpenAIStageProd |
SKU_OPENAI_STAGEPROD |
O | Y: "S0"J.dev: "S0" |
Azure OpenAI SKU Stage/Prod |
skuPostgreSQLDev |
SKU_POSTGRESQL_DEV |
O | Y: "Standard_B1ms"J.dev: "Standard_B1ms" |
PostgreSQL compute SKU Dev |
skuPostgreSQLStageProd |
SKU_POSTGRESQL_STAGEPROD |
O | Y: "Standard_B1ms"J.dev: "Standard_B1ms" |
PostgreSQL compute SKU Stage/Prod |
skuRedisDev |
SKU_REDIS_DEV |
O | Y: "Standard"J.dev: "Standard" |
Redis SKU Dev ['Basic','Standard','Premium'] |
skuRedisStageProd |
SKU_REDIS_STAGEPROD |
O | Y: "Standard"J.dev: "Standard" |
Redis SKU Stage/Prod |
skuSQLDatabaseDev |
SKU_SQLDATABASE_DEV |
O | Y: "S0"J.dev: "S0" |
Azure SQL DB (DTU model) SKU Dev |
skuSQLDatabaseStageProd |
SKU_SQLDATABASE_STAGEPROD |
O | Y: "S0"J.dev: "S0" |
Azure SQL DB (DTU model) SKU Stage/Prod |
skuSpeechDev |
SKU_SPEECH_DEV |
O | Y: "S0"J.dev: "S0" |
Azure AI Speech SKU Dev |
skuSpeechStageProd |
SKU_SPEECH_STAGEPROD |
O | Y: "S0"J.dev: "S0" |
Azure AI Speech SKU Stage/Prod |
skuStorageAccountDev |
SKU_STORAGEACCOUNT_DEV |
O | Y: "Standard_LRS"J.dev: "Standard_LRS" |
Project Storage Account SKU Dev ['Standard_LRS','Standard_GRS','Standard_RAGRS','Standard_ZRS','Premium_LRS','Premium_ZRS','Standard_GZRS','Standard_RAGZRS'] |
skuStorageAccountStageProd |
SKU_STORAGEACCOUNT_STAGEPROD |
O | Y: "Standard_LRS"J.dev: "Standard_LRS" |
Project Storage Account SKU Stage/Prod |
skuTierAksDev |
SKU_TIER_AKS_DEV |
O | Y: "Standard"J.dev: "Standard" |
AKS SKU tier Dev |
skuTierAksStageProd |
SKU_TIER_AKS_STAGEPROD |
O | Y: "Standard"J.dev: "Standard" |
AKS SKU tier Stage/Prod |
skuTierAzureMLDev |
SKU_TIER_AZUREML_DEV |
O | Y: "basic"J.dev: "basic" |
Azure ML workspace tier Dev |
skuTierAzureMLStageProd |
SKU_TIER_AZUREML_STAGEPROD |
O | Y: "basic"J.dev: "basic" |
Azure ML workspace tier Stage/Prod |
skuTierFunctionDev |
SKU_TIER_FUNCTION_DEV |
O | Y: "ElasticPremium"J.dev: "ElasticPremium" |
Function plan tier Dev |
skuTierFunctionStageProd |
SKU_TIER_FUNCTION_STAGEPROD |
O | Y: "ElasticPremium"J.dev: "ElasticPremium" |
Function plan tier Stage/Prod |
skuTierPostgreSQLDev |
SKU_TIER_POSTGRESQL_DEV |
O | Y: "Burstable"J.dev: "Burstable" |
PostgreSQL tier Dev ['Burstable','GeneralPurpose','MemoryOptimized'] |
skuTierPostgreSQLStageProd |
SKU_TIER_POSTGRESQL_STAGEPROD |
O | Y: "Burstable"J.dev: "Burstable" |
PostgreSQL tier Stage/Prod |
skuTierSQLDatabaseDev |
SKU_TIER_SQLDATABASE_DEV |
O | Y: "Standard"J.dev: "Standard" |
Azure SQL DB tier Dev ['Basic','Standard','Premium'] |
skuTierSQLDatabaseStageProd |
SKU_TIER_SQLDATABASE_STAGEPROD |
O | Y: "Standard"J.dev: "Standard" |
Azure SQL DB tier Stage/Prod |
skuTierWebAppDev |
SKU_TIER_WEBAPP_DEV |
O | Y: "PremiumV3"J.dev: "PremiumV3" |
Web App plan tier Dev |
skuTierWebAppStageProd |
SKU_TIER_WEBAPP_STAGEPROD |
O | Y: "PremiumV3"J.dev: "PremiumV3" |
Web App plan tier Stage/Prod |
skuVisionDev |
SKU_VISION_DEV |
O | Y: "S1"J.dev: "S1" |
Azure AI Vision SKU Dev |
skuVisionStageProd |
SKU_VISION_STAGEPROD |
O | Y: "S1"J.dev: "S1" |
Azure AI Vision SKU Stage/Prod |
skuWebAppDev |
SKU_WEBAPP_DEV |
O | Y: "P1v3"J.dev: "P1v3" |
Web App plan SKU Dev |
skuWebAppStageProd |
SKU_WEBAPP_STAGEPROD |
O | Y: "P1v3"J.dev: "P1v3" |
Web App plan SKU Stage/Prod |
Identity, access and encryption¶
| YAML / JSON key | GHA binding(s) | M/C/O | Source defaults | Description / conditions |
|---|---|---|---|---|
apimGatewayManagedIdentityPrincipalId |
APIM_GATEWAY_MANAGED_IDENTITY_PRINCIPAL_ID |
C | Y: ""J.dev: "" |
APIM system-assigned managed identity object ID. Required when assigning the OpenAI user role to the APIM managed identity. |
azureDevOpsTenantId |
No verified binding | M | Y: "<todo>_AzureDevOpsTenantId"J.dev: "<todo>_AzureDevOpsTenantId" |
Microsoft Entra tenant ID connected to the Azure DevOps organization. This can differ from tenantId used for Azure deployments. mandatory: Microsoft Entra tenant ID connected to the Azure DevOps organization. This can differ from tenantId used for Azure deployments. |
azure_machinelearning_sp_oid |
AZURE_MACHINELEARNING_SP_OID, TENANT_AZUREML_OID |
C | Y: "<todo>_ObjectID"J.dev: "<todo>_ObjectID" |
Azure ML service principal OID mandatory: Azure ML service principal OID ensure: find in Entra ID as "Azure Machine Learning" app (AppId: 0736f41a-0425-4b46-bdb5-1563eff02385). otherwise: optional if enableAIFoundry:'false'. |
cmk |
CMK |
O | Y: "false"J.dev: "false" |
Customer Managed Key encryption otherwise: true, enable CMK for Key Vault, Storage accounts, etc. |
cmkDisableForAISearch |
CMK_DISABLE_FOR_AI_SEARCH |
O | Y: "true"J.dev: "true" |
Disable CMK for AI Search otherwise: true, disables CMK encryption for Azure AI Search even when cmk:'true'. Reason: Foundry runtime creates indexes without providing CMK info, causing failures. |
cmkDisableForFoundry |
CMK_DISABLE_FOR_FOUNDRY |
O | Y: "true"J.dev: "true" |
Disable CMK for AI Foundry otherwise: true, disables CMK encryption for AI Foundry account even when cmk:'true'. Reason: Foundry does not respect AI Search CMK contract at runtime. |
cmkKeyName |
CMK_KEY_NAME |
C | Y: "<todo>_aifactory-cmk-key"J.dev: "<todo>_aifactory-cmk-key" |
CMK key name in seeding KV mandatory: if cmk:'true' ensure: key name in your Seeding Keyvault to use for CMK encryption. |
cmkKeyVersion |
CMK_KEY_VERSION |
O | Y: ""J.dev: "" |
CMK key version otherwise: pin to a specific GUID version string. |
commonServicePrincipleOIDKey |
COMMON_SERVICE_PRINCIPLE_OID_KEY |
C | Y: "<optional>esml-common-sp-oid"J.dev: "<optional>esml-common-sp-oid" |
Seeding KV secret name for common SP OID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
debug_disable_100_rbac_security |
DEBUG_DISABLE_100_RBAC_SECURITY |
O | Y: "false"J.dev: "false" |
Skip RBAC and security step otherwise: true, skip RBAC and security step for all services (steps 61-99). |
dev_seeding_kv_service_connection |
No verified binding | M | Y: "<todo>_ado_service_connection"J.dev: "<todo>_ado_service_connection" |
ADO service connection for DEV seeding KV mandatory: ADO service connection for DEV seeding KV ensure: name matches your service connection for the DEV seeding KV subscription. otherwise: can be same as dev_service_connection. |
dev_service_connection |
No verified binding | M | Y: "<todo>_ado_service_connection"J.dev: "<todo>_ado_service_connection" |
ADO service connection for DEV mandatory: ADO service connection for DEV ensure: name matches your Azure DevOps service connection for the DEV subscription. |
disableContributorAccessForUsers |
DISABLE_CONTRIBUTOR_ACCESS_FORUSERS, DISABLE_CONTRIBUTOR_ACCESS_FOR_USERS (not in .env template) |
O | Y: "false"J.dev: "false" |
Disable Contributor for project users recommended: false, enables users to create artifacts (managed online endpoints etc). otherwise: true, restrict Contributor access. |
disableLocalAuth |
DISABLE_LOCAL_AUTH |
O | Y: "true"J.dev: "true" |
Disable local API key ("admin account") auth on Cognitive/AI Services & Foundry, AAD-only recommended: true, disables key auth (many orgs forbid keys). otherwise: false, allow local API keys. |
disableRBACAdminOnRGForUsers |
DISABLE_RBAC_ADMIN_ON_RG_FORUSERS, DISABLE_RBAC_ADMIN_ON_RG_FOR_USERS (not in .env template) |
O | Y: "true"J.dev: "true" |
Disable RBAC Admin on RG for project users recommended: true, restricts users from assigning RBAC at resource group scope. |
groups_coreteam_members |
GROUPS_CORETEAM_MEMBERS |
C | Y: "<aif001sdc_coreteam_admin_p080>,<aif001sdc_coreteam_dataops_p081>,<aif001sdc_coreteam_dataops_fabric_p082>"J.dev: "<aif001sdc_coreteam_admin_p080>,<aif001sdc_coreteam_dataops_p081>,<aif001sdc_coreteam_dataops_fabric_p082>" |
Core team AD group ObjectIDs mandatory: if use_ad_groups:'true' |
groups_project_members_esml |
GROUPS_PROJECT_MEMBERS_ESML |
C | Y: "<aif001sdc_prj001_team_lead_p001>,<aif001sdc_prj001_team_member_ds_p002>,<aif001sdc_prj001_team_member_fend_p003>"J.dev: "<aif001sdc_prj001_team_lead_p001>,<aif001sdc_prj001_team_member_ds_p002>,<aif001sdc_prj001_team_member_fend_p003>" |
ESML project team AD group ObjectIDs mandatory: if use_ad_groups:'true' |
groups_project_members_genai_1 |
GROUPS_PROJECT_MEMBERS_GENAI_1 |
C | Y: "<aif001sdc_prj002_team_lead_p011>,<aif001sdc_prj002_genai_team_member_aifoundry_p012>,<aif002sdc_prj001_genai_team_member_agentic_p013>,<aif001sdc_prj001_genai_team_member_dataops_p014>,<aif001sdc_prj001_team_member_fend_p015>"J.dev: "<aif001sdc_prj002_team_lead_p011>,<aif001sdc_prj002_genai_team_member_aifoundry_p012>,<aif002sdc_prj001_genai_team_member_agentic_p013>,<aif001sdc_prj001_genai_team_member_dataops_p014>,<aif001sdc_prj001_team_member_fend_p015>" |
GenAI-1 project team AD group ObjectIDs mandatory: if use_ad_groups:'true' |
inputCommonSPIDKey |
INPUT_COMMON_SPID_KEY |
C | Y: "<optional>esml-common-sp-id"J.dev: "<optional>esml-common-sp-id" |
Seeding KV secret name for common SP App ID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
inputCommonSPSecretKey |
INPUT_COMMON_SP_SECRET_KEY |
C | Y: "<optional>esml-common-sp-secret"J.dev: "<optional>esml-common-sp-secret" |
Seeding KV secret name for common SP secret ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
personas_core_team |
PERSONAS_CORE_TEAM |
O | Y: "p080_coreteam_it_admin,coreteam_dataops,p081_coreteam_dataops_fabric, p103_coreteam_team_process_ops"J.dev: "p080_coreteam_it_admin,coreteam_dataops,p081_coreteam_dataops_fabric, p103_coreteam_team_process_ops" |
Core team personas keep-as-is: Mapped to group_coreteam_members. |
personas_project_esml |
PERSONAS_PROJECT_ESML |
O | Y: "p001_esml_team_lead,p002_esml_team_member_datascientist,p003_esml_team_member_front_end,p101_esml_team_process_ops"J.dev: "p001_esml_team_lead,p002_esml_team_member_datascientist,p003_esml_team_member_front_end,p101_esml_team_process_ops" |
ESML project personas keep-as-is: Mapped to groups_project_members_esml and PROJECT_TYPE=esml. |
personas_project_genai_1 |
PERSONAS_PROJECT_GENAI_1 |
O | Y: "p011_genai_team_lead,p012_genai_team_member_aifoundry,p013_genai_team_member_agentic,p014_genai_team_member_dataops,p015_genai_team_member_frontend,p102_esml_team_process_ops"J.dev: "p011_genai_team_lead,p012_genai_team_member_aifoundry,p013_genai_team_member_agentic,p014_genai_team_member_dataops,p015_genai_team_member_frontend,p102_esml_team_process_ops" |
GenAI-1 project personas keep-as-is: Mapped to groups_project_members_genai_1 and PROJECT_TYPE=genai-1. |
prod_seeding_kv_service_connection |
No verified binding | C | Y: "<todo>_ado_service_connection"J.dev: "<todo>_ado_service_connection" |
ADO service connection for PROD seeding KV mandatory: ADO service connection for PROD seeding KV ensure: name matches your service connection for the PROD seeding KV subscription. otherwise: can be same as prod_service_connection. Required when deploying that environment. |
prod_service_connection |
No verified binding | C | Y: "<todo>_ado_service_connection"J.dev: "<todo>_ado_service_connection" |
ADO service connection for PROD mandatory: ADO service connection for PROD ensure: name matches your Azure DevOps service connection for the PROD subscription. Required when deploying that environment. |
project_service_principal_AppID_seeding_kv_name |
PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID |
C | Y: "<optional>esml-project001-sp-id"J.dev: "<optional>esml-project001-sp-id" |
Project SP App ID secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
project_service_principal_OID_seeding_kv_name |
PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_OID |
C | Y: "<optional>esml-project001-sp-oid"J.dev: "<optional>esml-project001-sp-oid" |
Project SP OID secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
project_service_principal_Secret_seeding_kv_name |
PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_S |
C | Y: "<optional>esml-project001-sp-secret"J.dev: "<optional>esml-project001-sp-secret" |
Project SP secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
technical_admins_ad_object_id |
PROJECT_MEMBERS |
M | Y: "<todo>_EntraID_ObjectID"J.dev: "<todo>_EntraID_ObjectID" |
Project team Entra ID object ID(s) mandatory: Project team Entra ID object ID(s) ensure: comma-separated ObjectIDs of users or AD groups for the project team. |
technical_admins_email |
PROJECT_MEMBERS_EMAILS |
O | Y: "<todo>_email_or_securitygroup_name"J.dev: "<todo>_email_or_securitygroup_name" |
Project team contact email or group name recommended: set for better project tracking. |
tenantId |
TENANT_ID |
M | Y: "<todo>_TenantId"J.dev: "<todo>_TenantId" |
Azure tenant ID mandatory: Azure tenant ID ensure: find in Azure Portal > Entra ID > Overview (Directory ID). |
test_seeding_kv_service_connection |
No verified binding | C | Y: "<todo>_ado_service_connection"J.dev: "<todo>_ado_service_connection" |
ADO service connection for STAGE seeding KV mandatory: ADO service connection for STAGE seeding KV ensure: name matches your service connection for the STAGE seeding KV subscription. otherwise: can be same as test_service_connection. Required when deploying that environment. |
test_service_connection |
No verified binding | C | Y: "<todo>_ado_service_connection"J.dev: "<todo>_ado_service_connection" |
ADO service connection for STAGE mandatory: ADO service connection for STAGE ensure: name matches your Azure DevOps service connection for the STAGE subscription. Required when deploying that environment. |
updateKeyvaultRbac |
UPDATE_KEYVAULT_RBAC |
O | Y: "false"J.dev: "false" |
Update Key Vault RBAC otherwise: true, re-run to update RBAC properties. |
use_ad_groups |
USE_AD_GROUPS |
O | Y: "true"J.dev: "true" |
Use AD groups for project members otherwise: false, use individual ObjectIDs and simple mode Personas. |
Models and deployments¶
| YAML / JSON key | GHA binding(s) | M/C/O | Source defaults | Description / conditions |
|---|---|---|---|---|
default_embedding_capacity |
DEFAULT_EMBEDDING_CAPACITY |
O | Y: 25J.dev: 25 |
Embedding model TPM capacity (K) keep-as-is: 25 = 25K tokens per minute. |
default_gpt_4o_version |
DEFAULT_GPT_4O_VERSION |
O | Y: "2024-11-20"J.dev: "2024-11-20" |
gpt-4o version otherwise: "2024-08-06". |
default_gpt_54_mini_version |
DEFAULT_GPT_54_MINI_VERSION |
O | Y: "2026-03-17"J.dev: "2026-03-17" |
Version for the separately named GPT-5.4-mini deployment toggle. |
default_gpt_capacity |
DEFAULT_GPT_CAPACITY |
O | Y: 40J.dev: 40 |
GPT model TPM capacity (K) keep-as-is: 40 = 40K tokens per minute. |
default_model_sku |
DEFAULT_MODEL_SKU |
O | Y: "DataZoneStandard"J.dev: "DataZoneStandard" |
Default model deployment SKU keep-as-is: Keep inference within the selected data zone; confirm model/SKU availability and quota. |
deployModel_gpt_4o |
DEPLOY_MODEL_GPT_4O |
O | Y: "false"J.dev: "false" |
Deploy gpt-4o recommended: for general-purpose AI Foundry scenarios. |
deployModel_gpt_54_mini |
DEPLOY_MODEL_GPT_54_MINI |
O | Y: "false"J.dev: "false" |
Enable the separately named GPT-5.4-mini deployment toggle; inspect its workflow binding alongside deployModel_gpt_X. |
deployModel_gpt_X |
DEPLOY_MODEL_GPT_X |
O | Y: "true"J.dev: "true" |
Deploy custom GPT-X model otherwise: true, deploy the model defined in modelGPTXName. |
deployModel_text_embedding_3_large |
DEPLOY_MODEL_TEXT_EMBEDDING_3_LARGE |
O | Y: "true"J.dev: "true" |
Deploy text-embedding-3-large recommended: for production RAG scenarios. |
deployModel_text_embedding_3_small |
DEPLOY_MODEL_TEXT_EMBEDDING_3_SMALL |
O | Y: "false"J.dev: "false" |
Deploy text-embedding-3-small recommended: for cost-optimized scenarios. |
deployModel_text_embedding_ada_002 |
DEPLOY_MODEL_TEXT_EMBEDDING_ADA_002 |
O | Y: "false"J.dev: "false" |
Deploy text-embedding-ada-002 |
modelGPTXCapacity |
MODEL_GPTX_CAPACITY |
O | Y: 30J.dev: 30 |
GPT-X TPM capacity (K) keep-as-is: 30 = 30K tokens per minute. |
modelGPTXName |
MODEL_GPTX_NAME |
O | Y: "gpt-5.4-mini"J.dev: "gpt-5.4-mini" |
GPT-X model name ensure: model is available in your Azure region with sufficient quota. |
modelGPTXSku |
MODEL_GPTX_SKU |
O | Y: "DataZoneStandard"J.dev: "DataZoneStandard" |
GPT-X deployment SKU keep-as-is: Keep inference within the selected data zone; confirm model/SKU availability and quota. |
modelGPTXVersion |
MODEL_GPTX_VERSION |
O | Y: "2026-03-17"J.dev: "2026-03-17" |
GPT-X model version ensure: update the version when selecting a different model. |
GitHub Actions .env reference¶
Every unique assignment is included, including orchestrator-only and compatibility names. Values are decoded literals, not expansions; these are template values, not necessarily the workflow's effective fallback. No verified counterpart means no mapping was found in the inspected shared bindings, not proof that a setting is unused.
GHA: Factory, project, naming and orchestration¶
| Exact environment key | YAML / JSON counterpart(s) | M/C/O | Template value | Description / conditions |
|---|---|---|---|---|
ACA_W_REGISTRY_IMAGE |
aca_w_registry_image |
O | "mcr.microsoft.com/azuredocs/containerapps-helloworld:latest" |
Container Apps default registry image |
ADMIN_AISEARCH_TIER |
admin_aiSearchTier, skuAISearchDev, skuAISearchStageProd |
M | "basic" |
AI Search SKU tier mandatory: AI Search SKU tier ensure: 'free' is not allowed when using private endpoints. ['free','basic','standard','standard2','standard3','storage_optimized_l1','storage_optimized_l2'] |
ADMIN_AI_SEARCH_TIER |
No verified counterpart | M | "basic" |
AI Search SKU tier mandatory: AI Search SKU tier ensure: 'free' is not allowed when using private endpoints. ['free','basic','standard','standard2','standard3','storage_optimized_l1','storage_optimized_l2'] |
ADMIN_COMMON_RESOURCE_SUFFIX |
admin_commonResourceSuffix |
O | "-001" |
Common resources suffix otherwise: change to reprovision new services in the same common RG while keeping old ones. |
ADMIN_HYBRID_BENEFIT |
admin_hybridBenefit |
O | "true" |
Azure Hybrid Benefit for VMs otherwise: true, if you have eligible Windows licenses with Software Assurance (pay-as-you-go avoided). |
ADMIN_IP_FW |
admin_ip_fw |
O | "" |
Admin IP for firewall rules keep-as-is: Used by GHA runner to whitelist its own IP. |
ADMIN_PRJ_RESOURCE_SUFFIX |
admin_prjResourceSuffix |
O | "-001" |
Project resources suffix otherwise: change to reprovision new services in the same project RG while keeping old ones. |
ADMIN_SEMANTIC_SEARCH_TIER |
admin_semanticSearchTier |
M | "free" |
Semantic search tier mandatory: Semantic search tier |
ADMIN_USERNAME |
adminUsername |
O | "esmladmin" |
VM admin username |
AIFACTORY_BRANCH_CHOSEN |
aifactory_branch_chosen |
O | "release/v1.24" |
Submodule release branch |
AIFACTORY_COMMON_ONLY_DEV_ENVIRONMENT |
No verified counterpart | O | "true" |
Create common-DEV environment only otherwise: false, creates Dev, Stage, Prod environments in Azure. |
AIFACTORY_DASHBOARD_URL |
aifactory-dash-01 |
O | "" |
Existing Azure Portal AI Factory dashboard URL; never deploys a dashboard. |
AIFACTORY_LOCATION |
admin_location |
M | "eastus2" |
Azure region mandatory: Azure region |
AIFACTORY_LOCATION_SHORT |
admin_locationSuffix |
M | "eus2" |
Region short name mandatory: Region short name |
AIFACTORY_PREFIX |
admin_aifactoryPrefixRG |
O | "acme-ai" |
AI Factory resource group prefix keep-as-is: Max 6 chars. otherwise: set your company prefix, e.g. 'acme-ai-', 'contoso-'. |
AIFACTORY_SALT |
aifactory_salt |
O | "<5>" |
AI Factory deterministic salt (5 chars) ensure: read from COMMON RG resource names, e.g. the 'a4c2b' in 'adf-cmn-weu-dev-a4c2b-001'. Used in project resource naming. |
AIFACTORY_SALT_RANDOM |
aifactory_salt_random |
O | "<10>" |
Random salt placeholder (10 chars) keep-as-is: Do not change. Placeholder only. |
AIFACTORY_SEEDING_KEYVAULT_NAME |
dev_admin_bicep_kv_fw, prod_admin_bicep_kv_fw, test_admin_bicep_kv_fw |
M | "kv-seeding-sdc-001<todo>" |
DEV seeding KV name mandatory: DEV seeding KV name ensure: Key Vault name storing secrets mapped to PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID. |
AIFACTORY_SEEDING_KEYVAULT_RG |
dev_admin_bicep_kv_fw_rg, prod_admin_bicep_kv_fw_rg, test_admin_bicep_kv_fw_rg |
M | "rg-seeding-sdc-001<todo>" |
DEV seeding KV resource group mandatory: DEV seeding KV resource group ensure: resource group where the DEV seeding Key Vault resides. |
AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID |
dev_admin_bicep_input_keyvault_subscription, prod_admin_bicep_input_keyvault_subscription, test_admin_bicep_input_keyvault_subscription |
M | "<todo>" |
DEV seeding KV subscription ID mandatory: DEV seeding KV subscription ID ensure: subscription where the DEV seeding Key Vault resides. |
AIFACTORY_SUFFIX |
admin_aifactorySuffixRG |
M | "-001" |
AI Factory scaleset suffix mandatory: AI Factory scaleset suffix keep-as-is: For 1st scaleset. otherwise: increment to '-002', '-003' for additional scalesets. |
AIFACTORY_VERSION_MAJOR |
aifactory_version_major |
O | "1" |
AI Factory major version keep-as-is: Used to determine which bicep files to use. |
AIFACTORY_VERSION_MINOR |
aifactory_version_minor |
O | "24" |
AI Factory minor version keep-as-is: 2025-09-20: 24 = release/v1.24 |
AISEARCH_RETRY_CAPCITY_ARRAY |
aisearchRetryCapcityArray |
O | "true" |
Validate every candidate quota and retry only recognized capacity failures after four minutes. |
AISEARCH_SEMANTIC_TIER |
admin_semanticSearchTier |
M | "free" |
Semantic search tier mandatory: Semantic search tier |
AI_SEARCH_LOCATION |
aiSearchLocation |
O | "" |
AI Search region override. Empty keeps AIFACTORY_LOCATION. |
AML_STUDIO_UI_PRIVATE |
AMLStudioUIPrivate |
O | "true" |
AML Studio UI private access otherwise: false, only data plane is private; control plane is public. |
ASE_SKU |
aseSku |
O | "IsolatedV2" |
App Service Environment SKU |
ASE_SKU_CODE |
aseSkuCode |
O | "I1v2" |
ASE SKU code |
ASE_SKU_WORKERS |
aseSkuWorkers |
O | "1" |
ASE number of workers |
AZURE_CLIENT_ID |
AZURE_CLIENT_ID |
O | "" |
Preferred credentialless deployment identity: client ID of a federated app or user-assigned managed identity. When set, workflows use OIDC instead of AZURE_CREDENTIALS. |
BASTION_CUSTOM_NAME |
bastion_custom_name |
O | "" |
Bastion name override for common RG RBAC keep-as-is: Empty uses the standard Bastion naming convention. |
BASTION_SUBSCRIPTION_RESOURCE_GROUP |
bastion_subscription_resource_group |
O | "" |
Bastion resource group override for common RG RBAC keep-as-is: Empty uses the common resource group. |
BING_CUSTOM_SEARCH_SKU |
bingCustomSearchSku |
O | "G2" |
Bing Custom Search SKU |
COMMON_RESOURCE_GROUP_PARAM |
commonResourceGroup_param |
O | "" |
BYO common resource group name otherwise: provide a custom name for the common resource group. |
CONTAINER_APPS_RETRY_CAPACITY_ARRAY |
containerAppsRetryCapacityArray |
O | "true" |
Retry only Container Apps capacity errors, waiting 240 seconds before attempts 2 and 3. |
COSMOS_KIND |
cosmosKind |
O | "GlobalDocumentDB" |
Cosmos DB kind otherwise: MongoDB. |
DATALAKE_NAME_PARAM |
datalakeName_param |
O | "" |
BYO data lake storage account name otherwise: provide a custom storage account name. |
DEV_SUBSCRIPTION_ID |
dev_sub_id |
M | "<todo>" |
DEV subscription ID mandatory: DEV subscription ID |
FUNCTION_RUNTIME |
functionRuntime |
O | "dotnet" |
Functions runtime stack otherwise: python, node, java. |
FUNCTION_VERSION |
functionVersion |
O | "v7.0" |
Functions runtime version |
GITHUB_NEW_REPO |
GITHUB_NEW_REPO |
M | "<todo>/<todo>azure-enterprise-scale-aifactory-001" |
New GitHub repository path mandatory: New GitHub repository path ensure: format: |
GITHUB_NEW_REPO_VISIBILITY |
GITHUB_NEW_REPO_VISIBILITY |
O | "public" |
New repository visibility otherwise: private or internal. |
GITHUB_TEMPLATE_REPO |
GITHUB_TEMPLATE_REPO |
O | "azure/enterprise-scale-aifactory" |
GitHub template repository keep-as-is: Leave as-is if BYO repo. |
GITHUB_USERNAME |
GITHUB_USERNAME |
M | "<todo>" |
GitHub username or org mandatory: GitHub username or org |
GITHUB_USE_SSH |
GITHUB_USE_SSH |
O | "false" |
Use SSH for git operations otherwise: true, use SSH instead of HTTPS. |
KEYVAULT_SOFT_DELETE |
admin_keyvaultSoftDeleteDays |
C | "7" |
Key Vault soft delete days mandatory: if CMK:'true' (purge protection required). otherwise: 90 days recommended; 0 to disable. |
KV_NAME_FROM_COMMON_PARAM |
kvNameFromCOMMON_param |
O | "" |
BYO common Key Vault name otherwise: provide a custom Key Vault name. |
LAKE_CONTAINER_NAME |
lakeContainerName |
O | "lake3" |
Data lake container name |
LAKE_PREFIX |
commonLakeNamePrefixMax8chars |
O | "xxxyyy" |
Data lake storage name prefix keep-as-is: Max 8 characters. |
LOGIC_APP_TYPE |
No verified counterpart | O | "Standard" |
Logic Apps plan type keep-as-is: Consumption is multi-tenant with NO private endpoints/VNet integration - only valid when ENABLE_PUBLIC_ACCESS_WITH_PERIMETER:'true'. Use Standard for private networking. |
MAX_RETRY_ATTEMPTS |
maxRetryAttempts |
O | "2" |
Maximum retry attempts keep-as-is: Valid values: 1, 2, or 3. |
ORG_DEPARTMENT_ID |
org-department-id |
O | "" |
Project organizational department ID keep-as-is: Text, max 128 characters, not necessarily a GUID; identical across environments. No identity or authentication effect. |
ORG_DEPARTMENT_NAME |
org-department-name |
O | "" |
Project organizational department name keep-as-is: Unicode text, max 200 characters; identical across environments, independent of cost center. No factory inheritance or Azure tag writes. |
POSTGRESQL_RETRY_CAPACITY_ARRAY |
postgreSQLRetryCapacityArray |
O | "true" |
Retry only PostgreSQL capacity errors, waiting 240 seconds before attempts 2 and 3. |
POSTGRES_ADMIN_EMAILS |
postGresAdminEmails |
C | "" |
PostgreSQL administrator email(s) mandatory: if ENABLE_POSTGRESQL:'true' ensure: single email address for the PostgreSQL administrator. |
PROD_SUBSCRIPTION_ID |
prod_sub_id |
C | "<todo>" |
PROD subscription ID recommended: separate subscription from DEV. otherwise: can reuse DEV_SUBSCRIPTION_ID. Required when deploying that environment. |
PROJECT_NUMBER |
project_number_000 |
M | "001" |
Project number mandatory: Project number keep-as-is: For 1st project. otherwise: increment to '002', '003', etc. |
PROJECT_PREFIX |
projectPrefix |
O | "esml-" |
Project resource name prefix |
PROJECT_SUFFIX |
projectSuffix |
O | "-rg" |
Project resource name suffix |
PROJECT_TYPE |
admin_projectType |
O | "all" |
Project type keep-as-is: Not used anymore. Leave as is. |
STAGE_SUBSCRIPTION_ID |
test_sub_id |
C | "<todo>" |
STAGE subscription ID recommended: separate subscription from DEV. otherwise: can reuse DEV_SUBSCRIPTION_ID. Required when deploying that environment. |
TAGS |
tags |
O | "{\"CostCenter\":\"9999\",\"Description\":\"AI Factory common\",\"AIF-Repo\":\"aifactory\",\"AIF-Branch\":\"aifactory-001\",\"AIF-Version\":\"1.24\",\"AIF-Submodule-Chosen-Branch\":\"release/v1.24\",\"AIF-Scaleset\":\"-001\",\"AIF-Project Owners\":\"\",\"AIFactory project\":\"001\",\"AIF-Networking\":\"true,true,true\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"true\",\"AIF-disableAgentNetworkInjection\":\"false\",\"AIF-byoASEv3\":\"false\",\"AIF-BYO_subnets\":\"false\"}" |
Common-level Azure resource tags (JSON) keep-as-is: Update CostCenter, Description, and branch values to match your deployment. |
TAGS_PROJECT |
tagsProject |
O | "{\"CostCenter\":\"1234\",\"Description\":\"RAG Chat 1\",\"AIF-Branch\":\"aifactory-001/project001\",\"AIF-Scaleset\":\"-001\",\"AIF-Environment\":\"dev\",\"AIF-Project Owners\":\"\",\"AIFactory project\":\"001\",\"AIF-Networking\":\"true,true,true\",\"AIF-enableAIFactoryCreatedDefaultProjectForAIFv2\":\"true\",\"AIF-disableAgentNetworkInjection\":\"false\",\"AIF-byoASEv3\":\"false\",\"AIF-BYO_subnets\":\"false\"}" |
Project-level Azure resource tags (JSON) keep-as-is: Update CostCenter, Description, and project values to match your project. |
TAG_COSTCENTER |
tag_costcenter |
O | "1234" |
Project cost center tag keep-as-is: Metadata for per-project cost tracking. |
TAG_COSTCETER_COMMON |
tag_costceter_common |
O | "9999" |
Common cost center tag keep-as-is: Metadata for Resource group cost tracking. |
TAG_REPOSITORY |
tag_repository |
O | "aifactory" |
Repository name tag |
TAG_REPOSITORY_BRANCH |
tag_repository_branch |
O | "aifactory-001" |
Repository branch tag otherwise: per scaleset 'aifactory-002', or per project 'aifactory-001/project001-main'. |
USE_COMMON_ACR_FOR_PROJECTS |
useCommonACR, useCommonACR_override |
O | "true" |
Use shared ACR across projects otherwise: false, each project gets its own ACR (higher cost). |
USE_COMMON_ACR_OVERRIDE |
useCommonACR_override |
O | "true" |
Use shared ACR across projects (override) |
USE_SELF_HOSTED_BUILD_AGENT |
useSelfHostedBuildAgent |
O | "false" |
Run project deployment jobs on a registered self-hosted runner |
WEBAPP_RUNTIME |
webAppRuntime |
O | "python" |
Web App runtime stack otherwise: dotnet, node, java. |
WEBAPP_RUNTIME_VERSION |
webAppRuntimeVersion |
O | "3.11" |
Web App runtime version |
GHA: Services and feature switches¶
| Exact environment key | YAML / JSON counterpart(s) | M/C/O | Template value | Description / conditions |
|---|---|---|---|---|
ACR_ADMIN_USER_ENABLED |
acr_adminUserEnabled |
O | "false" |
Enable ACR admin user otherwise: true enables admin user; false is more secure. |
ACR_DEDICATED |
acr_dedicated |
O | "true" |
Dedicated ACR (Premium only) |
ACR_SKU |
acr_SKU |
O | "Premium" |
ACR SKU keep-as-is: Premium required for private endpoints or CMK. |
ADD_AI_FOUNDRY |
addAIFoundry |
O | "false" |
Add new AI Foundry instance otherwise: true, add new Foundry even if one already exists. |
ADD_AI_FOUNDRY_HUB |
addAIFoundryHub |
O | "false" |
DEPRECATED: Add new legacy Hub v1 keep-as-is: Add new Hub even if one exists. Use ADD_AI_FOUNDRY instead. |
ADD_AI_SEARCH |
addAISearch |
O | "false" |
Add new AI Search instance otherwise: true, add new instance even if one exists. |
ADD_AZURE_MACHINE_LEARNING |
addAzureMachineLearning |
O | "false" |
Add new Azure ML workspace |
ADD_BASTION_HOST |
addBastionHost |
O | "false" |
Add Bastion Host in common RG |
APIM_GATEWAY_AGGREGATE_TPM |
apimGatewayAggregateTpm |
C | "" |
80-90% of summed TPM across all Azure OpenAI backends. Required by the separate AI gateway workflow when APIM is enabled. |
APIM_GATEWAY_API_ID |
apimGatewayApiId |
O | "azure-openai-gpt55" |
Apim gateway api id. |
APIM_GATEWAY_API_PATH |
apimGatewayApiPath |
O | "openai" |
Apim gateway api path. |
APIM_GATEWAY_ASSIGN_OPENAI_USER_ROLE |
apimGatewayAssignOpenAIUserRole |
O | "false" |
Apim gateway assign openai user role. |
APIM_GATEWAY_BACKENDS_JSON |
apimGatewayBackendsJson |
C | "[]" |
Apim gateway backends json. Required by the separate AI gateway workflow when APIM is enabled. |
APIM_GATEWAY_BACKEND_POOL_NAME |
apimGatewayBackendPoolName |
O | "aoai-gpt55-pool" |
Apim gateway backend pool name. |
APIM_GATEWAY_CALLER_TPM |
apimGatewayCallerTpm |
O | "10000" |
Apim gateway caller tpm. |
APIM_GATEWAY_RESOURCE_GROUP |
apimGatewayResourceGroup |
C | "" |
Apim gateway resource group. Required by the separate AI gateway workflow when APIM is enabled. |
APIM_GATEWAY_RETRY_COUNT |
apimGatewayRetryCount |
O | "2" |
Apim gateway retry count. |
APIM_GATEWAY_SERVICE_NAME |
apimGatewayServiceName |
C | "" |
Apim gateway service name. Required by the separate AI gateway workflow when APIM is enabled. |
APIM_GATEWAY_SKU |
apimGatewaySku |
O | "StandardV2" |
BasicV2=dev/test; StandardV2=production default + VNet integration; PremiumV2=full private network isolation, zones, and high scale. Classic Developer/Basic/Standard/Premium cannot migrate to v2 in place. Consumption cannot use backend circuit breakers. |
APIM_GATEWAY_SKU_CAPACITY |
apimGatewaySkuCapacity |
O | "1" |
BasicV2/StandardV2 support up to 10 units; PremiumV2 supports up to 30. |
APIM_GATEWAY_SUBSCRIPTION_ID |
apimGatewaySubscriptionId |
O | "" |
Empty uses the GitHub Environment AZURE_SUBSCRIPTION_ID. |
CLEAN_FOUNDRY_CAPHOST |
cleanFoundryCaphost |
O | "true" |
Clean Foundry capability hosts before redeployment otherwise: true, deletes capability hosts before redeployment (useful when switching caphost configuration). |
DATABRICKS_OID |
databricksOID |
C | "<todo>" |
Databricks object ID mandatory: if ENABLE_DATABRICKS:'true' ensure: find Databricks object ID in Entra ID. |
DATABRICKS_PRIVATE |
databricksPrivate |
O | "true" |
Databricks private control plane otherwise: false, only data plane is private; control plane is public. |
DISABLE_WHITELISTING_FOR_BUILD_AGENTS |
disable_whitelisting_for_build_agents |
O | "false" |
Disable runner IP whitelisting otherwise: true, skip whitelisting (use only if runner already has network access). |
ELASTIC_COMPANY_NAME |
elasticCompanyName |
C | "Organization" |
Elastic Cloud company name mandatory: if ENABLE_ELASTICSEARCH:'true' |
ELASTIC_DEPLOYMENT_SIZE |
elasticDeploymentSize |
O | "small" |
Elasticsearch deployment size otherwise: medium or large. |
ELASTIC_EMAIL |
elasticEmail |
C | "admin@example.com" |
Elastic Cloud account email mandatory: if ENABLE_ELASTICSEARCH:'true' ensure: valid email address. |
ELASTIC_FIRST_NAME |
elasticFirstName |
C | "AI" |
Elastic Cloud contact first name mandatory: if ENABLE_ELASTICSEARCH:'true' |
ELASTIC_LAST_NAME |
elasticLastName |
C | "Factory" |
Elastic Cloud contact last name mandatory: if ENABLE_ELASTICSEARCH:'true' |
ELASTIC_SKU |
elasticSku, skuElasticDev, skuElasticStageProd |
O | "ess-consumption-2024_Monthly" |
Elastic Cloud SKU |
ELASTIC_TYPE |
elasticType |
O | "ElasticCloud" |
Elasticsearch deployment type otherwise: SelfManagedOnAKS (future support). |
ENABLE_ADMIN_VM |
enableAdminVM |
O | "false" |
Enable Admin VM in common RG |
ENABLE_AIFACTORY_CREATED_DEFAULT_PROJECT_FOR_AIFV2 |
enableAIFactoryCreatedDefaultProjectForAIFv2 |
O | "true" |
AI Factory default project for AIFv2 |
ENABLE_AI_DOC_INTELLIGENCE |
enableAIDocIntelligence |
O | "false" |
Enable Azure AI Document Intelligence |
ENABLE_AI_FACTORY_HUB |
enableAIFactoryHub |
O | "false" |
Own AI Factory Hub intent |
ENABLE_AI_FOUNDRY |
enableAIFoundry |
C | "true" |
Enable AI Foundry mandatory: Enable AI Foundry recommended: enterprise-grade private networking, BYOvNet. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths. |
ENABLE_AI_FOUNDRY_HUB |
enableAIFoundryHub |
O | "false" |
DEPRECATED: Legacy AI Foundry Hub v1 keep-as-is: Legacy Hub (v1). Use ENABLE_AI_FOUNDRY instead. |
ENABLE_AI_SEARCH |
enableAISearch |
C | "true" |
Required capability-host vector store for private Foundry standard agents. mandatory: Required capability-host vector store for private Foundry standard agents. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths. |
ENABLE_AI_SEARCH_SHARED_PRIVATE_LINK |
enableAISearchSharedPrivateLink |
O | "true" |
Enable AI Search shared private link |
ENABLE_AI_SERVICES |
enableAIServices |
O | "false" |
DEPRECATED: Standalone AI Services account keep-as-is: Replaced by ENABLE_AI_FOUNDRY. Requires ENABLE_AI_SERVICES:'true' for legacy Hub v1. |
ENABLE_AKS |
enableAKS |
O | "false" |
Deploy standalone AKS cluster keep-as-is: Independent of Azure ML, for general container workloads. |
ENABLE_AMPLS |
enableAMPLS |
O | "false" |
Enable AMPLS in Hub otherwise: true, AMPLS created in Hub subscription; AppInsights in private/private mode. |
ENABLE_APIM |
ENABLE_APIM |
O | "false" |
Enable apim. |
ENABLE_APPINSIGHTS_DASHBOARD |
enableAppInsightsDashboard |
O | "false" |
Enable Application Insights dashboard |
ENABLE_APPLICATION_INSIGHTS |
enableApplicationInsights |
O | "true" |
Workspace-based project Application Insights |
ENABLE_AZURE_AI_VISION |
enableAzureAIVision |
O | "false" |
Enable Azure AI Vision |
ENABLE_AZURE_MACHINE_LEARNING |
enableAzureMachineLearning |
O | "false" |
Enable Azure Machine Learning |
ENABLE_AZURE_MCP_SERVER |
enableAzureMcpServer |
O | "false" |
Enable the private, read-only Azure MCP server after its project configuration is prepared |
ENABLE_AZURE_OPENAI |
enableAzureOpenAI |
O | "false" |
Enable Azure OpenAI standalone account otherwise: true, deploy a standalone Azure OpenAI resource (separate from AI Foundry). |
ENABLE_AZURE_SPEECH |
enableAzureSpeech |
O | "false" |
Enable Azure AI Speech |
ENABLE_BING |
enableBing |
O | "false" |
Enable Bing Search |
ENABLE_BING_CUSTOM_SEARCH |
enableBingCustomSearch |
O | "false" |
Enable Bing Custom Search |
ENABLE_BOT_SERVICE |
enableBotService |
O | "true" |
Enable Azure Bot Service |
ENABLE_CONTAINER_APPS |
enableContainerApps |
O | "false" |
Enable Azure Container Apps |
ENABLE_CONTENT_SAFETY |
enableContentSafety |
O | "false" |
Enable Azure AI Content Safety |
ENABLE_COSMOS_DB |
enableCosmosDB |
C | "true" |
Required capability-host thread and agent-history store for private Foundry standard agents. mandatory: Required capability-host thread and agent-history store for private Foundry standard agents. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths. |
ENABLE_DATABRICKS |
enableDatabricks |
O | "false" |
Enable Azure Databricks |
ENABLE_DATAFACTORY |
enableDatafactory |
O | "false" |
Enable Azure Data Factory |
ENABLE_DATAFACTORY_COMMON |
enableDatafactoryCommon |
O | "false" |
Enable Data Factory in common RG |
ENABLE_DEFENDER_FOR_AI_RESOURCE_LEVEL |
enableDefenderforAIResourceLevel |
O | "false" |
Defender for AI at resource level keep-as-is: Per-resource Microsoft Defender for AI protection. |
ENABLE_DEFENDER_FOR_AI_SUB_LEVEL |
enableDefenderforAISubLevel |
O | "false" |
Defender for AI at subscription level keep-as-is: Subscription-level Microsoft Defender for AI protection. |
ENABLE_DELETE_FOR_DISABLED_RESOURCES |
enableDeleteForDisabledResources |
O | "false" |
Delete disabled services keep-as-is: true, delete resources that exist but are disabled (ENABLE_* flag = false). otherwise: false, keep all existing resources. |
ENABLE_ELASTICSEARCH |
enableElasticsearch |
O | "false" |
Enable Elasticsearch (Elastic Cloud) |
ENABLE_EVENT_HUBS |
enableEventHubs |
O | "false" |
Enable Azure Event Hubs |
ENABLE_FOUNDRY_CAPHOST |
enableAFoundryCaphost |
C | "true" |
Required for this private Foundry standard-agent architecture. Cannot be disabled; binds Cosmos DB, AI Search, and project Storage. mandatory: Required for this private Foundry standard-agent architecture. Cannot be disabled; binds Cosmos DB, AI Search, and project Storage. Required together for the standard private-agent capability-host architecture; not universal across all deployment paths. |
ENABLE_FUNCTION |
enableFunction |
O | "false" |
Enable Azure Functions |
ENABLE_KONG |
ENABLE_KONG |
O | "false" |
Enable kong. |
ENABLE_LOGIC_APPS |
enableLogicApps |
O | "false" |
Enable Azure Logic Apps |
ENABLE_POSTGRESQL |
enablePostgreSQL |
O | "false" |
Enable Azure PostgreSQL Flexible Server |
ENABLE_REDIS_CACHE |
enableRedisCache |
O | "false" |
Enable Azure Cache for Redis |
ENABLE_RETRIES |
enableRetries |
O | "false" |
Enable automatic job retries otherwise: true, enables retry logic for GenAI services deployment. |
ENABLE_SQL_DATABASE |
enableSQLDatabase |
O | "false" |
Enable Azure SQL Database |
ENABLE_WEBAPP |
enableWebApp |
O | "false" |
Enable Azure Web App |
FOUNDRY_API_MANAGEMENT_RESOURCE_ID |
foundryApiManagementResourceId |
O | "" |
Existing APIM resource ID for AI Foundry integration keep-as-is: Leave empty for no APIM integration. otherwise: provide full resourceId of existing API Management instance. |
FOUNDRY_DEPLOYMENT_TYPE |
foundryDeploymentType |
O | "2" |
<deprecated>Retained for configuration compatibility. AI Foundry always uses the second-option account deployment. |
KONG_CONSUMER_API_KEY |
No verified counterpart | C | "" |
Stored as an environment secret, never a variable. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret. |
KONG_GATEWAY_APIM_HOST |
kongGatewayApimHost |
C | "" |
Kong gateway apim host. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret. |
KONG_GATEWAY_CPU |
kongGatewayCpu |
O | "2" |
Kong gateway cpu. |
KONG_GATEWAY_IMAGE |
kongGatewayImage |
O | "kong/kong-gateway:3.9" |
Kong gateway image. |
KONG_GATEWAY_MEMORY_GB |
kongGatewayMemoryGb |
O | "4" |
Kong gateway memory gb. |
SERVICE_SETTING_DEPLOY_PROJECT_VM |
serviceSettingDeployProjectVM |
O | "false" |
Deploy VM in project resource group otherwise: true, deploy a jumpbox VM for use with Azure Bastion. |
UPDATE_AI_FOUNDRY |
updateAIFoundry |
O | "false" |
Update AI Foundry properties otherwise: true, update existing Foundry properties and RBAC. |
GHA: Networking, DNS and existing resources¶
| Exact environment key | YAML / JSON counterpart(s) | M/C/O | Template value | Description / conditions |
|---|---|---|---|---|
ACR_IP_WHITELIST |
acr_IP_whitelist |
O | "" |
ACR IP allowlist for selected networks keep-as-is: comma-separated approved IPv4 addresses/ranges for ACR. |
ALLOW_PUBLIC_ACCESS_WHEN_BEHINDVNET |
No verified counterpart | O | "true" |
Public UI access when behind vNet recommended: false to enable fully private networking. |
BYO_ASEV3 |
byoASEv3 |
O | "false" |
Bring your own ASEv3 otherwise: true, use a pre-existing App Service Environment v3. |
BYO_ASE_APP_SERVICE_PLAN_RESOURCE_ID |
byoAseAppServicePlanResourceId |
C | "" |
BYO App Service Plan resource ID mandatory: if BYO_ASEV3:'true' and re-using an existing App Service Plan. |
BYO_ASE_FULL_RESOURCE_ID |
byoAseFullResourceId |
C | "/subscriptions/...<todo><todo_if_BYO_ASEV3_is_true>yourASEnameS2" |
BYO ASEv3 full resource ID mandatory: if BYO_ASEV3:'true' ensure: full resource ID of the existing ASEv3. |
BYO_CONTRIBUTOR_ROLE_ID |
BYOContributorRoleID |
O | "b24988ac-6180-42a0-ab88-20f7382dd24c" |
Contributor role ID keep-as-is: Built-in Contributor role ID. otherwise: provide a custom role ID for finer-grained access control. |
BYO_SUBNETS |
BYO_subnets |
O | "false" |
Bring your own subnets otherwise: true, uses pre-existing subnets defined by the BYO subnet variables below. |
CENTRAL_DNS_ZONE_BY_POLICY_IN_HUB |
centralDnsZoneByPolicyInHub |
O | "false" |
Centralized DNS via Hub policy otherwise: true, uses central private DNS zones in HUB resource group managed by Azure Policy. |
COMMON_BASTION_SUBNET_CIDR |
common_bastion_subnet_cidr |
O | "172.16.XX.192/26" |
Bastion subnet CIDR template |
COMMON_BASTION_SUBNET_NAME |
common_bastion_subnet_name |
O | "AzureBastionSubnet" |
Bastion subnet name keep-as-is: Must be exactly 'AzureBastionSubnet'. |
COMMON_PBI_SUBNET_CIDR |
common_pbi_subnet_cidr |
O | "172.16.XX.128/26" |
Power BI subnet CIDR template |
COMMON_PBI_SUBNET_NAME |
common_pbi_subnet_name |
O | "snet-esml-cmn-pbi-001" |
Power BI subnet name |
COMMON_SUBNET_CIDR |
common_subnet_cidr |
O | "172.16.XX.0/26" |
Common subnet CIDR template keep-as-is: XX is replaced by the environment CIDR range value. |
COMMON_SUBNET_SCORING_CIDR |
common_subnet_scoring_cidr |
O | "172.16.XX.64/26" |
Common scoring subnet CIDR template |
COMMON_VNET_CIDR |
common_vnet_cidr |
O | "172.16.XX.0/18" |
Common vNet CIDR keep-as-is: XX must be network-aligned; environments must not overlap. Address intent only, not actual peering. |
DEV_CIDR_RANGE |
dev_cidr_range |
M | "0" |
DEV network-aligned XX value mandatory: DEV network-aligned XX value keep-as-is: VNet 172.16.0.0/18. |
DEV_NETWORK_ENV |
network_env_dev |
O | "dev-" |
DEV environment prefix for BYO subnets otherwise: set to empty string if not using environment-prefixed naming. |
DISABLE_AGENT_NETWORK_INJECTION |
disableAgentNetworkInjection |
O | "false" |
Disable agent network injection otherwise: true, disables network injection. Requires Class B/C network ranges (172.16/12 or 192.168/16). |
DISABLE_SUBNET_JOIN_ACTION |
disableSubnetJoinAction |
O | "false" |
Disable VNet subnet join RBAC recommended: false, grants Network Contributor role for subnet join actions (required for APIM, Container Apps, AKS). otherwise: true, skip if subnet permissions managed externally. |
ENABLE_PUBLIC_ACCESS_WITH_PERIMETER |
enablePublicAccessWithPerimeter |
O | "true" |
Public access with network perimeter recommended: false to enable fully private networking. |
ENABLE_PUBLIC_GENAI_ACCESS |
enablePublicGenAIAccess |
O | "true" |
Public GenAI access (control plane) recommended: false to enable fully private networking. |
KONG_GATEWAY_SUBNET_CIDR |
kongGatewaySubnetCidr |
C | "" |
Kong gateway subnet cidr. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret. |
KONG_GATEWAY_SUBNET_NAME |
kongGatewaySubnetName |
O | "snet-kong-001" |
Kong gateway subnet name. |
KONG_GATEWAY_VNET_NAME |
kongGatewayVnetName |
C | "" |
Kong gateway vnet name. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret. |
KONG_GATEWAY_VNET_RESOURCE_GROUP |
kongGatewayVnetResourceGroup |
C | "" |
Kong gateway vnet resource group. Required by the separate AI gateway workflow when Kong is enabled; the consumer API key is an environment secret. |
PRIV_DNS_RESOURCE_GROUP_PARAM |
privDnsResourceGroup_param |
C | "<todo>" |
Hub DNS resource group mandatory: if CENTRAL_DNS_ZONE_BY_POLICY_IN_HUB:'true' ensure: Hub connectivity resource group. |
PRIV_DNS_SUBSCRIPTION_PARAM |
privDnsSubscription_param |
C | "<todo>" |
Hub DNS subscription ID mandatory: if CENTRAL_DNS_ZONE_BY_POLICY_IN_HUB:'true' ensure: Hub connectivity subscription ID. |
PROD_CIDR_RANGE |
prod_cidr_range |
M | "128" |
PROD network-aligned XX value mandatory: PROD network-aligned XX value keep-as-is: VNet 172.16.128.0/18. |
PROD_NETWORK_ENV |
network_env_prod |
O | "prod-" |
PROD environment prefix for BYO subnets otherwise: 'pr-', or empty string. |
PROJECT_MEMBERS_IP_ADDRESS |
project_IP_whitelist |
C | "-" |
Project UI IP allowlist mandatory: if using IP-whitelisting networking mode ensure: comma-separated IPv4 addresses without spaces. |
RUN_JOB1_NETWORKING |
runNetworkingVar |
M | "true" |
Run networking module mandatory: Run networking module keep-as-is: true when creating or updating a project. otherwise: false, to skip networking on service-only updates. |
SCALING_MODE |
scaling-mode |
O | "shared-subscriptions" |
Address-planning preset: own-subscriptions or shared-subscriptions; no subscription provisioning, network resizing, or peering. |
STAGE_CIDR_RANGE |
test_cidr_range |
M | "64" |
STAGE network-aligned XX value mandatory: STAGE network-aligned XX value keep-as-is: VNet 172.16.64.0/18. |
STAGE_NETWORK_ENV |
network_env_stage |
O | "stage-" |
STAGE environment prefix for BYO subnets otherwise: 'tst-', 'test-', or empty string. |
SUBNET_COMMON |
subnetCommon |
C | "" |
BYO common subnet name mandatory: if BYO_SUBNETS:'true' |
SUBNET_COMMON_BASE |
common_subnet_name |
O | "snet-esml-cmn-001" |
Common subnet base name |
SUBNET_COMMON_POWERBI_GW |
subnetCommonPowerbiGw |
O | "" |
BYO Power BI gateway subnet name |
SUBNET_COMMON_SCORING |
subnetCommonScoring |
C | "" |
BYO common scoring subnet name mandatory: if BYO_SUBNETS:'true' |
SUBNET_PROJ_ACA |
subnetProjACA |
C | "" |
BYO Container Apps project subnet name mandatory: if ENABLE_CONTAINER_APPS:'true' and BYO_SUBNETS:'true' |
SUBNET_PROJ_ACA2 |
subnetProjACA2 |
O | "" |
BYO Container Apps secondary project subnet name |
SUBNET_PROJ_AKS |
subnetProjAKS |
C | "" |
BYO AKS project subnet name mandatory: if ENABLE_AKS_FOR_AZURE_ML:'true' and BYO_SUBNETS:'true' |
SUBNET_PROJ_AKS2 |
subnetProjAKS2 |
O | "" |
BYO AKS secondary project subnet name |
SUBNET_PROJ_DATABRICKS_PRIVATE |
subnetProjDatabricksPrivate |
C | "" |
BYO Databricks private subnet name mandatory: if ENABLE_DATABRICKS:'true' and BYO_SUBNETS:'true' |
SUBNET_PROJ_DATABRICKS_PUBLIC |
subnetProjDatabricksPublic |
C | "" |
BYO Databricks public subnet name mandatory: if ENABLE_DATABRICKS:'true' and BYO_SUBNETS:'true' |
SUBNET_PROJ_GENAI |
subnetProjGenAI |
C | "" |
BYO GenAI project subnet name mandatory: if BYO_SUBNETS:'true' |
SUBNET_PROJ_WEBAPP |
subnetProjWebapp |
C | "" |
BYO App Service/Function VNet-integration project subnet name mandatory: if (ENABLE_WEB_APP:'true' OR ENABLE_FUNCTION:'true') and BYO_SUBNETS:'true' |
VNET_NAME_BASE |
vnetNameBase |
O | "vnt-esmlcmn" |
Common vNet base name keep-as-is: Base name of the common virtual network. |
VNET_NAME_FULL_PARAM |
vnetNameFull_param |
C | "" |
BYO vNet full name mandatory: if BYO_SUBNETS:'true' ensure: full name of the existing virtual network. |
VNET_RESOURCE_GROUP_BASE |
vnetResourceGroupBase |
O | "esml-common" |
Common vNet resource group base name keep-as-is: Base name of the common vNet's resource group (used when not BYOvNet). |
VNET_RESOURCE_GROUP_PARAM |
vnetResourceGroup_param |
C | "" |
BYO vNet resource group mandatory: if BYO_SUBNETS:'true' ensure: resource group of the existing vNet. |
GHA: Per-environment SKUs and compute sizing¶
| Exact environment key | YAML / JSON counterpart(s) | M/C/O | Template value | Description / conditions |
|---|---|---|---|---|
ADMIN_AKS_GPU_SKU_DEV_OVERRIDE |
admin_aks_gpu_sku_dev_override |
O | "Standard_D4s_v5" |
AKS system node VM SKU for DEV ensure: use an AKS-supported system-pool SKU; configure GPU workloads in a separate user pool. |
ADMIN_AKS_GPU_SKU_TEST_PROD_OVERRIDE |
admin_aks_gpu_sku_test_prod_override |
O | "Standard_DS13-2_v2" |
AKS GPU SKU for TEST/PROD |
ADMIN_AKS_NODES_DEV_OVERRIDE |
admin_aks_nodes_dev_override |
O | "2" |
AKS system node count for DEV |
ADMIN_AKS_NODES_TEST_PROD_OVERRIDE |
admin_aks_nodes_testProd_override |
O | "3" |
AKS node count for TEST/PROD |
ADMIN_AKS_VERSION_OVERRIDE |
admin_aks_version_override |
O | "1.35.7" |
AKS Kubernetes version ensure: version has standard support in your region. |
ADMIN_AML_CLUSTER_MAX_NODES_DEV_OVERRIDE |
admin_aml_cluster_maxNodes_dev_override |
O | "3" |
AML cluster max nodes for DEV |
ADMIN_AML_CLUSTER_MAX_NODES_TEST_PROD_OVERRIDE |
admin_aml_cluster_maxNodes_testProd_override |
O | "5" |
AML cluster max nodes for TEST/PROD |
ADMIN_AML_CLUSTER_SKU_DEV_OVERRIDE |
admin_aml_cluster_sku_dev_override |
O | "Standard_DS3_v2" |
AML cluster VM SKU for DEV |
ADMIN_AML_CLUSTER_SKU_TEST_PROD_OVERRIDE |
admin_aml_cluster_sku_testProd_override |
O | "Standard_D13_v2" |
AML cluster VM SKU for TEST/PROD |
ADMIN_AML_COMPUTE_INSTANCE_DEV_SKU_OVERRIDE |
admin_aml_computeInstance_dev_sku_override |
O | "Standard_DS11_v2" |
AML compute instance SKU for DEV |
ADMIN_AML_COMPUTE_INSTANCE_TEST_PROD_SKU_OVERRIDE |
admin_aml_computeInstance_testProd_sku_override |
O | "Standard_ND96amsr_A100_v4" |
AML compute instance SKU for TEST/PROD |
ADMIN_VM_SIZE |
adminVMSize |
O | "Standard_D2s_v5" |
Admin VM size keep-as-is: Override when the regional SKU is unavailable. |
AKS_AZURE_FIREWALL_PRIVATE_IP |
aksAzureFirewallPrivateIp |
C | "" |
Azure Firewall private IP for AKS mandatory: if AKS_OUTBOUND_TYPE:'userDefinedRouting' |
AKS_ENABLE_PRIVATE_CLUSTER |
aksEnablePrivateCluster |
O | "true" |
Enable private AKS cluster |
AKS_OUTBOUND_TYPE |
aksOutboundType |
O | "loadBalancer" |
AKS outbound network type otherwise: userDefinedRouting for firewall/UDR scenarios. |
AKS_PRIVATE_DNS_ZONE |
aksPrivateDNSZone |
O | "system" |
AKS private DNS zone otherwise: none, or full resourceId of an existing private DNS zone. |
AKS_SKU_NAME |
aksSkuName |
O | "Base" |
AKS SKU name otherwise: Standard for production. |
AKS_SKU_TIER |
No verified counterpart | O | "Standard" |
AKS SKU tier otherwise: Free or Premium. |
ENABLE_AKS_FOR_AZURE_ML |
enableAksForAzureML |
C | "true" |
Enable AKS for Azure ML inference mandatory: if ENABLE_AZURE_MACHINE_LEARNING:'true' |
SKU_AISEARCH_DEV |
skuAISearchDev |
O | "basic" |
AI Search SKU for Dev. Must be included in SKU_ARRAY_AISEARCH_DEV when retry is enabled. |
SKU_AISEARCH_STAGEPROD |
skuAISearchStageProd |
O | "standard" |
AI Search SKU for Stage and Prod. Must be included in SKU_ARRAY_AISEARCH_STAGEPROD when retry is enabled. |
SKU_AISERVICES_DEV |
skuAIServicesDev |
O | "S0" |
Azure AI Services (multi-service account) SKU Dev |
SKU_AISERVICES_STAGEPROD |
skuAIServicesStageProd |
O | "S0" |
Azure AI Services SKU Stage/Prod |
SKU_AI_SEARCH_DEV_ARRAY |
skuAISearchDevArray |
O | "[\"basic\",\"standard\",\"standard2\"]" |
Sku ai search dev array. |
SKU_AI_SEARCH_STAGE_PROD_ARRAY |
skuAISearchStageProdArray |
O | "[\"basic\",\"standard\",\"standard2\"]" |
Sku ai search stage prod array. |
SKU_AKS_DEV |
skuAksDev |
O | "" |
AKS SKU Dev keep-as-is: Leave empty for managed/auto SKU. |
SKU_AKS_STAGEPROD |
skuAksStageProd |
O | "" |
AKS SKU Stage/Prod |
SKU_ARRAY_AISEARCH_DEV |
skuArrayAISearchDev |
O | "basic,standard,standard2" |
Ordered Azure AI Search capacity fallback candidates (one to three SKUs). |
SKU_ARRAY_AISEARCH_STAGEPROD |
skuArrayAISearchStageProd |
O | "basic,standard,standard2" |
Ordered Azure AI Search capacity fallback candidates (one to three SKUs). |
SKU_ARRAY_CONTAINER_APPS_DEV |
skuArrayContainerAppsDev |
O | "Consumption,D4,D8" |
Ordered capacity fallback profiles; D4/D8 have dedicated pricing. |
SKU_ARRAY_CONTAINER_APPS_STAGEPROD |
skuArrayContainerAppsStageProd |
O | "Consumption,D4,D8" |
Ordered capacity fallback profiles; D4/D8 have dedicated pricing. |
SKU_ARRAY_POSTGRESQL_DEV |
skuArrayPostgreSQLDev |
O | "Standard_B1ms,Standard_B2s,Standard_B2ms" |
Ordered regional/SKU capacity fallback candidates; selected Dev SKU first. |
SKU_ARRAY_POSTGRESQL_STAGEPROD |
skuArrayPostgreSQLStageProd |
O | "Standard_B1ms,Standard_B2s,Standard_B2ms" |
Ordered regional/SKU capacity fallback candidates; selected Stage/Prod SKU first. |
SKU_AZUREML_DEV |
skuAzureMLDev |
O | "basic" |
Azure ML workspace SKU Dev |
SKU_AZUREML_STAGEPROD |
skuAzureMLStageProd |
O | "basic" |
Azure ML workspace SKU Stage/Prod |
SKU_BING_DEV |
skuBingDev |
O | "G2" |
Bing Custom Search SKU Dev keep-as-is: ['G2'] |
SKU_BING_STAGEPROD |
skuBingStageProd |
O | "G2" |
Bing Custom Search SKU Stage/Prod |
SKU_BOTSERVICE_DEV |
skuBotServiceDev |
O | "S1" |
Bot Service SKU Dev keep-as-is: ['F0','S1'] |
SKU_BOTSERVICE_STAGEPROD |
skuBotServiceStageProd |
O | "S1" |
Bot Service SKU Stage/Prod |
SKU_CONTAINER_APPS_DEV |
skuContainerAppsDev |
O | "Consumption" |
Container Apps workload profile Dev ['Consumption','D4','D8']. |
SKU_CONTAINER_APPS_STAGEPROD |
skuContainerAppsStageProd |
O | "Consumption" |
Container Apps workload profile Stage/Prod. |
SKU_CONTENTSAFETY_DEV |
skuContentSafetyDev |
O | "S0" |
Content Safety SKU Dev |
SKU_CONTENTSAFETY_STAGEPROD |
skuContentSafetyStageProd |
O | "S0" |
Content Safety SKU Stage/Prod |
SKU_DATABRICKS_DEV |
skuDatabricksDev |
O | "premium" |
Databricks workspace SKU Dev keep-as-is: ['standard','premium','trial'] |
SKU_DATABRICKS_STAGEPROD |
skuDatabricksStageProd |
O | "premium" |
Databricks workspace SKU Stage/Prod |
SKU_DOCINTELLIGENCE_DEV |
skuDocIntelligenceDev |
O | "S0" |
Document Intelligence SKU Dev |
SKU_DOCINTELLIGENCE_STAGEPROD |
skuDocIntelligenceStageProd |
O | "S0" |
Document Intelligence SKU Stage/Prod |
SKU_ELASTIC_DEV |
skuElasticDev |
O | "ess-consumption-2024_Monthly" |
Elastic Cloud SKU Dev |
SKU_ELASTIC_STAGEPROD |
skuElasticStageProd |
O | "ess-consumption-2024_Monthly" |
Elastic Cloud SKU Stage/Prod |
SKU_EVENTHUBS_DEV |
skuEventHubsDev |
O | "Basic" |
Event Hubs namespace SKU Dev keep-as-is: ['Basic','Standard','Premium'] |
SKU_EVENTHUBS_STAGEPROD |
skuEventHubsStageProd |
O | "Basic" |
Event Hubs namespace SKU Stage/Prod |
SKU_FUNCTION_DEV |
skuFunctionDev |
O | "EP1" |
Function plan SKU Dev |
SKU_FUNCTION_STAGEPROD |
skuFunctionStageProd |
O | "EP1" |
Function plan SKU Stage/Prod |
SKU_LOGICAPPS_DEV |
skuLogicAppsDev |
O | "WS1" |
Logic Apps (Standard) SKU Dev |
SKU_LOGICAPPS_STAGEPROD |
skuLogicAppsStageProd |
O | "WS1" |
Logic Apps (Standard) SKU Stage/Prod |
SKU_OPENAI_DEV |
skuOpenAIDev |
O | "S0" |
Azure OpenAI SKU Dev |
SKU_OPENAI_STAGEPROD |
skuOpenAIStageProd |
O | "S0" |
Azure OpenAI SKU Stage/Prod |
SKU_POSTGRESQL_DEV |
skuPostgreSQLDev |
O | "Standard_B1ms" |
PostgreSQL compute SKU Dev |
SKU_POSTGRESQL_STAGEPROD |
skuPostgreSQLStageProd |
O | "Standard_B1ms" |
PostgreSQL compute SKU Stage/Prod |
SKU_REDIS_DEV |
skuRedisDev |
O | "Standard" |
Redis SKU Dev keep-as-is: ['Basic','Standard','Premium'] |
SKU_REDIS_STAGEPROD |
skuRedisStageProd |
O | "Standard" |
Redis SKU Stage/Prod |
SKU_SPEECH_DEV |
skuSpeechDev |
O | "S0" |
Azure AI Speech SKU Dev |
SKU_SPEECH_STAGEPROD |
skuSpeechStageProd |
O | "S0" |
Azure AI Speech SKU Stage/Prod |
SKU_SQLDATABASE_DEV |
skuSQLDatabaseDev |
O | "S0" |
Azure SQL DB (DTU model) SKU Dev |
SKU_SQLDATABASE_STAGEPROD |
skuSQLDatabaseStageProd |
O | "S0" |
Azure SQL DB (DTU model) SKU Stage/Prod |
SKU_STORAGEACCOUNT_DEV |
skuStorageAccountDev |
O | "Standard_LRS" |
Project Storage Account SKU Dev keep-as-is: ['Standard_LRS','Standard_GRS','Standard_RAGRS','Standard_ZRS','Premium_LRS','Premium_ZRS','Standard_GZRS','Standard_RAGZRS'] |
SKU_STORAGEACCOUNT_STAGEPROD |
skuStorageAccountStageProd |
O | "Standard_LRS" |
Project Storage Account SKU Stage/Prod |
SKU_TIER_AKS_DEV |
skuTierAksDev |
O | "Standard" |
AKS tier Dev keep-as-is: ['Free','Standard','Premium'] |
SKU_TIER_AKS_STAGEPROD |
skuTierAksStageProd |
O | "Standard" |
AKS tier Stage/Prod |
SKU_TIER_AZUREML_DEV |
skuTierAzureMLDev |
O | "basic" |
Azure ML workspace tier Dev |
SKU_TIER_AZUREML_STAGEPROD |
skuTierAzureMLStageProd |
O | "basic" |
Azure ML workspace tier Stage/Prod |
SKU_TIER_FUNCTION_DEV |
skuTierFunctionDev |
O | "ElasticPremium" |
Function plan tier Dev |
SKU_TIER_FUNCTION_STAGEPROD |
skuTierFunctionStageProd |
O | "ElasticPremium" |
Function plan tier Stage/Prod |
SKU_TIER_POSTGRESQL_DEV |
skuTierPostgreSQLDev |
O | "Burstable" |
PostgreSQL tier Dev keep-as-is: ['Burstable','GeneralPurpose','MemoryOptimized'] |
SKU_TIER_POSTGRESQL_STAGEPROD |
skuTierPostgreSQLStageProd |
O | "Burstable" |
PostgreSQL tier Stage/Prod |
SKU_TIER_SQLDATABASE_DEV |
skuTierSQLDatabaseDev |
O | "Standard" |
Azure SQL DB tier Dev keep-as-is: ['Basic','Standard','Premium'] |
SKU_TIER_SQLDATABASE_STAGEPROD |
skuTierSQLDatabaseStageProd |
O | "Standard" |
Azure SQL DB tier Stage/Prod |
SKU_TIER_WEBAPP_DEV |
skuTierWebAppDev |
O | "PremiumV3" |
Web App plan tier Dev |
SKU_TIER_WEBAPP_STAGEPROD |
skuTierWebAppStageProd |
O | "PremiumV3" |
Web App plan tier Stage/Prod |
SKU_VISION_DEV |
skuVisionDev |
O | "S1" |
Azure AI Vision SKU Dev |
SKU_VISION_STAGEPROD |
skuVisionStageProd |
O | "S1" |
Azure AI Vision SKU Stage/Prod |
SKU_WEBAPP_DEV |
skuWebAppDev |
O | "P1v3" |
Web App plan SKU Dev |
SKU_WEBAPP_STAGEPROD |
skuWebAppStageProd |
O | "P1v3" |
Web App plan SKU Stage/Prod |
GHA: Identity, access and encryption¶
| Exact environment key | YAML / JSON counterpart(s) | M/C/O | Template value | Description / conditions |
|---|---|---|---|---|
APIM_GATEWAY_MANAGED_IDENTITY_PRINCIPAL_ID |
apimGatewayManagedIdentityPrincipalId |
C | "" |
Apim gateway managed identity principal id. Required when assigning the OpenAI user role to the APIM managed identity. |
AZURE_MACHINELEARNING_SP_OID |
azure_machinelearning_sp_oid |
C | "<todo>" |
Azure ML service principal OID mandatory: Azure ML service principal OID ensure: find in Entra ID as 'Azure Machine Learning' app. otherwise: optional if ENABLE_AI_FOUNDRY:'false'. |
CMK |
cmk |
O | "false" |
Customer Managed Key encryption otherwise: true enables CMEK where supported. Requires KEYVAULT_SOFT_DELETE > 7 days. |
CMK_DISABLE_FOR_AI_SEARCH |
cmkDisableForAISearch |
O | "true" |
Disable CMK for AI Search otherwise: false, enables CMK encryption for AI Search even when CMK:'true'. |
CMK_DISABLE_FOR_FOUNDRY |
cmkDisableForFoundry |
O | "true" |
Disable CMK for AI Foundry otherwise: false, enables CMK encryption for AI Foundry even when CMK:'true'. |
CMK_KEY_NAME |
cmkKeyName |
C | "<todo>aifactory-cmk-key" |
CMK key name in seeding KV mandatory: if CMK:'true' ensure: key must exist in seeding Key Vault. |
CMK_KEY_VERSION |
cmkKeyVersion |
O | "" |
CMK key version keep-as-is: Leave empty to always use the latest key version. |
COMMON_SERVICE_PRINCIPAL_KV_S_NAME_APPID |
No verified counterpart | C | "<optional>esml-common-bicep-sp-id" |
Seeding KV secret name for common SP App ID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
COMMON_SERVICE_PRINCIPAL_KV_S_NAME_SECRET |
No verified counterpart | C | "<optional>esml-common-bicep-sp-secret" |
Seeding KV secret name for common SP secret ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
COMMON_SERVICE_PRINCIPLE_OID_KEY |
commonServicePrincipleOIDKey |
C | "<todo>esml-common-sp-oid" |
Seeding KV secret name for common SP OID mandatory: Seeding KV secret name for common SP OID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
DEBUG_DISABLE_100_RBAC_SECURITY |
debug_disable_100_rbac_security |
O | "false" |
Disable step 100: RBAC & Security keep-as-is: RBAC assignments for steps 61-99. |
DISABLE_CONTRIBUTOR_ACCESS_FORUSERS |
disableContributorAccessForUsers |
O | "false" |
Disable Contributor for project users recommended: true, restrict direct Contributor for better governance. |
DISABLE_LOCAL_AUTH |
disableLocalAuth |
O | "true" |
Disable local API key ("admin account") auth on Cognitive/AI Services & Foundry, AAD-only recommended: true, disables key auth (many orgs forbid keys). otherwise: false, allow local API keys. |
DISABLE_RBAC_ADMIN_ON_RG_FORUSERS |
disableRBACAdminOnRGForUsers |
O | "false" |
Disable RBAC Admin on RG for project users recommended: true, restrict RBAC Admin on resource group for better governance. |
GROUPS_CORETEAM_MEMBERS |
groups_coreteam_members |
M | "<aif001sdc_coreteam_admin_p080>,<aif001sdc_coreteam_dataops_p081>,<aif001sdc_coreteam_dataops_fabric_p082>" |
Core team Entra ID group OIDs mandatory: Core team Entra ID group OIDs ensure: 3 comma-separated AD group ObjectIDs matching personas in PERSONAS_CORE_TEAM. |
GROUPS_PROJECT_MEMBERS_ESML |
groups_project_members_esml |
M | "<aif001sdc_prj001_team_lead_p001>,<aif001sdc_prj001_team_member_ds_p002>,<aif001sdc_prj001_team_member_fend_p003>" |
ESML project team Entra ID group OIDs mandatory: ESML project team Entra ID group OIDs ensure: 3 comma-separated AD group ObjectIDs matching personas in PERSONAS_PROJECT_ESML. |
GROUPS_PROJECT_MEMBERS_GENAI_1 |
groups_project_members_genai_1 |
M | "<aif001sdc_prj002_team_lead_p011>,<aif001sdc_prj002_genai_team_member_aifoundry_p012>,<aif002sdc_prj001_genai_team_member_agentic_p013>,<aif001sdc_prj001_genai_team_member_dataops_p014>,<aif001sdc_prj001_team_member_fend_p015>" |
GenAI-1 project team Entra ID group OIDs mandatory: GenAI-1 project team Entra ID group OIDs ensure: 5 comma-separated AD group ObjectIDs matching personas in PERSONAS_PROJECT_GENAI_1. |
INPUT_COMMON_SPID_KEY |
inputCommonSPIDKey |
C | "<todo>esml-common-sp-id" |
Seeding KV secret name for common SP App ID mandatory: Seeding KV secret name for common SP App ID ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
INPUT_COMMON_SP_SECRET_KEY |
inputCommonSPSecretKey |
C | "<todo>esml-common-sp-secret" |
Seeding KV secret name for common SP secret mandatory: Seeding KV secret name for common SP secret ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
PERSONAS_CORE_TEAM |
personas_core_team |
O | "p080_coreteam_it_admin,coreteam_dataops,p081_coreteam_dataops_fabric, p103_coreteam_team_process_ops" |
Core team persona list keep-as-is: 4 personas (3 user, 1 SP). Mapped to GROUPS_CORETEAM_MEMBERS. |
PERSONAS_PROJECT_ESML |
personas_project_esml |
O | "p001_esml_team_lead,p002_esml_team_member_datascientist,p003_esml_team_member_front_end,p101_esml_team_process_ops" |
ESML project persona list keep-as-is: 4 personas (3 user, 1 SP). Mapped to GROUPS_PROJECT_MEMBERS_ESML. |
PERSONAS_PROJECT_GENAI_1 |
personas_project_genai_1 |
O | "p011_genai_team_lead,p012_genai_team_member_aifoundry,p013_genai_team_member_agentic,p014_genai_team_member_dataops,p015_genai_team_member_frontend,p102_esml_team_process_ops" |
GenAI-1 project persona list keep-as-is: 6 personas (5 user, 1 SP). Mapped to GROUPS_PROJECT_MEMBERS_GENAI_1. |
PROJECT_MEMBERS |
technical_admins_ad_object_id |
M | "<todo>_object_id" |
Project team Entra ID object ID(s) mandatory: Project team Entra ID object ID(s) ensure: comma-separated ObjectIDs of users or AD groups (when USE_AD_GROUPS:'true'). |
PROJECT_MEMBERS_EMAILS |
technical_admins_email |
O | "<todo>_EntraID-Security-Group-Name" |
Project team contact email or group name recommended: set for better project tracking. |
PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_APPID |
project_service_principal_AppID_seeding_kv_name |
C | "<optional>esml-project001-sp-id" |
Project SP App ID secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_OID |
project_service_principal_OID_seeding_kv_name |
C | "<optional>esml-project001-sp-oid" |
Project SP OID secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
PROJECT_SERVICE_PRINCIPAL_KV_S_NAME_S |
project_service_principal_Secret_seeding_kv_name |
C | "<optional>esml-project001-sp-secret" |
Project SP secret name in seeding KV ensure: name matches the secret in your Seeding Keyvault. Secret-name reference for the selected service-principal/seeding path; not a credential value. |
TENANT_AZUREML_OID |
azure_machinelearning_sp_oid |
C | "<todo>" |
Azure ML service principal OID mandatory: Azure ML service principal OID ensure: find in Entra ID as 'Azure Machine Learning' app (AppId: 0736f41a-0425-4b46-bdb5-1563eff02385). otherwise: optional if ENABLE_AI_FOUNDRY:'false'. |
TENANT_ID |
tenantId |
M | "<todo>" |
Azure tenant ID mandatory: Azure tenant ID ensure: find in Azure Portal > Entra ID > Overview (Directory ID). |
UPDATE_KEYVAULT_RBAC |
updateKeyvaultRbac |
O | "false" |
Update Key Vault RBAC otherwise: true enables updating KV RBAC by rerunning the pipeline. |
USE_AD_GROUPS |
use_ad_groups |
O | "true" |
Use AD groups for project members otherwise: false, use individual ObjectIDs and simple mode Personas. |
GHA: Operations, diagnostics and lifecycle¶
| Exact environment key | YAML / JSON counterpart(s) | M/C/O | Template value | Description / conditions |
|---|---|---|---|---|
DEBUG_DISABLE_05_BUILD_ACR_IMAGE |
debug_disable_05_build_acr_image |
O | "false" |
Disable ACR image build step keep-as-is: Cannot be disabled if ContainerApps is enabled (requires ACR networking with runner IP allowlist). |
DEBUG_DISABLE_10_AIFACTORY_DASHBOARDS |
debug_disable_10_aifactory_dashboards |
O | "true" |
Disable AI Factory Dashboards step |
DEBUG_DISABLE_61_FOUNDATION |
debug_disable_61_foundation |
O | "false" |
Disable step 61: Foundation keep-as-is: Resource groups, UAMIs, VMs. |
DEBUG_DISABLE_62_CORE_INFRASTRUCTURE |
debug_disable_62_core_infrastructure |
O | "false" |
Disable step 62: Core infrastructure keep-as-is: Application Insights, Key Vault, Storage, ACR. |
DEBUG_DISABLE_63_COGNITIVE_SERVICES |
debug_disable_63_cognitive_services |
O | "false" |
Disable step 63: Cognitive Services keep-as-is: AI Search, OpenAI Standalone, Vision, Speech. |
DEBUG_DISABLE_64_DATABASES |
debug_disable_64_databases |
O | "false" |
Disable step 64: Databases keep-as-is: CosmosDB, SQL Database. |
DEBUG_DISABLE_65_COMPUTE_SERVICES |
debug_disable_65_compute_services |
O | "false" |
Disable step 65: Compute services keep-as-is: Container Apps, WebApp, FunctionApp. |
DEBUG_DISABLE_66_AI_PLATFORM |
debug_disable_66_ai_platform |
O | "false" |
Disable step 66: AI Platform keep-as-is: AI Foundry Hub (V1) with default project and connections. |
DEBUG_DISABLE_67_ML_PLATFORM |
debug_disable_67_data_ml_platform |
O | "false" |
Disable step 67: ML Platform keep-as-is: Azure Machine Learning, Datafactory, Databricks. |
DEBUG_DISABLE_68_INTEGRATION |
debug_disable_68_integration |
O | "false" |
Disable step 68: Integration keep-as-is: Logic Apps, Event Hubs. |
DEBUG_DISABLE_69_AIFOUNDRY_2025 |
debug_disable_69_aifoundry_2025 |
O | "false" |
Disable step 69: AI Foundry V2 keep-as-is: AI Foundry V2 including RBAC and default project (CosmosDB, Storage). |
DEBUG_DISABLE_VALIDATION_TASKS |
debug_disable_validation_tasks |
O | "false" |
Disable validation tasks otherwise: true, skip subnet, submodule, and DNS checks. |
DEBUG_ENABLE_CLEANING |
debugEnableCleaning |
O | "false" |
Enable error cleanup tasks otherwise: true, enables cleanup tasks (71-73) that delete resources on deployment failures. |
DELETE_ALL_FOR_PROJECT |
deleteAllForProject |
O | "false" |
Delete EVERYTHING for project otherwise: true, deletes ALL resources in project RG including KV, Storage, AppInsights, and networking resources (subnets, NSGs) in common RG. Use with extreme caution! |
DELETE_ALL_SERVICES_FOR_PROJECT |
deleteAllServicesForProject |
O | "false" |
Delete all project services otherwise: true, delete ALL services in the project RG (except KV, Storage, AppInsights) before redeploy. |
DELETE_KEYVAULT_ALSO |
deleteKeyvaultAlso |
O | "false" |
Also delete Key Vault when DELETE_ALL_SERVICES_FOR_PROJECT:'true' recommended: false, retains Key Vault as a safety net (secrets, CMK keys, RBAC). otherwise: true, also deletes the project Key Vault. |
DIAGNOSTIC_SETTING_LEVEL |
diagnosticSettingLevel |
O | "gold" |
Diagnostics level otherwise: silver or bronze for less verbose (lower cost) logging. |
POLICY_EXEMPTION_ASSIGNMENT_IDS |
policyExemptionAssignmentIds |
O | "[]" |
JSON array of policy assignment IDs (deployIfNotExists or auditIfNotExists) scoped to the VNet RG keep-as-is: Prevents DINE remediation race conditions during AI Foundry Standard Agent network injection. Leave as '[]' in greenfield/non-ALZ. otherwise: e.g. '["/subscriptions/ |
POLICY_EXEMPTION_DEFINITION_REFERENCE_IDS |
policyExemptionDefinitionReferenceIds |
O | "[]" |
JSON array of policyDefinitionReferenceIds to narrow exemption to specific DINE members within an initiative keep-as-is: Leave as '[]' to exempt the full assignment. |
RETRY_MINUTES |
retryMinutes |
O | "5" |
Minutes between 1st and 2nd retry attempt |
RETRY_MINUTES_EXTENDED |
retryMinutesExtended |
O | "15" |
Minutes between 2nd and 3rd retry attempt |
SELF_HOSTED_RUNNER_LABEL |
selfHostedRunnerLabel |
O | "aifactory-admin-vm" |
Custom label assigned to the GitHub self-hosted runner |
GHA: Models and deployments¶
| Exact environment key | YAML / JSON counterpart(s) | M/C/O | Template value | Description / conditions |
|---|---|---|---|---|
DEFAULT_EMBEDDING_CAPACITY |
default_embedding_capacity |
O | "25" |
Embedding model capacity (TPM in K) |
DEFAULT_GPT_4O_VERSION |
default_gpt_4o_version |
O | "2024-11-20" |
GPT-4o version |
DEFAULT_GPT_54_MINI_VERSION |
default_gpt_54_mini_version |
O | "2026-03-17" |
Version for the separately named GPT-5.4-mini deployment toggle. |
DEFAULT_GPT_CAPACITY |
default_gpt_capacity |
O | "40" |
GPT model capacity (TPM in K) keep-as-is: 40 = 40K tokens per minute. |
DEFAULT_MODEL_SKU |
default_model_sku |
O | "DataZoneStandard" |
Default model deployment SKU keep-as-is: Keep inference within the selected data zone; confirm model/SKU availability and quota. |
DEPLOY_MODEL_GPT_4O |
deployModel_gpt_4o |
O | "false" |
Deploy GPT-4o model |
DEPLOY_MODEL_GPT_54_MINI |
deployModel_gpt_54_mini |
O | "false" |
Enable the separately named GPT-5.4-mini deployment toggle. |
DEPLOY_MODEL_GPT_X |
deployModel_gpt_X |
O | "true" |
Deploy custom GPT-X model otherwise: true, deploys the model defined in MODEL_GPTX_NAME. |
DEPLOY_MODEL_TEXT_EMBEDDING_3_LARGE |
deployModel_text_embedding_3_large |
O | "true" |
Deploy text-embedding-3-large |
DEPLOY_MODEL_TEXT_EMBEDDING_3_SMALL |
deployModel_text_embedding_3_small |
O | "false" |
Deploy text-embedding-3-small |
DEPLOY_MODEL_TEXT_EMBEDDING_ADA_002 |
deployModel_text_embedding_ada_002 |
O | "false" |
Deploy text-embedding-ada-002 |
MODEL_GPTX_CAPACITY |
modelGPTXCapacity |
O | "30" |
Custom GPT-X model capacity (TPM in K) keep-as-is: 30 = 30K tokens per minute. |
MODEL_GPTX_NAME |
modelGPTXName |
O | "gpt-5.4-mini" |
Custom GPT-X model name |
MODEL_GPTX_SKU |
modelGPTXSku |
O | "DataZoneStandard" |
Custom GPT-X model SKU keep-as-is: Keep inference within the selected data zone; confirm model/SKU availability and quota. |
MODEL_GPTX_VERSION |
modelGPTXVersion |
O | "2026-03-17" |
Custom GPT-X model version keep-as-is: Update the version when selecting a different model. |
Shared-binding collisions¶
These GHA names occur against multiple YAML/JSON keys. Follow the relevant workflow/environment rather than treating this as a one-to-one rename. All source defaults remain separate above.
| GHA binding / fallback | YAML / JSON keys |
|---|---|
ADMIN_AISEARCH_TIER |
admin_aiSearchTier, skuAISearchDev, skuAISearchStageProd |
AIFACTORY_SEEDING_KEYVAULT_NAME |
dev_admin_bicep_kv_fw, prod_admin_bicep_kv_fw, test_admin_bicep_kv_fw |
AIFACTORY_SEEDING_KEYVAULT_RG |
dev_admin_bicep_kv_fw_rg, prod_admin_bicep_kv_fw_rg, test_admin_bicep_kv_fw_rg |
AIFACTORY_SEEDING_KEYVAULT_SUBSCRIPTION_ID |
dev_admin_bicep_input_keyvault_subscription, prod_admin_bicep_input_keyvault_subscription, test_admin_bicep_input_keyvault_subscription |
ELASTIC_SKU |
elasticSku, skuElasticDev, skuElasticStageProd |
USE_COMMON_ACR_FOR_PROJECTS |
useCommonACR, useCommonACR_override |
Bootstrap environment inputs¶
Inputs are read by the create launchers, with version selectors also used by update. M means a value must resolve (an authenticated-context default may supply it); C means route/mode-specific; O means a default or optional override. $... defaults below are literal source expressions, not values discovered on this machine. Blank means no literal default at that point. Prompts, simple-mode fixed values, and validation can narrow them further.
| Input | M/C/O | Source default / expression | Description |
|---|---|---|---|
ADO_AGENT_NAME |
C | "dsvm-cmn-${AIF_LOCATION_SHORT}-dev-001" |
Ado agent name override; see create launcher. |
ADO_AGENT_POOL |
C | "Default" |
Azure DevOps agent pool |
ADO_AUTH_METHOD |
C | "aad" |
Azure DevOps authentication: Microsoft Entra (aad) or PAT (pat); allowed: aad pat |
ADO_BRANCH |
C | "main" |
ADO update branch; reviewed project dispatch requires main. |
ADO_ORGANIZATION |
C | "" |
Azure DevOps organization name or URL |
ADO_PIPELINE_NAME |
C | "infra-project-genai" |
ADO legacy update pipeline name. |
ADO_PROJECT |
C | "" |
Azure DevOps project name |
ADO_REPOSITORY_NAME |
C | "${AIF_PREFIX%-}aifactory-${AIF_SCALESET_SUFFIX}" |
Azure DevOps repository name |
ADO_RUNNER_MODE |
C | "$runner_default" |
Project build agent: self-hosted admin VM (s, recommended for private access) or Microsoft-hosted (h); allowed: s h |
ADO_RUNNER_SELECTION |
C | "from-config" |
ADO legacy update runner selection. |
ADO_SERVICE_CONNECTION_NAME |
C | "sc-${AIF_PREFIX%-}dev-${AIF_SCALESET_SUFFIX}" |
Azure DevOps service connection name |
ADO_SETTINGS_FILE |
C | "$HOME/.aifactory-ado-settings.json" |
ADO saved organization/project context path; generator never reads this file. |
ADO_TENANT |
C | "$AIF_TENANT_ID" |
Azure DevOps connected tenant ID |
AIFACTORY_COMMIT_CHANGES |
O | "" |
Update confirmation y/yes or n/no; default No. Choosing Yes authorizes the launcher's commit/continue path. |
AIFACTORY_PROJECT_CONFIG |
C | "" |
Reviewed project JSON file; required together with explicit target environment, project number and repository root. |
AIFACTORY_PROJECT_DEPLOYMENT_SCOPE |
O | "project" |
ADO update scope: project or azure-mcp. |
AIFACTORY_PROJECT_NUMBER |
C | "" |
Reviewed update/project target number; required together with target environment, project configuration and repository root. |
AIFACTORY_PROJECT_ONLY |
O | "false" |
Update launcher equivalent of --project-only. |
AIFACTORY_REPO_ROOT |
O | "" |
Repository root; --repo-root overrides it. |
AIFACTORY_TARGET_ENVIRONMENT |
C | "dev" |
Update target: dev, test/stage, or prod; verify route/environment naming. |
AIFACTORY_UPDATE_GITHUB_VARIABLES |
O | "" |
GHA update confirmation y/yes or n/no for synchronization from .env; default No. |
AIFACTORY_USE_JSON_OVERRIDE |
O | "" |
y/yes enables variables.json overrides; blank/n/no disables. Explicit reviewed project inputs force this to yes. |
AIFACTORY_VERSION |
O | "" |
Explicit template release; omitted Create uses 124 and Update inherits the installed version. --aifactory-version takes precedence. |
AIF_ACCESS_HUB_MODE |
C | "i" |
Standalone access hub: integrated in DEV common network (i) or external connectivity subscription (e); allowed: i e |
AIF_ACCESS_HUB_RESOURCE_GROUP |
C | "aifactory-connectivity" |
External access-hub and private-DNS resource group |
AIF_ACCESS_HUB_SUBSCRIPTION_ID |
C | "" |
External access-hub subscription ID |
AIF_ACCESS_HUB_VNET_CIDR |
C | "10.240.0.0/22" |
External access-hub vNet CIDR |
AIF_ACCESS_HUB_VNET_NAME |
C | "" |
Aif access hub vnet name override; see create launcher. |
AIF_ADD_BASTION |
O | "" |
Compatibility input; collection resets this to false. Access-hub Bastion is controlled separately. |
AIF_ADMIN_GROUP_ID |
O | "" |
Existing administrators group object ID (blank to create/ensure by name) |
AIF_ADMIN_GROUP_MODE |
O | "$admin_group_default" |
Technical administrators: reuse initial team (team) or separate Entra group (separate); allowed: team separate |
AIF_ADMIN_GROUP_NAME |
O | "${AIF_PREFIX%-}-admins" |
Entra administrators security group |
AIF_ADMIN_MEMBER_EMAIL |
O | "$current_user" |
Initial administrators group member |
AIF_ADMIN_VM_SIZE |
O | "$([[ \"$AIF_RUNNER_VM_OS\" == linux ]] && echo Standard_D4s_v5 || echo Standard_D2s_v5)" |
Self-hosted admin VM size |
AIF_APP_GATEWAY_BACKEND_FQDN |
C | "" |
Simple-mode distinct private HTTPS backend; trusted TLS and unauthenticated GET / returning 200-399. |
AIF_APP_GATEWAY_CERT_SECRET_ID |
C | "" |
Simple-mode versionless Key Vault PFX certificate-secret URI, not a secret value. |
AIF_APP_GATEWAY_HOSTNAME |
C | "" |
Simple-mode custom frontend FQDN covered by certificate DNS SAN. |
AIF_AZURE_ML_PRINCIPAL_ID |
O | "" |
Existing Azure Machine Learning enterprise-application object ID; otherwise discovered/ensured. |
AIF_BOOTSTRAP_RESOURCE_GROUP |
O | "rg-${AIF_PREFIX%-}-bootstrap-${AIF_LOCATION_SHORT}-${AIF_SCALESET_SUFFIX}" |
Aif bootstrap resource group override; see create launcher. |
AIF_CONFIGURE_VPN_CLIENT |
O | "$configure_vpn_client_default" |
Install and configure Azure VPN Client on this computer? (Y/n) |
AIF_COST_CENTER |
O | "123456" |
Simple-mode common and project cost-center tag. |
AIF_CREATE_DEFAULT_VERSION |
O | "124" |
Legacy Create launcher default when no explicit version selector is supplied. |
AIF_DATABRICKS_PRINCIPAL_ID |
O | "" |
Existing Databricks enterprise-application object ID; otherwise discovered/ensured when needed. |
AIF_DEPLOYMENT_IDENTITY_NAME |
O | "id-${AIF_PREFIX%-}-deploy-${AIF_LOCATION_SHORT}-${AIF_SCALESET_SUFFIX}" |
Aif deployment identity name override; see create launcher. |
AIF_DEV_SUBSCRIPTION_ID |
M | "$current_subscription" |
DEV subscription ID |
AIF_DEV_VNET_CIDR |
O | "172.16.0.0/18" |
DEV vNet CIDR used to derive aligned XX templates for all environments (/18, /19 or /20; no XX placeholder) |
AIF_DRY_RUN |
O | "false" |
Aif dry run override; see create launcher. |
AIF_HUB_RESOURCE_GROUP |
C | "" |
Hub private-DNS resource group |
AIF_HUB_SUBSCRIPTION_ID |
C | "" |
Hub subscription ID |
AIF_HUB_VNET_NAME |
C | "" |
Hub vNet name |
AIF_HUB_VNET_RESOURCE_GROUP |
C | "$AIF_HUB_RESOURCE_GROUP" |
Hub vNet resource group |
AIF_IDENTITY_MODE |
O | "c" |
Deployment identity: create managed identity (c), existing managed identity (mi), or existing service principal (sp); allowed: c mi sp |
AIF_IP_ALLOWLIST |
O | "" |
IPv4 allowlist input; the current create prompt accepts private networking only. |
AIF_LOCATION |
O | "swedencentral" |
Azure region (swedencentral, westeurope, northeurope, eastus, eastus2, uksouth, westgermany) |
AIF_MI_RESOURCE_ID |
C | "" |
Existing user-assigned managed identity resource ID |
AIF_NETWORK_MODE |
O | "priv" |
Networking: private-only (priv; enforced by policy); allowed: priv |
AIF_NON_INTERACTIVE |
O | "false" |
Aif non interactive override; see create launcher. |
AIF_NO_WAIT |
O | "false" |
Aif no wait override; see create launcher. |
AIF_PREFIX |
O | "aif-" |
AI Factory naming prefix |
AIF_PREPARE_ONLY |
O | "false" |
Aif prepare only override; see create launcher. |
AIF_PROD_SUBSCRIPTION_ID |
O | "$AIF_DEV_SUBSCRIPTION_ID" |
Aif prod subscription id override; see create launcher. |
AIF_PROJECT_NUMBER |
O | "001" |
First project number (001-999) |
AIF_RUNNER_MODE |
O | "$runner_default" |
Project runner: self-hosted (recommended for private access) or github-hosted; allowed: self-hosted github-hosted |
AIF_RUNNER_VM_NAME |
O | "$default_name" |
Aif runner vm name override; see create launcher. |
AIF_RUNNER_VM_OS |
O | "$([[ \"$AIF_ROUTE\" == gha ]] && echo linux || echo windows)" |
Aif runner vm os override; see create launcher. |
AIF_RUNNER_VM_RESOURCE_GROUP |
O | "${AIF_PREFIX}esml-common-${AIF_LOCATION_SHORT}-dev${AIF_SCALESET_SUFFIX_DASH}" |
Aif runner vm resource group override; see create launcher. |
AIF_SCALESET_SUFFIX |
O | "001" |
Scale-set number (001-999) |
AIF_SEEDING_KEYVAULT_NAME |
C | "kv${prefix_compact}${AIF_LOCATION_SHORT}${AIF_SCALESET_SUFFIX}" |
Existing seeding Key Vault name |
AIF_SEEDING_MODE |
O | "c" |
Seeding Key Vault: create/ensure (c) or use existing (e); allowed: c e |
AIF_SEEDING_RESOURCE_GROUP |
C | "$AIF_BOOTSTRAP_RESOURCE_GROUP" |
Existing seeding Key Vault resource group |
AIF_SEED_PROJECT_SP |
O | "n" |
Create and seed an optional project automation service principal? (y/N) |
AIF_SETUP_HUB_ACCESS |
O | "y" |
Set up Azure VPN Gateway in the hub and Bastion Developer for DEV? (Y/n) |
AIF_SIMPLE_MODE |
O | "false" |
Opt in to the GHA Dev private foundation contract. |
AIF_SIMPLE_PROJECT_RESOURCES_JSON |
O | "[\"foundry\",\"foundry-capability-host\",\"ai-search\",\"cosmos-db\",\"application-insights\"]" |
Simple-mode JSON resource-ID selection. Required project dependencies cannot be removed; [] removes only optional selections. |
AIF_SP_CLIENT_ID |
C | "" |
Existing service-principal client ID |
AIF_SP_CLIENT_SECRET |
C | "" |
Existing service-principal client secret |
AIF_STAGE_SUBSCRIPTION_ID |
O | "$AIF_DEV_SUBSCRIPTION_ID" |
Aif stage subscription id override; see create launcher. |
AIF_SUBMODULE_BRANCH |
O | "" |
Legacy explicit branch selector consumed by release-version resolution. |
AIF_SUBMODULE_REF |
C | "" |
Exact published commit SHA; required for the simple-mode source verification contract. |
AIF_TEAM_GROUP_ID |
O | "" |
Reuse an existing team group by object ID; otherwise resolve/create from group name. |
AIF_TEAM_GROUP_NAME |
O | "${AIF_PREFIX%-}prj${AIF_PROJECT_NUMBER}-team" |
Entra security group for the initial team |
AIF_TEAM_MEMBER_EMAIL |
M | "$current_user" |
Initial team member |
AIF_TENANT_ID |
M | "$current_tenant" |
Azure tenant ID |
AIF_TOPOLOGY |
O | "s" |
Topology: standalone (s) or hub/spoke with central DNS (hs); allowed: s hs |
AIF_UPDATE_DEFAULT_VERSION |
O | "" |
Optional Update override; omission inherits the installed factory version. |
AIF_VPN_CLIENT_CIDR |
O | "172.31.240.0/24" |
Point-to-site VPN client address pool |
AIF_YES |
O | "false" |
Aif yes override; see create launcher. |
AZURE_DEVOPS_EXT_PAT |
C | "" |
Azure DevOps PAT |
GITHUB_REPOSITORY |
C | "$current_repo" |
GitHub repository (owner/name) |
GITHUB_REPOSITORY_VISIBILITY |
O | "private" |
Simple-mode repository visibility: private or public; independent of Azure networking. |
Configuration helper CLI inputs¶
bootstrap/lib/aifactory_scaleset_config.py is a local configuration API, not an HTTP endpoint. --route, --repo-root, and --state-file are required together for the default write operation. Other switches select independent inspection/validation operations. Unspecified argparse values are null; boolean switches default to false.
| Exact option | M/C/O | Parser default | Meaning / choices |
|---|---|---|---|
--app-gateway-backend-fqdn |
C | "" |
App gateway backend fqdn |
--app-gateway-certificate-secret-id |
C | "" |
App gateway certificate secret id |
--app-gateway-hostname |
C | "" |
App gateway hostname |
--certificate-metadata |
C | null |
Local certificate metadata JSON; validates metadata only, not private key material. |
--enable-application-gateway |
C | null |
Enable application gateway; choices: true, false |
--gateway-health |
C | null |
Local gateway backend-health JSON; exit status indicates health. |
--project-resources |
C | null |
JSON array of simple-mode project resource IDs; required dependencies are retained. |
--repo-root |
C | null |
Consumer root containing the generated .env/YAML/JSON configuration. |
--repository-visibility |
C | "private" |
Repository visibility |
--route |
C | null |
Route; choices: ado, gha |
--simple-gateway-inputs |
C | false |
Validate gateway input strings and print normalized JSON; no deployment. |
--simple-mode-hub-subnets |
C | null |
Validate existing subnet JSON and print reserved simple-mode subnets. |
--simple-mode-manifest |
C | false |
Offline read-only contract/preset preview. |
--simple-project-providers |
C | false |
Simple project providers |
--simple-project-selected |
C | null |
Simple project selected; choices: storage, key-vault, managed-identities, foundry, foundry-capability-host, ai-search, cosmos-db, application-insights, azure-machine-learning, aks-for-azure-ml, aks, databricks, datafactory, event-hubs, postgresql, container-apps |
--state-file |
C | null |
Bootstrap state JSON, not variables.json; consumed by the selected route writer. |
--verify-simple-mode-source |
C | null |
Compare supplied checkout with the required shared source trees. |
Bootstrap state JSON fields¶
These exact fields are consumed by the Python helper's local --state-file API. Normally the shell bootstrap writes this state after resolving identities and scope; it is not the persistent deployment variables.json. C below means required in the named function/route when invoked; O denotes only guarded .get() reads. Missing required keys are not defaulted. project_sp_secret_names contains the nested secret-name keys app_id, object_id, and secret, not secret values.
| Exact state field | M/C/O | Missing-key behavior | Consumer / meaning |
|---|---|---|---|
access_hub_mode |
O | null |
apply_gha, common_values; Access hub mode |
add_bastion |
C | Required lookup | apply_gha, common_values; Add bastion |
admin_group_id |
O | null |
common_values; Admin group id |
admin_member_email |
O | null |
common_values; Admin member email |
admin_vm_size |
O | "Standard_D2s_v5" |
apply_gha, common_values; Admin vm size |
ado_agent_name |
O | "" |
common_values; Ado agent name |
ado_agent_pool |
O | "Default" |
common_values; Ado agent pool |
ado_tenant_id |
C | Required lookup | apply_ado; Ado tenant id |
allow_public_access_behind_vnet |
C | Required lookup | apply_gha, common_values; Allow public access behind vnet |
azure_ml_principal_id |
O | "" |
apply_gha, common_values; Azure ml principal id |
cost_center |
C | Required lookup | common_values; Cost center |
databricks_principal_id |
O | "" |
apply_gha, common_values; Databricks principal id |
dev_service_connection |
C | Required lookup | apply_ado; Dev service connection |
dev_subscription_id |
C | Required lookup | apply_gha, common_values; Dev subscription id |
dev_vnet_cidr |
C | Required lookup | common_values; Dev vnet cidr |
enable_public_genai_access |
C | Required lookup | apply_gha, common_values; Enable public genai access |
enable_public_perimeter |
C | Required lookup | apply_gha, common_values; Enable public perimeter |
github_repository |
C | Required lookup | apply_gha; Github repository |
github_repository_visibility |
O | null |
common_values; Github repository visibility |
github_runner_label |
C | Required lookup | apply_gha; Github runner label |
hub_resource_group |
O | "" |
apply_gha, common_values; Hub resource group |
hub_subscription_id |
O | "" |
apply_gha, common_values; Hub subscription id |
ip_allowlist |
O | "", null |
apply_gha, common_values; Ip allowlist |
location |
C | Required lookup | apply_gha, common_values; Location |
location_short |
C | Required lookup | apply_gha, common_values; Location short |
oidc_client_id |
O | "" |
apply_gha; Oidc client id |
prefix |
C | Required lookup | apply_gha, common_values; Prefix |
prod_service_connection |
C | Required lookup | apply_ado; Prod service connection |
prod_subscription_id |
C | Required lookup | apply_gha, common_values; Prod subscription id |
project_number |
C | Required lookup | apply_gha, common_values, selected_project_organization; Project number |
project_sp_secret_names |
O | null |
apply_gha, common_values; Project sp secret names |
runner_mode |
O | null |
apply_gha, common_values; Runner mode |
runner_vm_os |
O | "windows", "linux" |
apply_gha, common_values; Runner vm os |
scaleset_suffix |
C | Required lookup | apply_gha, common_values; Scaleset suffix |
seeding_keyvault_name |
C | Required lookup | apply_gha, common_values; Seeding keyvault name |
seeding_resource_group |
C | Required lookup | apply_gha, common_values; Seeding resource group |
seeding_subscription_id |
C | Required lookup | apply_gha, common_values; Seeding subscription id |
simple_mode |
O | "false" |
simple_mode_enabled; Simple mode |
simple_project_resources_json |
O | null |
common_values; Simple project resources json |
stage_service_connection |
C | Required lookup | apply_ado; Stage service connection |
stage_subscription_id |
C | Required lookup | apply_gha, common_values; Stage subscription id |
team_group_id |
C | Required lookup | apply_gha, common_values; Team group id |
team_group_name |
C | Required lookup | apply_gha, common_values; Team group name |
team_member_email |
O | null |
apply_gha, common_values; Team member email |
tenant_id |
C | Required lookup | apply_gha, common_values; Tenant id |
topology |
C | Required lookup | apply_gha, common_values; Topology |