Sets up the following:
- Windows Jumpbox VM
- VM
- OS Disk
- Network Interfaces
- Diagnostics Storage Account
- Public IP Address
- Custom Script Extension to disable IE Enhanced Security Configuration (ESC)
- Diagnostics Extension
- Log Analytics (aka OMS) Extension
- Azure Automation to turn off on schedule (alternative to Schedule which is available in Azure Gov)
- VM
This template only has 1 parameter: namingPrefix. This parameter is used to autogenerate the names of all resources. For example, for namingPrefix of contoso_ will result in contoso_vm_jumpbox and contoso_nic_jumpbox.
All resources are created in the same location as the resource group they are contained in.
-
Create a resource group for your jumpboxes if you don't already have one
az group create -n contoso-jumpboxes -l usgovvirginia -
Deploy the template
az group deployment create -g contoso-jumpboxes -n $(date +%Y%m%d_%H%M%S) --template-file vms-jumpbox-linux/template.json --parameters namingPrefix=linuxjumpbox1 -
Once that completes, you can:
- SSH into the VM
- Got to Log Analytics and see telemetry for this VM
- Use Storage Explorer to query the diagnostics metrics in the diagnostics storage account
- Wait for the automation job to kick in and automatically turn off the VM at the end of the day
- VM Computer Names don't use the prefix given naming constraints.
- VM
storageProfile.osDisk.ostypeis hardcoded due to dependency onosProfile.[windows/linux]Configuration - VM
diagnosticsProfile.bootDiagnostics.storageUriis a reference implemented via thereferencefunction to retreive the storage account'sprimaryEndpoints.blob. - VM is deployed in vnet & subnets that are deployed separately, can be on same or different resource group. Implemented using
resourceId(subscriptionId,resourceGroupName,...). - Extensions in general can be added at the root level or as child resources of VMs, opted for root level to reduce nesting.
- Diagnostics extension gathers logs and sends them to storage account.
- Configuration must include ResourceId.
- According to docs, can use XML but v1.9 assumes JSON, thus went with JSON.
storageAccountEndpointis a reference, don't hardcode it.- v1.11 not available in Gov, had to use v1.9 (see list of extension versions available in Gov)
- Log Analytics (aka OMS) extensions sends logs from Diagnostics extension to Log Analytics.
- Log Analytics deployment is not supported via Azure Resource Manager templates.
- The extension is only deployed if WorkspaceId and WorkspaceKey parameters are provided. Implemented using
condition.
- Custom script extension creates a hello-world file in
/tmp.- Scripts pulled from open URI. Alternatively can use storage account & storage key.
- Add Recovery Services
- Add Alert rules
- Add support for multiple VMs through
copyandcopyIndex()