Infrastructure as code

Bicep implementation guide

The current template establishes a repeatable starting point and makes the missing security work visible.

Declared resources

  • Virtual network and AppSubnet.
  • Key Vault for protected configuration.
  • Cosmos DB account for structured audit information.
  • Azure OpenAI account with public network access disabled.

Recommended build-out order

Complete private connectivity and DNS, add managed identities and least-privilege roles, configure data and model resources, deploy application workloads, then add monitoring, retention, recovery and policy validation.

Scope

The document explains intended architecture and code. It is not certification or evidence that the environment has been deployed or tested.