Microsoft Azure
Infrastructure as Code — Bicep, ARM & Terraform
Define infrastructure in version control so environments are reproducible and changes are reviewable.
Three options, and Bicep is the current Azure-native answer.
Architectural drawings rather than a building put up from memory. Changes are marked up and approved, and the same plans raise an identical building elsewhere.
Key Concepts
1
ARM templates JSON. Verbose, and what everything compiles to.
Bicep a readable language that transpiles to ARM.
No state file -- Azure holds it.
Terraform multi-cloud, HCL, you own the state file.2
Bicep exists because ARM JSON was painful.
// Bicep
resource sa 'Microsoft.Storage/storageAccounts@2023-01-01' = {
name: storageName
location: location
sku: { name: 'Standard_LRS' }
kind: 'StorageV2'
}3
The ARM JSON equivalent is several times longer, with string-concatenated expressions. Bicep compiles to exactly that, so there is no runtime difference and no lock-in — az bicep decompile goes back.
az bicep decompile
4
What-if shows you the change before you make it.
az deployment group what-if ...5
+ Microsoft.Insights/components/api-insights create
~ Microsoft.Web/sites/api modify
properties.siteConfig.alwaysOn: false -> true
- Microsoft.Sql/servers/db DELETE6
That last line is the one to read. Some property changes force replacement, and for a database that is data loss.
7
Deployment modes are an Azure-specific trap.
Incremental (default) leaves resources not in the template alone
Complete DELETES anything in the resource group that the
template does not declare8
Running Complete mode against a shared resource group removes things nobody intended. It is occasionally what you want, and it should always be deliberate.
9
Modules keep templates manageable, with a registry so teams share versioned building blocks rather than copying.
10
State is where Terraform differs. Azure tracks deployment state for Bicep and ARM; Terraform keeps a state file you must store remotely — a storage account with blob leasing — or two engineers applying at once will corrupt it.
11
Which to choose. Azure only, and you want nothing to manage: Bicep. More than one cloud, or an existing Terraform practice: Terraform. Writing raw ARM JSON by hand is no longer a sensible default.
12
What the interviewer is probing.1. "Bicep or ARM templates?" Probing: what Bicep is. Stalls: "Different products." *Moves
up:* Bicep transpiles to ARM, so there is no runtime difference or lock-in — it exists because ARM
JSON is painful to write and read.
13
2. "What does Complete mode do?" Probing: the Azure-specific hazard. Stalls: "It deploys
everything." Moves up: it deletes anything in the resource group the template does not declare,
which removes resources nobody intended.
14
3. "What do you check in a what-if before approving?" Probing: the dangerous line. Stalls:
"That it looks right." Moves up: anything marked for replacement, since some property changes
destroy and recreate — and for a database that is data loss.
15
4. "Where should Terraform state live on Azure?" Probing: locking. Stalls: "In the repo."
Moves up: a storage account with blob leasing for locking; the file also contains secrets, so it
needs tight access control.