Is it possible to create resources in azure in multiple subscriptions using single pipeline?

Viewed 60

I have a requirement to create resources based on the text file uploaded to the azure devops repos by my client. My client wants to keep it minimal and need only one file to be updated and single pipeline to deploy resources to multiple subscriptions (dev, test, prod).

Text file preview

enter image description here

I am able to read this file and create resources using powershell (using loop) in single subscription. I am not sure how to create single pipeline to read this file and create resources in multiple subscriptions.

Note: TargetSubscription is a service connection.

Is it possible? If yes, what is the best way to achieve this?

Any help would be appreciated. Thanks in advance!

1 Answers

If TargetSubscription is a service connection, I assume each service connection has necessary access in the relevant Subscription. Since you already said you have a PowerShell code, you can use Connect-AzAccount for every new service connection:

$SecureStringPwd = $sp.PasswordCredentials.SecretText | ConvertTo-SecureString -AsPlainText -Force
$pscredential = New-Object -TypeName System.Management.Automation.PSCredential -ArgumentList $sp.AppId, $SecureStringPwd
Connect-AzAccount -ServicePrincipal -Credential $pscredential -Tenant $tenantId

Azure Docs link: https://docs.microsoft.com/en-us/powershell/azure/authenticate-azureps?view=azps-8.1.0#password-based-authentication

Your Azure DevOps service connections need to have a relevant service principal in Azure side. If that service principal has permission to deploy resources (for example, Contributor RBAC on subscription), you can create your resources in that Subscription after you sign in with it.

Call the Connect-AzAccount every time you read a new Service Connection from the text file, and then the remaining of your script will run to create resources. Your sign in session should only see that specific Subscription.

You can create client secret on Azure side for each service principal. Then you can put this secret into Key Vault, get the value securely from Key Vault in your script and pass it as a parameter to $SecureStringPwd, as displayed above.

Related