How do you deal with the problems you face when using Azure? This practical guide provides over 75 recipes to help you to work with common Azure issues in everyday scenarios. That includes key tasks like setting up permissions for a storage account, working with Cosmos DB APIs, managing Azure role-based access control, governing your Azure subscriptions using Azure Policy, and much more.
Author Reza Salehi has assembled real-world recipes that enable you to grasp key Azure services and concepts quickly. Each recipe includes CLI scripts that you can execute in your own Azure account. Recipes also explain the approach and provide meaningful context. The solutions in this cookbook will take you beyond theory and help you understand Azure services in practice.
You'll find recipes that let you:
• Store data in an Azure storage account or in a data lake
• Work with relational and nonrelational databases in Azure
• Manage role-based access control (RBAC) for Azure resources
• Safeguard secrets in Azure Key Vault
• Govern your Azure subscription using Azure Policy
• Use CLI code to construct your application or fix a particular problem
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
# Azure Cookbook: Recipes to Create and Maintain Cloud Solutions in Azure
## 【One-Line Pitch】
A practical, hands-on guide with 75+ Azure recipes covering security, networking, storage, databases, and serverless services—perfect for cloud engineers and developers who want to solve real Azure problems using CLI scripts rather than reading theory.
## 【Book Arc】
- **Opening (~0%–9%)**: Introduces the book's structure across 11 chapters, from Security and Networking to Cognitive Services and Management/Monitoring, with a clear promise of CLI-driven, practical recipes for everyday Azure scenarios.
- **Early (~9%–25%)**: Dives into security fundamentals—creating users, custom RBAC roles, connecting to private VMs via Azure Bastion, disk encryption, and Key Vault secrets—establishing a pattern of "Problem → Solution → Steps → Discussion" for each recipe.
- **Early-to-Middle (~25%–38%)**: Expands into networking (VNet peering, user-defined routes) and storage (encryption at rest with Key Vault keys, SAS tokens, blob snapshots, lifecycle management policies for cost optimization).
- **Middle (~38%–47%)**: Covers data persistence with Azure SQL and Cosmos DB, including API selection (SQL/Core, Table), private access via endpoints, and custom role definitions for database access control.
- **Late (~47%–end)**: Continues with messaging, big data, Functions, App Service, containers, Cognitive Services, and monitoring—though excerpts only partially cover these later chapters.
## 【Key Takeaways】
- **RBAC custom roles are the backbone of Azure security** (Early): Creating custom roles with specific Actions/DataActions (like blob read-only) lets you enforce least-privilege access; the book shows JSON definitions and CLI assignment commands.
- **Azure Bastion solves the private VM access problem** (Early): For VMs without public IPs, Bastion provides secure RDP/SSH through the Azure portal without exposing endpoints to the internet.
- **Key Vault centralizes secret management** (Early): Store passwords, connection strings, and encryption keys in one place; recipes show how to create vaults, generate keys, and grant client access for retrieval.
- **Storage encryption at rest is configurable via Key Vault keys** (Early): Use customer-managed keys (CMK) in Key Vault to encrypt Azure Storage, giving you control over key rotation and lifecycle.
- **SAS tokens provide time-limited, scoped access** (Early): Generate tokens with specific permissions (read/write), services (blob/table/file), and expiry times—critical for secure App Service-to-Storage integration.
- **Lifecycle management policies automate storage cost optimization** (Middle): Define rules to move blobs from Hot to Cool to Archive tiers based on age, and delete old data—reducing costs without manual intervention.
- **Cosmos DB offers multiple APIs for different needs** (Middle): Choose SQL (Core) for JSON documents, Table API for Azure Table Storage migration, and others; each has distinct consistency, distribution, and security features.
- **Private endpoints are essential for production data stores** (Middle): Restrict Cosmos DB (and other services) to private traffic only, using IP rules for static clients and VNet rules for Azure-deployed resources.
## 【Reading Tips】
- **Skim the "Discussion" sections first**: Each recipe ends with context explaining why the solution works—read these to understand the "why" before diving into CLI commands.
- **Deep-read Chapters 1–3**: Security, Networking, and Storage recipes are foundational and heavily covered in excerpts; master these before moving to databases and serverless.
- **Use the CLI scripts as templates**: Copy and adapt the `az` commands for your own environment; replace placeholder variables like `<key-vault-name>` and `<rgName>` with your values.
- **Watch for prerequisites**: Many recipes assume Owner role access and a configured workstation—check the preface's "General Workstation Setup Instructions" before starting.
- **Skip ahead if you're experienced**: If you already know RBAC and VNet peering, jump to Chapters 4+ for Cosmos DB, Functions, and App Service recipes.
## 【Coverage Limits】
This guide is based on excerpts covering roughly the first half of the book (Chapters 1–4). Later chapters on messaging, big data, Functions, App Service, containers, Cognitive Services, and monitoring are mentioned in the preface but not detailed in the available material.
##
Page 7
Types in a Subscription 7 1.4 Assigning Allowed Locations for Azure Resources 10 1.5 Connecting to a Private Azure Virtual Machine Using Azure Bastion 11 1.6...
clients to read the secrets from the Key Vault when needed. The flow is shown in Figure 1-13. Figure 1-13. Storing and accessing keys, secrets, and certifica...
: expiryDate=`date -u -d "15 minutes" '+%Y-%m-%dT%H:%MZ'` 4. The storage account key is also needed to authenticate the SAS generation com‐ mand. We only nee...
ess for Azure Cosmos DB, as shown in Figure 4-4. Figure 4-4. Allowing only private traffic to Azure Cosmos DB using private endpoints 4.4 Configuring Azure C...
Data Lake Storage Gen2 and a child filesystem (con‐ tainer). Azure Databricks can use this storage for big data analysis. By passing 158 | Chapter 6: Big Dat...
method to quickly get your web application up and running. You can also use the following options to manually deploy your code to Azure App Service: • FTP •...
ple Cognitive Services kinds with the same endpoint and key. You will get billed against the single multi- service resource. You can use the single-service typ
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Azure Cookbook Recipes to Create and Maintain Cloud Solutions in Azure (Reza Salehi)(Z-Library)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Azure Cookbook Recipes to Create and Maintain Cloud Solutions in Azure (Reza Salehi)(Z-Library)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment