resource-group
FoundationResource group with region and tags.
Root modules under terraform/modules/azure/ — ARM regions, shared tagging, documented conventions. Browse the catalogue below, open a module page for a deep link, or jump to AWS Terraform modules and GitHub Actions.
Try a different search term or clear the filter.
Baseline identity and resource groups most stacks start from.
Resource group with region and tags.
User-assigned managed identity with tags.
Grant a managed identity Contributor on a resource group and AcrPush on ACR.
Shared environment, apps, jobs, storage mounts, and metric alerts.
Container Apps Environment: shared runtime with Log Analytics integration.
Mount Azure Files storage to the environment (persistent volumes for containers).
Azure Container App: single app with ingress, scaling, container image, and secrets management.
Container Apps Job: cron Schedule or on-demand Manual trigger.
Container App plus built-in alerts in one module (pre-wired monitoring).
Metric alerts for Container App CPU, memory, and requests (Azure Monitor).
ACR and service-principal access for CI/CD.
Azure Container Registry (SKU, optional admin user).
Grant a service principal access to ACR (pull/push for CI/CD).
VNet layout for CAE + PostgreSQL and Azure DNS records.
Virtual network with subnets for Container Apps Environment and PostgreSQL Flexible Server.
Create an Azure DNS zone.
A single CNAME record in an Azure DNS zone.
A single TXT record in an Azure DNS zone (e.g. domain validation).
Multiple TXT and CNAME records in one zone (map-driven for_each).
PostgreSQL Flexible Server, databases, users, and Cosmos DB for MongoDB vCore.
Azure Database for PostgreSQL – Flexible Server (SKU, backup, networking, authentication).
Create a database on an existing PostgreSQL Flexible Server.
Create an application user and password on PostgreSQL (optional random password).
Cosmos DB for MongoDB vCore — cluster and related resources via Azure API.
Redis and Service Bus.
Azure Cache for Redis instance (SKU, capacity, TLS).
Azure Service Bus namespace (SKU; queues and topics).
Key Vault and app registration with RBAC.
Azure Key Vault with network ACLs, access policies or RBAC, optional external secret-sync service principal.
App registration, client secret, service principal, and RBAC role assignments on resource group(s).
Azure AI Services account and OpenAI deployments.
Azure AI Services (AIServices kind) cognitive account with diagnostic settings – AI Foundry workloads.
Azure OpenAI model deployments (models and capacity) within an existing cognitive account.
ACS, Email Communication Service, and custom domains.
Azure Communication Services resource (SMS, voice; optional email domain association).
Azure Email Communication Service – transactional email resource.
Custom sender domain for Email Communication Service (verification, DNS records).
Static Web Apps and custom / apex DNS.
Azure Static Web Apps (SKU, optional basic authentication).
Attach a subdomain or hostname to a Static Web App (CNAME or TXT validation).
Apex (root) domain for Static Web App: custom domain plus DNS TXT validation.
Log Analytics, action groups, dashboards, and workbooks.
Log Analytics workspace for logs and metrics.
Azure Monitor Action Group: route alerts to email and Azure mobile app push notifications.
Azure Portal dashboard with Container App metrics (CPU, memory, requests, logs).
Application Insights workbook with metric views scoped by Container App resource ID.
VM, storage, and Web PubSub.
Linux virtual machine with disk, NIC, SSH key or password-based admin.
Azure Storage account (tier, redundancy, encryption settings).
Azure Web PubSub for real-time WebSocket traffic.