Trust is earned, not given

A different perspective

2025-04-12 · Projects

DotNetCode, part 4: Terraform for a production-shaped Azure site

TerraformAzureSite (part of DotNetCode) contains no C# at all — it is infrastructure as code: Terraform files that build a production-shaped Azure environment. Reading it is the fastest architecture course I can recommend.

What gets built

ComponentFileWhy it is there
Front Door Premium + WAFfrontdoor.tfOWASP managed rules, bot protection, geo rules, HTTPS-only entry; reaches the app over a private endpoint
App Service Premium v3appservice.tfLinux, .NET 10 stack, autoscale 1–5 workers on CPU, staging slot, VNet integration
Azure SQL + geo-replicasql.tfBusiness Critical tier, secondary in another region, auto-failover group; the app connects to the failover listener
Redis (Premium)redis.tfPrivate-endpoint only, TLS
Key Vaultkeyvault.tfPrivate-endpoint only, RBAC; the app's identity gets Key Vault Secrets User
Monitoringmonitoring.tfLog Analytics + Application Insights
Networkingnetworking.tfVNet, subnets, private DNS zones, private endpoints for SQL/Redis/Vault

Three ideas worth stealing

App deployment is deliberately out of scope

The Terraform state holds infrastructure only; the README shows how CI/CD publishes the app separately. Mixing the two makes every code deploy a state mutation — a beginner trap worth avoiding from day one.

Repository: github.com/bobhuang1/DotNetCode/tree/master/TerraformAzureSite