Q: Your cloud infrastructure is managed by legacy 3,500-line ARM JSON templates full of nested concat() functions, unreadable parameters, and copy loops. Deployment errors are frequent and onboarding new engineers takes weeks. How do you refactor the codebase into modular Azure Bicep, validate deployments via What-If pipelines, and share modules across teams?
Engineering guide for refactoring unmaintainable, multi-thousand-line ARM JSON templates into clean, modular, reusable Azure Bicep modules with CI/CD What-If validation and private registry publishing.
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Decompile Legacy ARM Templates to Bicep Code
Convert existing JSON templates to native Bicep syntax using Azure CLI:
- Decompile Command: Executed
az bicep decompile --file legacy-landing-zone.json. - Syntax Cleanup: Replaced verbose
[parameters('env')]and[concat('rg-', variables('appName'))]with clean string interpolation:'rg-${appName}-${env}'.
Deconstruct Monolith into Single-Responsibility Bicep Modules
Organize infrastructure components into independent, composable building blocks:
- Module Directory: Created reusable modules:
modules/network.bicep,modules/aks.bicep,modules/keyvault.bicep,modules/database.bicep. - Parameter Contracts: Defined strict strongly-typed parameters using decorators:
@allowed(['dev', 'staging', 'prod']) param env stringand@secure() param adminPassword string.
Publish Modules to Private Azure Container Registry (ACR)
Distribute versioned Bicep modules across the enterprise:
- Publish Module: Published module to private ACR:
az bicep publish --file modules/aks.bicep --target br:crplatform.azurecr.io/bicep/modules/aks:v2.1.0. - Consume in Projects: Referenced remote modules via
module aks 'br:crplatform.azurecr.io/bicep/modules/aks:v2.1.0' = { ... }.
Implement What-If Deployment Verification in GitHub Actions
Prevent accidental resource deletion before executing production changes:
- Bicep Linting: Added
az bicep build --file main.bicepstep in CI to enforce static code analysis and security best practices. - What-If Analysis: Ran
az deployment group what-if --resource-group rg-prod --template-file main.bicepand posted the exact resource delta (Create, Modify, Delete) to the GitHub PR comment.
- Decompile legacy ARM JSON templates into concise, human-readable Bicep syntax.
- Deconstruct monoliths into strongly-typed single-responsibility Bicep modules.
- Publish versioned modules to Azure Container Registry for enterprise sharing.
- Automate What-If delta predictions in CI/CD pull requests to eliminate destructive deployment surprises.