• 5 min,  azure

    Associate or add an Azure subscription to your Azure Active Directory tenant

    Add an existing Azure subscription to your tenant – Azure AD – Microsoft Entra | Microsoft Learn An Azure subscription has a trust relationship with Azure Active Directory (Azure AD). A subscription trusts Azure AD to authenticate users, services, and devices. Multiple subscriptions can trust the same Azure AD directory. Each subscription can only trust a single directory.

  • azure

    Azure Pipelines CI/CD TODO

    Azure Pipelines documentation – Azure DevOps | Microsoft Docs What is Azure Pipelines? Azure Pipelines automatically builds and tests code projects to make them available to others. Azure Pipelines combines continuous integration (CI) and continuous delivery (CD) to test and build your code and ship it to any target. Continuous Integration (CI) is the practice used by development teams of automating merging and testing code. Artifacts are produced from CI systems and fed to release processes to drive frequent deployments. Continuous Delivery (CD) is a process by which code is built, tested, and deployed to one or more test and production environments. Continuous Testing (CT) on-premises or in the cloud…

    Comments Off on Azure Pipelines CI/CD TODO
  • azure,  mysql

    Azure for MySql single server (with Zabbix)

    Make ubuntu vm Make Azure for MySql single server Add 2 NSG to the vm Add firwale rules to the MySQL Install and configure Zabbix Connect to MySQL with HeidiSQL Connect Zabbix to MySQL Configure frontend Azure Database for MySQL documentation | Microsoft Docs Note port 3306 vs 3309 for client. If you install Zabbix 6, it needs MySql v8, use port 3309. 3309 Connect to a gateway node to a specific MySQL version Azure Database for MySQL managing updates and upgrades | Microsoft Docs Make Paas Mysql singel server and one Ubuntu vm When you provision the vm, make a public ip for it. (Just for test now) MySql…

    Comments Off on Azure for MySql single server (with Zabbix)
  • 5 min,  azure

    Azure monitor

    Azure Monitor overview – Azure Monitor | Microsoft Docs Must of the resources does not have monitoring enabled by default. Search monitor in Azure. Now lets have a look at Diagnostics settings under monitor Her we see that all is disabled, to enable it diagnostics (log and more), press the resource. If we press the the NSG, we get all available options for diagnistics. Typically if there are issues, we turn on more monitoring and we the issues i solved, we turn off most of the diagnostics logs. They will impact the resource and you need to store the logs also. There are still some monitoring we can check, under…

    Comments Off on Azure monitor
  • 5 min,  azure

    5min Tutorial: Use a Windows VM system-assigned managed identity to access Azure Storage via a SAS credential

    Tutorial`:` Use managed identity to access Azure Storage using SAS credential – Azure AD – Microsoft Entra | Microsoft Docs Create a storage account Grant your VM access to a storage account SAS in Resource Manager Get an access token using your VM’s identity, and use it to retrieve the SAS from Resource Manager Vm is deployed with this script (good to test all ARM templates over and over again) azure-arm-104/deploy_vm.ps1 at master · spawnmarvel/azure-arm-104 · GitHub So the VM is ready We deployed it in a secure extrenal vnet and subnet with its own security group on the subnet. So this bypasses all rules that was deployed automatic in…

    Comments Off on 5min Tutorial: Use a Windows VM system-assigned managed identity to access Azure Storage via a SAS credential
  • 5 min,  azure

    5 min Network watcher

    Start by search “Network watcher” , to get the all the functions IP FLOW Lets test the IP flow for a VM from. There are two IP addresses for cn.bing.com: 202.89. 233.100 and 202.89. 233.101 (from nslookup). For this VM we are using a VNET with a global NSG. Success, and we see what rule it is. Lets remove the Port_80 rule. And the default rule kick’s in, DenyAllInbound Packet Capture Add packet capture The trick is how you filter it.

    Comments Off on 5 min Network watcher
  • 5 min,  azure

    5 Min Azure quickstart github

    All the templates from the repository can be deployd with one click and a small bit of configuration. The configuration is usually for the resource group and name(s) azure-quickstart-templates/quickstarts at master · Azure/azure-quickstart-templates · GitHub If we take a look at microsoft.storage, we see there is a “Deploy to Azure” button. We can test the storage-file-share. After clicking the button it opens up Azure. Now lets deploy it. Click deploy to Azure Make a new rg Choose a region Name the file share At the Azure tab you see that there are 2 resources that will be created. And then, review and create. Deployment succeededDeployment ‘Microsoft.Template-20220809135158’ to resource group ‘test-quickstart’…

    Comments Off on 5 Min Azure quickstart github