Microsoft Azure

Infrastructure as Code — Bicep, ARM & Terraform

Define infrastructure in version control so environments are reproducible and changes are reviewable.

Three options, and Bicep is the current Azure-native answer.

Architectural drawings rather than a building put up from memory. Changes are marked up and approved, and the same plans raise an identical building elsewhere.

Key Concepts

1
    ARM templates  JSON. Verbose, and what everything compiles to.
    Bicep          a readable language that transpiles to ARM.
                   No state file -- Azure holds it.
    Terraform      multi-cloud, HCL, you own the state file.
2
Bicep exists because ARM JSON was painful.
    // Bicep
    resource sa 'Microsoft.Storage/storageAccounts@2023-01-01' = {
      name: storageName
      location: location
      sku: { name: 'Standard_LRS' }
      kind: 'StorageV2'
    }
3
The ARM JSON equivalent is several times longer, with string-concatenated expressions. Bicep compiles to exactly that, so there is no runtime difference and no lock-in — az bicep decompile goes back.
az bicep decompile
4
What-if shows you the change before you make it.
    az deployment group what-if ...
5
    + Microsoft.Insights/components/api-insights   create
    ~ Microsoft.Web/sites/api                      modify
        properties.siteConfig.alwaysOn: false -> true
    - Microsoft.Sql/servers/db                     DELETE
6
That last line is the one to read. Some property changes force replacement, and for a database that is data loss.
7
Deployment modes are an Azure-specific trap.
    Incremental  (default) leaves resources not in the template alone
    Complete     DELETES anything in the resource group that the
                 template does not declare
8
Running Complete mode against a shared resource group removes things nobody intended. It is occasionally what you want, and it should always be deliberate.
9
Modules keep templates manageable, with a registry so teams share versioned building blocks rather than copying.
10
State is where Terraform differs. Azure tracks deployment state for Bicep and ARM; Terraform keeps a state file you must store remotely — a storage account with blob leasing — or two engineers applying at once will corrupt it.
11
Which to choose. Azure only, and you want nothing to manage: Bicep. More than one cloud, or an existing Terraform practice: Terraform. Writing raw ARM JSON by hand is no longer a sensible default.
12
What the interviewer is probing.1. "Bicep or ARM templates?" Probing: what Bicep is. Stalls: "Different products." *Moves up:* Bicep transpiles to ARM, so there is no runtime difference or lock-in — it exists because ARM JSON is painful to write and read.
13
2. "What does Complete mode do?" Probing: the Azure-specific hazard. Stalls: "It deploys everything." Moves up: it deletes anything in the resource group the template does not declare, which removes resources nobody intended.
14
3. "What do you check in a what-if before approving?" Probing: the dangerous line. Stalls: "That it looks right." Moves up: anything marked for replacement, since some property changes destroy and recreate — and for a database that is data loss.
15
4. "Where should Terraform state live on Azure?" Probing: locking. Stalls: "In the repo." Moves up: a storage account with blob leasing for locking; the file also contains secrets, so it needs tight access control.