Microsoft Certified: DevOps Engineer Expert flashcards
160 free flashcards. Tap a card to flip it.
Azure Pipelines Self-Hosted Agent
Flip cardAn Azure Pipelines self-hosted agent is software that you install on your own infrastructure (e.g., on-premises VMs, physical servers) to run jobs from Azure Pipelines. It provides the compute capacity for your pipelines and enables deployments to environments not directly accessible by Microsoft-hosted agents.
- Connects securely outbound to Azure DevOps.
- Executes pipeline jobs and deployment tasks.
- Required for deploying to on-premises resources or specific network-restricted environments.
Memory trick: The agent is the messenger between cloud and home.
Canary Deployment
Flip cardA deployment strategy where a new version of an application is released to a small subset of users or servers, monitored for health and performance, and then gradually rolled out to the rest of the infrastructure if successful.
- Minimizes risk by limiting exposure of new code.
- Allows for real-world testing with a small user group.
- Enables quick rollback if issues are detected.
Memory trick: A canary sings softly before the full chorus.
Release Gates
Flip cardRelease gates in Azure DevOps automatically check for health and success criteria from external services before allowing a release to proceed to the next stage or environment.
- Can be configured for pre-deployment or post-deployment stages.
- Continuously monitor conditions and delay deployment until all conditions are met.
- Integrate with various services like Azure Monitor, Work Items, and custom APIs.
Memory trick: Gates guard the path, ensuring all checks pass.
Azure App Service Slot Settings
Flip cardSlot settings (or 'sticky settings') in Azure App Service deployment slots are application settings or connection strings that are specifically tied to a slot and do not swap with the application content when a slot swap occurs. This ensures environment-specific configurations remain in their correct slots.
- Ensures environment-specific configurations persist across swaps.
- Prevents unintended configuration changes in production during deployment.
- Configured in the 'Configuration' section of an App Service slot.
Memory trick: Sticky settings stay put, even when slots swap.
Self-hosted Agent (Azure DevOps)
Flip cardAn agent that you set up and manage on your own infrastructure (on-premises or in cloud VMs) to run build and deployment jobs in Azure DevOps.
- Provides full control over dependencies, software, and network access.
- Required for deploying to on-premises environments or custom cloud setups.
- Reduces build/release times by pre-installing necessary tools.
Memory trick: If it's 'your house', you need a 'self-hosted' agent.
Azure Resource Manager Service Connection
Flip cardAn Azure Resource Manager service connection in Azure DevOps establishes a secure link between your Azure DevOps organization and an Azure subscription. It uses a Service Principal to authenticate and authorize Azure DevOps pipelines to deploy and manage resources within that subscription.
- Essential for deploying to Azure services like AKS, App Service, VMs.
- Uses Service Principal for secure, role-based access.
- Supports various authentication methods (e.g., automated, manual).
Memory trick: ARM is the key to unlock Azure's door.
Stage-Specific Approvals/Gates
Flip cardIn Azure DevOps release pipelines, pre-deployment and post-deployment approvals and gates can be configured for individual stages. This allows for fine-grained control over deployments, enabling specific manual sign-offs and automated health checks before or after a stage's execution.
- Enables granular control for multi-environment or multi-region deployments.
- Supports sequential execution with checks at each step.
- Essential for implementing complex release strategies with compliance and quality checks.
Memory trick: Each region has its own gatekeeper and health checks.
YAML Pipeline Versioning & Backup
Flip cardYAML-based Azure Pipelines definitions are stored as files within a Git repository. This inherently provides version control, audit trails, and a robust backup mechanism by leveraging the Git repository's capabilities, allowing for easy restoration and management of pipeline definitions.
- YAML pipelines are code, managed like application code in Git.
- Version control (Git) provides history, branching, and restore points.
- Backup of the Git repository implicitly backs up pipeline definitions.
Memory trick: YAML lives in Git, making recovery a simple commit.
Release Pipeline History
Flip cardThe Release Pipeline History in Azure DevOps provides an audit trail of all modifications made to a release pipeline's definition, including details on the change, the user who made it, and the timestamp. It also enables reverting to prior versions.
- Logs all definition changes (who, what, when).
- Supports compliance and auditing requirements.
- Allows reverting to any previous version of the pipeline definition.
Memory trick: History remembers all, and allows going back.
Post-deployment Gates (Azure DevOps)
Flip cardPost-deployment gates in Azure DevOps are automated health and quality checks that run continuously after a stage completes successfully. They ensure that the application remains stable and healthy in that environment for a specified duration before the release can proceed to the next stage.
- Monitors external services (e.g., Azure Monitor, Work Items, custom APIs).
- Delays progression to the next stage until conditions are met.
- Crucial for ensuring the stability of deployments across environments.
Memory trick: Post-gates guard the next step, ensuring the current is sound.
Release Triggers (Azure DevOps)
Flip cardMechanisms in Azure DevOps release pipelines that define when a new release should be created and deployed to a specific stage.
- Continuous deployment triggers automatically start a release upon a successful build.
- Scheduled release triggers start releases at specific times.
- Manual only triggers require explicit human initiation.
Memory trick: Dev is automatic, Staging/Prod needs a human touch.
Task Group
Flip cardA Task Group in Azure DevOps is a sequence of tasks that can be encapsulated into a single reusable task in a build or release pipeline. It helps in standardizing and centralizing common deployment or build logic.
- Increases reusability and maintainability of pipelines.
- Ensures consistency across multiple pipelines.
- Can be versioned and managed like other pipeline components.
Memory trick: Tasks grouped together make a powerful, reusable unit.
Pre/Post-Deployment Gates
Flip cardAutomated validations or manual approvals that run before or after a stage in an Azure DevOps release pipeline, controlling the flow of releases.
- Pre-deployment gates/approvals run before a stage starts.
- Post-deployment gates/approvals run after a stage completes.
- Can integrate with external systems for automated checks or trigger actions.
Memory trick: Approve BEFORE, alert AFTER if it fails.
Error Budget Calculation (Availability)
Flip cardThe maximum allowable time a service can be unavailable or perform poorly while still meeting its Service Level Objective (SLO).
- Calculated as (100% - SLO%) * total time in period.
- Exceeding the error budget indicates a failure to meet the SLO.
- Helps balance reliability and innovation.
Memory trick: Error Budget: 'SLO, time, then compare.'
Cosmos DB Multi-Region Writes (Strong Consistency)
Flip cardA configuration in Azure Cosmos DB where a database account is deployed across multiple Azure regions, allowing write operations to be performed in any region. When combined with Strong consistency, writes are synchronously committed to all regions before acknowledgment, ensuring near-zero RPO.
- Provides global distribution with highest consistency guarantees.
- Achieves RPO as close to zero as possible.
- Writes are synchronous across all regions.
- May introduce higher write latency due to cross-region synchronization.
Memory trick: Cosmos DB RPO: 'Multi-region writes, strong consistency, zero tears.'
DR Strategy: Pilot Light
Flip cardA disaster recovery strategy where a minimal version of the application is continuously running in a secondary region, with data replicated asynchronously. In a disaster, the full application stack is provisioned and scaled up.
- Achieves RPOs of minutes to hours.
- Achieves RTOs of minutes to hours.
- Lower cost than Warm/Hot Standby but higher than Backup/Restore.
- Requires some pre-provisioned infrastructure in the DR region.
Memory trick: RPO/RTO: 'Cold, Pilot, Warm, Hot – pick your speed!'
Percentile-based SLO and Alerting
Flip cardDefining Service Level Objectives (SLOs) and corresponding alerts based on percentiles (e.g., 99th percentile) ensures that a certain percentage of user requests meet a performance target, providing a better measure of user experience than simple averages.
- Percentiles are robust against outliers.
- Directly reflects user experience for a segment of users.
- Alerts should mirror the SLO's percentile definition.
- Commonly used for latency and throughput SLOs.
Memory trick: SLO percentile: 'Alert on the P, not the A.'
Retry with Exponential Backoff
Flip cardA transient fault-handling design pattern where an application automatically retries a failed operation, increasing the wait time between retries exponentially. This reduces the load on a busy service and allows it time to recover.
- Effective for transient errors (network, temporary service unavailability).
- Prevents overwhelming a recovering service.
- Often combined with a maximum number of retries or a circuit breaker.
- Wait time = base * (2^attempt) + random jitter.
Memory trick: Transient errors: 'Retry and wait, don't overwhelm the gate!'
Post-Incident Review (PIR)
Flip cardA blameless process conducted after a significant incident to understand its causes, effects, and to identify actionable improvements that can prevent recurrence and reduce future Mean Time To Recovery (MTTR).
- Focuses on learning, not blaming.
- Identifies root causes, contributing factors, and systemic weaknesses.
- Generates actionable improvement items.
- Directly contributes to lower MTTR and increased system resilience.
Memory trick: Reduce MTTR: 'Review, Learn, Improve, Repeat!'
DR Strategy: Active-Active
Flip cardA disaster recovery strategy where the application is fully deployed and actively serving traffic from multiple, geographically separated regions simultaneously. Traffic is distributed across all active regions, and failover is typically instantaneous.
- Provides the highest level of availability and lowest RTO/RPO.
- Often uses global load balancers (like Azure Front Door) for traffic management.
- Requires real-time or near real-time data synchronization.
- Most complex and expensive to implement.
Memory trick: Continuous Availability: 'Front Door to Active-Active, always on!'
Azure SQL Failover Groups
Flip cardA feature of Azure SQL Database and SQL Managed Instance that manages replication and failover of a group of databases to a secondary region, providing automatic failover capabilities and a single endpoint for application connectivity.
- Leverages Active Geo-Replication for data synchronization.
- Supports RPO in minutes (asynchronous) or seconds (synchronous, cross-zone for Hyperscale).
- Automates failover to a secondary region, reducing RTO.
- Provides a read-write and an optional read-only listener endpoint for applications.
Memory trick: SQL DR: 'Backups for slow, Geo for fast, Failover for auto-blast!'
Circuit Breaker Pattern
Flip cardA design pattern used in distributed systems to prevent an application from repeatedly trying to invoke a service that is likely to fail, thus preventing cascading failures and allowing the failing service to recover.
- Has three states: Closed, Open, Half-Open.
- Opens when failures or timeouts exceed a threshold.
- Prevents unnecessary requests to a failing dependency.
- Often combined with the Retry pattern.
Memory trick: Cascading Failures: 'Break the circuit, save the system.'
Distributed Tracing (APM)
Flip cardA technique used in Application Performance Monitoring (APM) to track requests as they flow through multiple services and components in a distributed system, providing an end-to-end view of transaction execution.
- Helps identify latency bottlenecks and error origins.
- Crucial for microservices architectures.
- Provides a call graph or waterfall diagram of a request's journey.
- Often implemented with OpenTelemetry or similar standards.
Memory trick: Intermittent bugs: 'Trace the path, see the flow.'
Proactive SLO-aligned Alerting
Flip cardSetting up monitoring and alerts that track Service Level Indicators (SLIs) in a way that provides early warning of potential SLO breaches, often by alerting on a slightly less stringent threshold or a lower percentile than the SLO itself.
- Aims to detect degradation before users are significantly impacted.
- Often involves monitoring percentiles (e.g., 99th percentile for a 99.9% SLO).
- Allows for intervention before an error budget is consumed too quickly.
- Requires careful selection of SLIs and thresholds.
Memory trick: Proactive SLO: 'Alert early, save the budget.'
Service Level Indicator (SLI)
Flip cardA carefully defined, quantifiable measure of some aspect of the level of service that is provided.
- Directly measures user experience or service health.
- Must be measurable and actionable.
- Examples: request latency, error rate, throughput, availability.
Memory trick: SLI: 'User's view, success, direct link.'
Azure Key Vault
Flip cardA cloud service for securely storing and accessing secrets. A secret is anything you want to tightly control access to, such as API keys, passwords, certificates, or cryptographic keys. Key Vault helps you safeguard cryptographic keys and other secrets used by cloud applications and services.
- Centralized secure storage for secrets, keys, certificates.
- Reduces risk of hardcoding sensitive information.
- Integrates with Azure services like App Service, Azure DevOps, and Managed Identities.
Memory trick: Key Vault keeps my secrets safe, like a digital safe.
Azure Monitor Custom Metrics
Flip cardA feature of Azure Monitor that allows applications to send custom, application-specific metrics for monitoring, visualization, and alerting alongside platform metrics. These metrics can be numerical values representing any aspect of an application's behavior or performance.
- Enables collection of application-specific data points.
- Integrates with Azure Monitor for dashboards and alerts.
- Supports various ingestion methods like Application Insights SDK or REST API.
Memory trick: My App's Custom Stats go straight to Monitor's Metrics.
Azure Monitor for Containers
Flip cardA feature of Azure Monitor that provides comprehensive monitoring for Azure Kubernetes Service (AKS) and other containerized workloads.
- Collects performance metrics for nodes, pods, and containers.
- Aggregates container logs into Log Analytics.
- Provides live data view and supports custom metrics.
Memory trick: For containers, Container Insights is the clear choice.
Azure Monitor Agent (AMA)
Flip cardThe unified agent for Azure Monitor that collects telemetry from Azure and hybrid machines, configured via Data Collection Rules (DCRs).
- Replaces legacy Log Analytics agent (MMA) and Azure Diagnostics Extension.
- Uses Data Collection Rules (DCRs) for granular configuration.
- Supports custom text logs, syslog, performance counters, and event logs.
Memory trick: AMA and DCRs: The modern way to collect VM logs.
Application Insights Application Map
Flip cardA visual tool within Application Insights that automatically maps the topology of a distributed application, showing components, dependencies, and performance metrics.
- Provides a graphical representation of service interactions.
- Highlights performance bottlenecks and failures.
- Automatically discovers components instrumented with Application Insights.
Memory trick: Application Map for the 'whole picture' of your app's journey.
Azure Monitor Workbook Parameters
Flip cardDynamic values within Azure Monitor Workbooks that allow users to interact with and customize reports, filtering data and controlling visualizations.
- Enable interactive filtering, time range selection, and resource selection.
- Can be used in queries, text, and other workbook elements.
- Key to creating flexible and reusable monitoring dashboards.
Memory trick: Parameters make your workbook smart and responsive.
Azure Application Insights
Flip cardAn Application Performance Management (APM) service that monitors live web applications, providing insights into performance, availability, and usage.
- Collects performance metrics, logs, and distributed traces.
- Supports various programming languages and platforms.
- Offers real-time diagnostics and alerting.
Memory trick: App Insights: Your app's health, traced and true.
Azure Activity Log Alerts
Flip cardA type of alert in Azure Monitor that notifies you when a specific event occurs in your Azure subscription's Activity Log. These events include resource creation, updates, deletion, and other administrative actions.
- Monitors control-plane operations (e.g., PUT, POST, DELETE).
- Crucial for security, compliance, and operational auditing.
- Can trigger Action Groups for various notification types.
Memory trick: Activity Log Alerts are the 'A' in 'AUDIT' for Azure changes.
Azure Monitor for Networks
Flip cardA comprehensive solution within Azure Monitor that provides centralized monitoring and diagnostics for all Azure networking products and their dependencies. It includes pre-built workbooks, topology maps, and health views.
- Monitors Azure Front Door, VPN Gateways, Traffic Manager, ExpressRoute.
- Collects performance metrics, health, and diagnostics logs (e.g., WAF logs).
- Integrates with Log Analytics for advanced querying and visualization.
Memory trick: Networks' health and WAF logs are seen with Monitor for Networks.
Application Insights Distributed Tracing
Flip cardA feature of Application Insights that visualizes the end-to-end flow of requests across different components and services in a distributed application.
- Automatically correlates telemetry data (requests, dependencies, logs).
- Provides a 'transaction search' and 'application map' for visualization.
- Supports various Azure services and SDKs for instrumentation.
Memory trick: Application Insights traces the journey of every request.
Azure Monitor for Containers & Log Analytics
Flip cardAzure Monitor for Containers provides rich monitoring experiences for AKS. It collects performance metrics, inventory data, and health status from container hosts and containers. This data is stored in a Log Analytics workspace, enabling powerful Kusto queries, visualizations, and alerts.
- Collects logs from all Kubernetes components (pods, nodes, controllers).
- Log Analytics offers centralized storage, KQL querying, and retention.
- Provides pre-built dashboards and insights for AKS health and performance.
Memory trick: Containers' chaos is calmed by Monitor's logs in Analytics' lake.
Azure Monitor Workbooks
Flip cardInteractive canvas reports that combine text, analytics queries, metrics, and parameters into rich, flexible, and customizable dashboards. They can be used for operational troubleshooting, root cause analysis, and creating detailed monitoring views.
- Combine multiple data sources (logs, metrics, resource health).
- Support interactive parameters and rich visualizations.
- Excellent for complex, cross-resource monitoring and troubleshooting.
Memory trick: Workbooks are the 'W' in 'WISDOM' for interactive insights.
Application Insights for Azure Functions
Flip cardA feature of Azure Monitor that provides comprehensive performance monitoring and diagnostics for Azure Functions. It automatically collects logs, traces, metrics, and dependency data, centralizing it for analysis.
- Automatic instrumentation for Azure Functions.
- Captures invocation details, exceptions, dependencies.
- Integrates with Log Analytics for powerful querying.
Memory trick: Functions' Fails and Flows go to Insights for forensic finds.
Azure Monitor Action Groups
Flip cardA collection of notification preferences and actions that can be triggered by an Azure alert, enabling automated responses and integrations.
- Reusable across multiple alert rules.
- Supports various actions: email, SMS, push notifications, webhooks, ITSM, runbooks, functions.
- Centralized management of alert responses.
Memory trick: Action Groups: The 'what to do' when an alert screams.
Azure Monitor Metric Alerts
Flip cardAlert rules that trigger when a numeric metric value crosses a specified threshold, based on various aggregations and time granularities.
- Used for performance and availability monitoring.
- Evaluates data from Azure Monitor Metrics.
- Supports various action types via action groups (email, SMS, webhooks, Teams, etc.).
Memory trick: Metrics for performance, logs for deep dive, activity for resource changes.
Azure Monitor Log Analytics
Flip cardA service within Azure Monitor that collects and analyzes telemetry data from various sources, enabling powerful querying and visualization.
- Centralized repository for logs and metrics.
- Uses Kusto Query Language (KQL) for data exploration.
- Integrates with other Azure services for comprehensive monitoring.
Memory trick: Log Analytics is the hub for all your log data.
Log Analytics Workspace for Diagnostics
Flip cardA centralized log repository in Azure Monitor that collects diagnostic and performance data from various Azure resources, enabling powerful analysis and long-term retention.
- Scalable for high volumes of log data.
- Offers flexible data retention policies (up to 730 days).
- Supports Kusto Query Language (KQL) for complex queries.
Memory trick: Log Analytics: Store, Query, Analyze, Repeat.
Learning from Failures (SRE)
Flip cardA core SRE principle emphasizing thorough, blameless post-incident reviews to understand systemic weaknesses and implement improvements, rather than assigning blame.
- PIRs are blameless.
- Focuses on identifying systemic issues and contributing factors.
- Aims to generate actionable items for improvement.
Memory trick: After the fire, learn the lessons, avoid the blame game.
Availability Calculation
Flip cardThe process of determining the maximum permissible downtime or the expected uptime based on a Service Level Objective (SLO) for availability.
- Availability % = (Total Time - Downtime) / Total Time * 100.
- Error Budget % = 100% - Availability %.
- Downtime = Total Time * Error Budget %.
Memory trick: Turn the percentage into a fraction, then multiply by total time.
Active-Active (Hot Standby) DR
Flip cardA disaster recovery strategy where identical, fully provisioned application instances run simultaneously in multiple regions, ready to handle traffic immediately.
- Offers the lowest RTO and RPO (seconds/minutes).
- Highest cost due to duplicate infrastructure.
- Can distribute live traffic across regions for load balancing and redundancy.
Memory trick: DR Strategies: How fast can you get back online and how much data can you lose?
Queue-Based Load Leveling
Flip cardAn architectural pattern that uses a message queue as a buffer between service components to smooth out intermittent heavy loads and prevent downstream services from being overwhelmed.
- Decouples producers from consumers.
- Provides resilience by buffering messages during transient failures.
- Manages spikes in demand, preventing resource exhaustion.
Memory trick: Queue-Based Load Leveling: A queue to smooth out the waves of requests.
Error Budget Burn Rate Alerting
Flip cardA proactive alerting strategy that triggers when the rate of error consumption exceeds a predefined threshold, indicating that the service is on track to exhaust its error budget and potentially breach its SLO.
- Provides early warning before an SLO is breached.
- Calculates how fast the 'allowed' errors are being used up.
- Helps teams prioritize and take corrective action proactively.
Memory trick: Don't just watch the fence, watch how fast the budget burns!
Pilot Light DR Strategy
Flip cardA disaster recovery strategy where a minimal, critical set of resources and continuously replicated data are maintained in a secondary region, ready to be fully provisioned and scaled up upon disaster.
- Balances cost and RTO/RPO.
- Core infrastructure always running, compute provisioned on demand.
- Faster recovery than Backup & Restore, slower than Warm/Hot Standby.
Memory trick: Pilot Light keeps the engine warm, ready for takeoff, but not full speed.
Proactive Alerting
Flip cardAn alerting strategy focused on detecting early warning signs of impending issues or SLO breaches, allowing teams to intervene before user impact or full system failure.
- Uses predictive indicators (e.g., burn rate, anomalies).
- Aims to notify before an SLO is formally breached.
- Reduces Mean Time To Detect (MTTD) and Mean Time To Respond (MTTR).
Memory trick: Don't just watch the fire, smell the smoke from afar.
Kubernetes Readiness Probe
Flip cardA mechanism in Kubernetes to determine if a container is ready to serve requests. If it fails, the pod is removed from service load balancing.
- Ensures traffic is only sent to healthy instances.
- Can be HTTP, TCP, or command-based.
- Prevents traffic from being routed to a pod that is still initializing or temporarily unhealthy.
Memory trick: Probes: Kubernetes' way of checking if your app is alive, ready, or just starting up.
Distributed Tracing
Flip cardAn observability technique used to monitor requests as they propagate through multiple services in a distributed system, providing end-to-end visibility of transaction flow.
- Tracks a single request across service boundaries.
- Helps identify latency and errors in microservices.
- Often implemented with OpenTelemetry or similar standards.
Memory trick: For microservices, you need a tracing thread to follow the path.
Percentile-based SLI
Flip cardA Service Level Indicator (SLI) that measures the percentage of requests or operations that complete within a specific time threshold, often used to capture user experience variations.
- Captures tail latency issues.
- Commonly expressed as 'X% of requests complete within Y milliseconds'.
- Directly aligns with user experience expectations.
Memory trick: Percentiles paint the truest picture of user experience.
Error Budget Calculation
Flip cardThe maximum amount of time a system can be unavailable or perform poorly without violating its Service Level Objective (SLO).
- Calculated as (100% - SLO%) * total period duration.
- Represents the acceptable amount of 'bad' performance or downtime.
- Consumed when the service deviates from its SLO.
Memory trick: Error Budget: It's your 'downtime allowance' for the month.
Active-Active DR (Hot Standby)
Flip cardA disaster recovery strategy where full, identical application environments run simultaneously in multiple regions, distributing live traffic and providing immediate failover capabilities.
- Achieves near-zero RTO and RPO.
- Highest cost due to duplicate active infrastructure.
- Requires global load balancing (e.g., Azure Front Door, Traffic Manager).
Memory trick: Active-Active regions keep traffic flowing without a single hiccup.
Warm Standby DR
Flip cardA disaster recovery strategy where a scaled-down, but fully functional, duplicate environment is maintained in a secondary region, ready to be scaled up and take over production traffic.
- Balances RTO/RPO with cost.
- Faster recovery than Pilot Light or Backup & Restore.
- Requires continuous replication of data.
Memory trick: Recovering from disaster, each strategy offers a different speed and price.
Static Application Security Testing (SAST)
Flip cardA white-box testing method that analyzes an application's source code, bytecode, or binary code for security vulnerabilities without executing the application.
- Performed early in the SDLC (Shift Left).
- Identifies vulnerabilities like SQL injection, XSS, buffer overflows.
- Does not require a running application.
Memory trick: Code security: Scan early, scan often, scan for everything!
Azure DevOps Environment Approvals
Flip cardA feature in Azure DevOps that enforces manual or automated checks and approvals on an environment before a stage targeting that environment can be executed in a pipeline.
- Can be configured for pre-deployment or post-deployment checks.
- Supports manual approvals from specified users or groups.
- Provides an auditable record of approvals within the pipeline run.
Memory trick: Environments are the Checkpoints for your Pipeline's Journey!
Azure Functions VNet Integration
Flip cardEnabling an Azure Function app to access resources within or connected to an Azure Virtual Network (VNet).
- Allows outbound traffic from Function to VNet resources.
- Supports both VNet-restricted resources and private endpoints.
- Function itself remains publicly accessible by default (inbound).
Memory trick: Functions need VNet integration to 'walk' inside the network and reach restricted doors.
Azure Policy DeployIfNotExists
Flip cardAn Azure Policy effect that audits for compliant resources and automatically deploys a specified resource if the condition is met and the resource does not exist.
- Ideal for enforcing baseline configurations like VNet peerings or diagnostic settings.
- Runs after a resource is created or updated.
- Can be used to add missing components or settings to resources.
Memory trick: Policy is the Auto-Pilot for Network Compliance, Deploying what's Missing!
Azure Private Link / Private Endpoints for PaaS
Flip cardA service that enables you to access Azure PaaS services (like App Service, Storage, Key Vault) over a private endpoint in your virtual network, bringing the service into your VNet and removing public internet access.
- Secures connectivity to PaaS services.
- Traffic travels over Microsoft's backbone network, not public internet.
- Enables private IP access for PaaS services, blocking public access.
Memory trick: Private Link 'Brings the Cloud Inside', keeping it off the public 'Street'.