AI Instructor Live Labs Included

AZ-DEV-200: Infrastructure as Code with Bicep and GitHub Actions

Intermediate
1d 13h 30m
20 Lessons
AZ-DEV-200

About This Course

Ship Azure infrastructure with Bicep and GitHub Actions the way modern .NET teams do. You will author Bicep templates, compose modules from a private registry, gate changes with what-if and deployment stacks, wire zero-secret OIDC federation to GitHub Actions, promote across dev/test/prod with review gates, seed Key Vault and App Configuration, and test infrastructure with PSRule and Pester. By the end you can ship a landing-zone-style workload from a PR merge with drift detection, deny-settings, and complete auditability.

Course Curriculum

20 Lessons
01
AI Lesson
AI Lesson

AZ-DEV-200 M1L1 - Bicep fundamentals - syntax, targets, and parameters

1h 0m

Learn the Bicep mental model before writing production templates. Cover the ARM-native DSL, resource declarations with symbolic names, parameter types with decorators (@allowed, @description, @secure), variables, outputs, string interpolation, and target scopes (resourceGroup, subscription, managementGroup, tenant). By the end you can read any Bicep template fluently and pick the right target scope for a workload.

02
Lab Exercise
Lab Exercise

AZ-DEV-200 M1L2 - Author and deploy your first Bicep template with az deployment group create - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Write a resource-group-scoped Bicep template that provisions a Storage Account, App Service Plan, and Web App for the Anchorline Outdoors storefront. Parameterize app name, location, and SKU with decorators. Deploy with az deployment group create, inspect the deployment outputs, and hit the web app URL.

03
AI Lesson
AI Lesson

AZ-DEV-200 M2L3 - Bicep modules and composition - local, registry, and versioning

1h 0m

Move beyond single-file templates. Learn how local modules (relative path), private Bicep module registries (ACR-backed), and the public registry work together. Cover module versioning with semver, module outputs and inputs, module dependencies, and when to extract shared modules from a template.

04
Lab Exercise
Lab Exercise

AZ-DEV-200 M2L4 - Extract three modules and publish them to a private Bicep registry - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Extract three shared modules (storage-account, key-vault, app-insights) from an existing Anchorline template. Publish them to a private ACR-backed Bicep registry with semver versions. Consume the versioned modules from a top-level template, bump one module's version, and observe the deployment respect the pin.

05
AI Lesson
AI Lesson

AZ-DEV-200 M3L5 - Loops, conditionals, and dynamic deployments

1h 0m

Bicep's dynamic constructs: for loops over arrays and index counts, if conditionals on resources and modules, the existing keyword for referencing existing resources without redeploy, and explicit dependsOn when Bicep can't infer. By the end you can drive N-resource deployments from parameter arrays and mix environment-specific resources into a single template.

06
Lab Exercise
Lab Exercise

AZ-DEV-200 M3L6 - Deploy N storage accounts, a conditional Key Vault, and reference an existing VNet - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Drive an Anchorline Outdoors deployment from a parameter file. Loop over an array of storage account definitions, add a conditional Key Vault deployed only in prod, and reference an existing VNet via existing to inject a new subnet. Verify with mixed dev and prod parameter sets.

07
AI Lesson
AI Lesson

AZ-DEV-200 M4L7 - What-if, preflight, and deployment modes

1h 0m

Preview infrastructure changes before you ship them. Cover incremental vs complete deployment modes, az deployment ... what-if output format and interpretation, preflight validation, deployment operations history, and the fundamentals of drift detection between template and Azure.

08
Lab Exercise
Lab Exercise

AZ-DEV-200 M4L8 - Gate a deployment on a what-if diff and post it as a PR comment - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Take an existing Anchorline workload, modify the Bicep to change a SKU, and run what-if to interpret the diff. Then use --confirm-with-what-if to gate the deploy. Wire the same flow into a GitHub Actions PR check that posts the what-if diff as a PR comment for review.

09
AI Lesson
AI Lesson

AZ-DEV-200 M5L9 - Deployment stacks and drift detection

1h 0m

Manage related resources as one lifecycle unit. Learn deployment stack semantics, drift detection between stack state and real Azure, deny-settings (deny delete and modify) on stack-managed resources, and the unmanage-vs-delete choice on removal.

10
Lab Exercise
Lab Exercise

AZ-DEV-200 M5L10 - Convert a workload to a deployment stack, enable deny-settings, and remediate drift - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Convert an existing Anchorline workload to a deployment stack. Enable deny-settings preventing manual deletion of stack resources. Simulate drift by modifying a resource in the portal, run drift detection, and re-apply the stack to remediate.

11
AI Lesson
AI Lesson

AZ-DEV-200 M6L11 - GitHub Actions with OIDC federation - zero-secret Azure deploys

1h 0m

The modern zero-secret deployment story. Cover federated credentials on an Entra ID app registration, GitHub Actions OIDC token exchange via azure/login@v2, environment secrets and variables, environment protection rules, and review gates.

12
Lab Exercise
Lab Exercise

AZ-DEV-200 M6L12 - Configure federated credentials and deploy Bicep from GitHub Actions with no client secret - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Configure a federated credential allowing your GitHub repo's main branch to obtain Entra tokens. Wire a GitHub Actions workflow that authenticates with no client secret, deploys Bicep for the Anchorline workload, and returns the deployment output. Verify no AZURE_CLIENT_SECRET exists anywhere.

13
AI Lesson
AI Lesson

AZ-DEV-200 M7L13 - Multi-environment pipelines - dev to test to prod with review gates

1h 0m

Environment-per-tier design (dev, test, prod). Cover GitHub Actions environments with protection rules and required reviewers, matrix strategies for parallel dev+test deploys, and promotion patterns (auto to dev, gated to test, manual approval to prod).

14
Lab Exercise
Lab Exercise

AZ-DEV-200 M7L14 - Build a dev/test/prod pipeline with approvals and a rollback path - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Build the full Anchorline dev→test→prod pipeline: PR merges auto-deploy to dev, manual approval promotes to test, PR-review-plus-approver-approval promotes to prod. Include a rollback path that redeploys the previous known-good tag.

15
AI Lesson
AI Lesson

AZ-DEV-200 M8L15 - Secrets and config - Key Vault references, App Configuration, and secret rotation

1h 0m

Wire secrets and configuration into your Bicep templates. Cover Key Vault references from Bicep (getSecret()), App Configuration seeding with feature flags, secret rotation strategies, and the @secure parameter contract.

16
Lab Exercise
Lab Exercise

AZ-DEV-200 M8L16 - Seed Key Vault and App Configuration, wire Key Vault references into the app - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Deploy a Bicep template that provisions a Key Vault, seeds three secrets from a source of truth, then deploys an Anchorline App Service using Key Vault references for its app settings. Add App Configuration with feature flags. Verify the app reads Key Vault-backed settings and App Config feature flags at boot.

17
AI Lesson
AI Lesson

AZ-DEV-200 M9L17 - Testing Bicep - bicep lint, PSRule for Azure, and Pester

1h 0m

Add tests to your infrastructure pipeline. Cover bicep lint and rule customization, PSRule for Azure with the Az.Resources ruleset, Pester tests for Bicep and deployment output, ARM-TTK for legacy templates, and policy-as-code with Azure Policy assignments.

18
Lab Exercise
Lab Exercise

AZ-DEV-200 M9L18 - Add bicep lint, PSRule, and Pester gates to the pipeline - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.

Add bicep lint to CI, PSRule tests catching common misconfigurations (public Storage, weak TLS, missing tags), and Pester tests verifying deployment outputs match expected values. All checks gate the pipeline. Introduce a violation and verify CI blocks the merge.

19
AI Lesson
AI Lesson

AZ-DEV-200 M10L19 - Landing-zone-style deployment - modules, stacks, and multi-region

1h 0m

Design a landing-zone-style deployment for a multi-region workload. Cover networking, identity, monitoring, and governance baselines, multi-region topology patterns, cost tagging conventions, and how deployment stacks scale from one workload to many.

20
Lab Exercise
Lab Exercise

AZ-DEV-200 M10L20 - Capstone - Ship the Anchorline landing zone with modules, stacks, tests, and OIDC federation - Lab Exercises

2h 45m 4 Exercises

Note: This lab pre-provisions Azure resources at start — allow up to 15 minutes for the environment to become ready before beginning the exercises.

Build a landing-zone-style deployment for the multi-region Anchorline .NET workload: VNet + Key Vault + App Configuration + App Insights + Storage + SQL + App Service across two regions via Bicep modules from a registry. Manage each environment with a deployment stack. Full dev/test/prod pipeline with PSRule + Pester tests + what-if gates + OIDC federation. Deploy end-to-end from a PR merge.

This course includes:

  • 24/7 AI Instructor Support
  • Live Lab Environments
  • 10 Hands-on Lessons
Skill Level Intermediate
Total Duration 1d 13h 30m