DotNetCode, part 4: Terraform for a production-shaped Azure site
TerraformAzureSite (part of DotNetCode) contains no C# at all — it is infrastructure as code: Terraform files that build a production-shaped Azure environment. Reading it is the fastest architecture course I can recommend.
What gets built
| Component | File | Why it is there |
|---|---|---|
| Front Door Premium + WAF | frontdoor.tf | OWASP managed rules, bot protection, geo rules, HTTPS-only entry; reaches the app over a private endpoint |
| App Service Premium v3 | appservice.tf | Linux, .NET 10 stack, autoscale 1–5 workers on CPU, staging slot, VNet integration |
| Azure SQL + geo-replica | sql.tf | Business Critical tier, secondary in another region, auto-failover group; the app connects to the failover listener |
| Redis (Premium) | redis.tf | Private-endpoint only, TLS |
| Key Vault | keyvault.tf | Private-endpoint only, RBAC; the app's identity gets Key Vault Secrets User |
| Monitoring | monitoring.tf | Log Analytics + Application Insights |
| Networking | networking.tf | VNet, subnets, private DNS zones, private endpoints for SQL/Redis/Vault |
Three ideas worth stealing
- Private by default. SQL, Redis and Key Vault have no public reachability — only the VNet's private endpoints. The blast radius of a misconfigured firewall is zero because there is no public surface.
- Identity instead of secrets-in-config. The app gets a system-assigned managed identity; the database grants it access; secrets come from Key Vault via RBAC. No connection strings with passwords in app settings.
- Failover is a connection-string detail. The app points at the auto-failover listener, so a region failure is a DNS switch the driver follows — no redeploy.
App deployment is deliberately out of scope
The Terraform state holds infrastructure only; the README shows how CI/CD publishes the app separately. Mixing the two makes every code deploy a state mutation — a beginner trap worth avoiding from day one.
Repository: github.com/bobhuang1/DotNetCode/tree/master/TerraformAzureSite