This repository bootstraps a secure and scalable Azure environment for Terraform provisioning and future DevOps automation.
- Azure CLI installed (
brew install azure-cli) - Terraform installed
- Logged in to Azure:
az login --all
az account list --output table
az account set --subscription "Microsoft Azure Sponsorship"
az account show --output table
⚠️ If"Microsoft Azure Sponsorship"causes errors, use the primary"Azure subscription 1".
az provider register --namespace Microsoft.Storage
az provider show --namespace Microsoft.Storage --query "registrationState"Wait until status is "Registered".
az group create --name tfstate-rg --location australiaeast
az storage account create --name tfstate88hours1978 --resource-group tfstate-rg --sku Standard_LRS --encryption-services blob --location australiaeast
az storage container create --name tfstate --account-name tfstate88hours1978Note: Storage account name must be lowercase, no hyphens, and globally unique.
az ad sp create-for-rbac --name "terraform-sp" --role="Contributor" --scopes="/subscriptions/<subscription_id>" --sdk-authCopy the returned JSON and extract these fields:
ARM_CLIENT_ID
ARM_CLIENT_SECRET
ARM_SUBSCRIPTION_ID
ARM_TENANT_IDTemporary for session:
set -x ARM_CLIENT_ID "<appId>"
set -x ARM_CLIENT_SECRET "<password>"
set -x ARM_SUBSCRIPTION_ID "<subscriptionId>"
set -x ARM_TENANT_ID "<tenant>"Persistent (add to ~/.config/fish/config.fish):
set -gx ARM_CLIENT_ID "<appId>"
set -gx ARM_CLIENT_SECRET "<password>"
set -gx ARM_SUBSCRIPTION_ID "<subscriptionId>"
set -gx ARM_TENANT_ID "<tenant>"terraform {
backend "azurerm" {
resource_group_name = "tfstate-rg"
storage_account_name = "tfstate88hours1978"
container_name = "tfstate"
key = "terraform.tfstate"
}
}Then initialize:
terraform initprovider "azurerm" {
features {}
}resource "azurerm_management_group" "root_mg" {
display_name = "Root Management Group"
name = "root-mg"
}resource "azurerm_management_group" "prod" {
display_name = "Production"
name = "prod-mg"
parent_management_group_id = azurerm_management_group.root_mg.id
}"## 🔗 Step 8 – Link Subscription to Management Group
Use Terraform to associate your current subscription with a management group.
data \"azurerm_subscription\" \"current\" {}resource \"azurerm_management_group_subscription_association\" \"link\" {
subscription_id = data.azurerm_subscription.current.subscription_id
management_group_id = azurerm_management_group.root_mg.id
}```
## To link to a child group (e.g. prod):
```hcl
management_group_id = azurerm_management_group.prod.id
}```
## 🔍 Helpful CLI Debug/Inspect Commands
```bash
az account list --output table
az account show
az provider list --output table
az provider show --namespace Microsoft.Storage
az provider register --namespace Microsoft.Storage
az group list
az role assignment list --assignee <email>
az ad signed-in-user show- Secure and compliant Terraform backend on Azure
- Service Principal auth for automation
- Management group hierarchy for future governance
- CLI-friendly setup via
fishshell config