# Bicep Templates — Azure

Source: https://www.skillbyai.com/en/azure/o-bicep

> Describe Azure infrastructure declaratively with Bicep and preview changes safely.

## Declare the end state

**Bicep** is Azure's domain-specific language for infrastructure as code. It compiles to ARM JSON templates but is far shorter and has type checking for every resource type and API version. You declare **parameters**, **resources**, **modules** (reusable Bicep files) and **outputs**; Azure Resource Manager works out the order from references and makes the real state match. Deployments are **incremental** by default: resources missing from the file are left alone. Before applying, run **`what-if`** to see exactly what will be created, modified or deleted. **Deployment stacks** can additionally manage and clean up resources that disappear from a template. Many teams use **Terraform** instead, which works across clouds; both approaches are fine, but pick one per estate.

## From file to resources

A Bicep file goes through what-if review and is then applied by Resource Manager.

![A document icon flowing to a magnifying-glass review step and then to a cluster of resource blocks.](assets/figures/azure/section-7-map.svg) — Figure 7.1 — Write, preview with what-if, then deploy.

## A parameterised storage module

Secure defaults are written once in the template instead of remembered by people.

```bicep
@description('Globally unique storage account name')
@minLength(3)
@maxLength(24)
param name string
param location string = resourceGroup().location
@allowed(['Standard_LRS', 'Standard_ZRS', 'Standard_GZRS'])
param sku string = 'Standard_ZRS'

resource sa 'Microsoft.Storage/storageAccounts@2023-01-01' = {
  name: name
  location: location
  sku: { name: sku }
  kind: 'StorageV2'
  properties: {
    minimumTlsVersion: 'TLS1_2'
    allowBlobPublicAccess: false
    allowSharedKeyAccess: false
    supportsHttpsTrafficOnly: true
  }
}

output blobEndpoint string = sa.properties.primaryEndpoints.blob

// preview, then deploy:
// az deployment group what-if -g rg-shop-dev-cin -f storage.bicep -p name=stshopdev123
// az deployment group create  -g rg-shop-dev-cin -f storage.bicep -p name=stshopdev123
```

## Never skip what-if in production

Changing an immutable property can make Azure replace a resource, and replacing a database or storage account loses data. Run what-if in the pipeline, show the output in the pull request and require approval for production.

**Quiz:** What does `az deployment group what-if` do?

- [x] Shows predicted creates, changes and deletes without applying them
- [ ] Deletes resources not in the template
- [ ] Converts Terraform to Bicep
- [ ] Rolls back the last deployment

*Answer:* Shows predicted creates, changes and deletes without applying them. what-if previews the changes a deployment would make, so you can review them first.
