Release to Azure With Azure ARM Templates
Learn how to start using Azure with Azure ARM Templates for DevOps and automated continuous deployment.
Join the DZone community and get the full member experience.Join For Free
thanks to the new release management system in vsts/tfs, creating a release to your on-premise environment is really simple.
in this example i’m using azure as iaas, deploying a software on a windows virtual machine. while this is probably not the best approach to cloud (paas is surely a better approach), to create a test environment it can be perfectly acceptable.
i’m not going to give you an introduction or explanation of azure resource manager because there are tons of resources on the web, and azure moves so quickly that the info i’d give you would probably be old by the time i press "publish." the purpose of this post is giving you a general idea on how to use azure arm to create a release definition that automatically generates the resource in azure and deploys your software on it.
my goal is using azure arm for devops and automatic / continuous deployment and the first step is creating a template file that describes exactly all the azure resource needed to host my application. instead of starting to write such template file i start checking on github because there are tons of template files s ready to use.
as an example, i took one of the simplest, called 101-vm-simple-windows. it creates a simple windows virtual machine and nothing else. that template has various parameters that can allow you to specify vm names and other properties, and it can be directly used by a release management definition. i’ve done simple modifications to the template file and, in this situation, it is better to first check if everything is working as expected, triggering the deploy process directly from command line.
new-azurermresourcegroupdeployment -name jarvisrm -resourcegroupname jarvisrm -templatefile "azuredeploy.json" -adminusername alkampfer -adminpassword ********** -vmname jarviscmtest -storageaccount jarvisrmstorage -dnslabelprefix jarvisrm
as you can see, i need to choose the name of the resource group (jarvisrm), specify the template file (azuredeploy.json), and finally set all the parameters of the template as if they are parameters of the powershell cmdlet. once the script has finished, verify that the resource group was created correctly and all the resources are suitable to deploy your software.
figure 1: your resource group was correctly created.
once everything is correct, i deleted the jarvisrm resource group, and i’m ready to use the template on a release definition.
always test your arm template directly from command line to verify that everything is all right. when the resources are created, try to use them as a manual target of a deploy and only once everything is ok, start automating with release management.
when you have a good template file, the best place to store it is in your source control, this allows you to version this file along with the version of the code that is supposed to use it. if you do not need versioning, you can simply store it in a network share, but to avoid problems, it is better to have release management agent run the template from a local disk and not from a network share.
figure 2: copy template file from a network share to a local folder of the agent.
the first step of the release process is copying template files from a network share to the $(system.defaultworkingdirectory)\arm folder so powershell can run against scripts that are placed on local disk. the second task is azure resource group deployment that uses the template to deploy all resources to azure.
figure 3: the azure deployment task is used to create a resource group from a template definition.
you should only specify the template file and the parameters of the template, such as username, password, dns name of the vm, etc. as a nice option, you can choose to enable deployment prerequisites to have your vm be able to be used as a target for deploy action. you can read more about prerequisites on the msdn blog . basically, when you select this action, the script will configure powershell and other options on the target machine to be able to execute the script remotely.
virtual machines need to be configured to be used as the targets of deploy tasks, such as remote powershell execution, but the azure deployment task can take care of everything for you.
this task requires that you already connected the target azure subscription with your vsts account. if you never connected your tfs/vsts account to your azure subscription with arm, you can follow the instruction at this link , that contains a powershell script that does everything for you. just run the script and annotate all the data you should insert to your tfs/vsts instance to connect to azure with arm in a safe place .
another aspect you need to take care of is the version of powershell azure tools installed in the machine where the release agent is running. release management scripts are tested against specific versions of azure powershell tools, and because the azure team is constantly upgrading the tools, it could happen that tfs/vsts release management tasks are not compatible with the latest version of the azure tools.
all of these tasks are open sourced, and you can find information directly on github. as an example, at this link there is information about the deployazureresourcegroup task . if you go to the bottom, you can verify the powershell tools version suggested to run that task.
figure 4: supported version of azurerm module version.
clearly, you should install a compatible version in the machine where the agent is installed. if you are unsure if the agents have a suitable version of azure powershell tools, you can go to the tfs admin page and verify the capabilities of the agent directly from vsts/tfs.
figure 5: agent capabilities contains the version of azure powershell tools installed.
demand for azure ps is present on release definition, but it does not specify the version, so it is not guaranteed that your release is going to be successful.
figure 5: release process has a demand for azure powershell tools but not to a specific version.
as a result, i had problems in setting up the release process because my agents have powershell tools version 1.4 installed, but they are not fully compatible with release manager task. downgrading the tools solved the problem.
if your release fails with strange errors (such as nullreferenceexception) you need to check the version of powershell tools in github needed to run that task and install the right version in the agent (or at least you can try to change the version until you find the most recent that works).
the azure resource group deployments takes care of everything, i’ve modified the base script to apply a specific network security group to the vm, but the general concept is that it configures every azure resource you need to use. at the end of the script you have everything you need to deploy your software (virtual machines, sites, databases, etc).
in my example, i only need a vm, and once it is configured, i can simply use the copy to azure vm task and the execute powershell on azure vm task to release my software, as i did for my on-premise environment.
figure 6: configuration of the task used to copy files to azure vm.
you can specify the files you want to copy (1) log into the machine (2), and thanks to the enable copy prerequisites (3) option, you can let the task take care of every step needed to copy files to the vm.this option is not needed if you already chose it in the azure deployment task, but it can be really useful if you have a pre-existing virtual machine you want to use.
the final step is executing the release script on the target machine, and it has the same options you specified to run a script on a machine on-premise.
figure 7: run the installation powershell script on target azure vm.
once everything is in place you only need to create a release and wait for it to be finished.
figure 8: output of release definition with azure arm.
with this example, because i’m using a virtual machine, the deploy script is the same i used for on-premise release, with a paas approach, usually you have a different script that targets azure-specific resources (websites, documentdb, etc.).
if the release succeeded, you can log in to portal.azure.com to verify that your new resource group was correctly created figure 1 and check that all the expected resources are in the resource group figure 9 .
figure 9: resources created inside the group.
to verify that everything is ok, you should check the exact version of the software that is actually deployed on the environment. from figure 10, i can see that the release deployed the version 1.5.2.
figure 10: list of all most recent releases.
now i can log into the vm and try to use the software to verify that it is correctly installed and that the installed version is correct.
figure 11: software is correctly installed and the version corresponds to the version of the release.
azure resource management is a powerful feature that can dramatically simplify releasing your software to azure because you can just download scripts from github to automatically create all azure resources needed by your application. it also lets vsts release management tasks take care of everything.
Published at DZone with permission of Ricci Gian Maria. See the original article here.
Opinions expressed by DZone contributors are their own.