← Work

bicep · powershell · azure-devops · json-schema

Deployment Contract Platform

Client configuration in, a deterministic Azure deployment plan out — with what-if, drift handling and least-privilege identity.

Problem

Every client deployment of AI infrastructure and application code starts from that client’s configuration. If the scripts between the config and Azure are free to reinterpret it, two runs of the same config can do different things — and nobody can say which one production reflects.

Constraints

  • One source-of-truth configuration per client.
  • Fully automated production deployments through Azure DevOps pipelines.
  • Least privilege: deployments run under a managed-identity model, not broad credentials.

Decisions

  • Client intent flows through an explicit contract: config → deployment-plan.json → Bicep → deployment record. Each stage consumes the previous stage’s output, so no script reinterprets source intent.
  • JSON schemas define the contract, so a malformed configuration fails before anything deploys.
  • The plan carries what-if mode, an existing-resource preflight, and drift handling, so a run can show what it will change before it changes it.
  • Built from scratch — 126 commits — in Bicep, PowerShell and Azure DevOps pipelines.

Verification

  • Pester tests cover the failure modes, not only the happy path.
  • Every run ends in a deployment record: the last link in the contract chain, and the answer to “what did we actually ship?”

Outcome

Fully automated production deployments of AI infrastructure and application code, each driven from a single configuration per client. I lead planning for the platform implementations that build on it.

Next: InfoPath Migration Pipeline →