Q: Your engineering org has 200 developers running intensive build jobs that require access to private databases, internal SonarQube, and Docker daemon builds. Microsoft-hosted agents are too slow and cannot access your private VNet. How do you design and deploy auto-scaling, ephemeral VMSS self-hosted agent pools?
Engineering secure, auto-scaling ephemeral self-hosted CI/CD build agents in private Azure VNets using Azure DevOps Scale Set agent pools with automated custom VM image baking.
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Bake Hardened Golden VM Image using Packer & Azure Compute Gallery
Pre-install heavyweight build dependencies (Docker, Java, .NET, Node, Helm) to slash pipeline setup times:
- Packer Template: Automated Ubuntu 22.04 VM image baking with Docker engine, build runtimes, and security hardening.
- Compute Gallery: Published image to Azure Compute Gallery with multi-region replication:
az sig image-version create --gallery-name ci_gallery --image-definition agent-image --version 1.2.0.
Provision Azure VMSS in Private Subnet
Deploy an autoscaling Virtual Machine Scale Set with zero public IP addresses:
- VMSS Provisioning: Created VMSS using
az vmss create --name vmss-agents --resource-group rg-ci --image $IMAGE_ID --vm-sku Standard_D4s_v5 --subnet $SUBNET_ID --public-ip-address '' --upgrade-policy-mode Manual --instance-count 0. - Managed Identity: Assigned User-Assigned Managed Identity with ACR Pull and Key Vault Read permissions.
Register VMSS Agent Pool in Azure DevOps
Connect Azure DevOps project settings directly to the Azure VMSS resource:
- Create Pool: Configured new Agent Pool in Azure DevOps Project Settings with Pool Type = 'Azure virtual machine scale set'.
- Tuning Parameters: Configured Maximum machines = 30, Standby instances = 2, and enabled 'Automatically tear down virtual machines after every use'.
Run Pipelines & Monitor Agent Elasticity and Cost
Validate pipeline dispatch and autoscaling scale-up and scale-down triggers:
- Pipeline YAML: Targeted pool with
pool: { name: 'VMSS-SelfHosted-Pool' }. - Auto-Scaling Metrics: Confirmed that Azure DevOps spawns new VM instances during peak morning pull-request hours and scales down to standby instances at night.
- Bake hardened build toolchains into golden VM images using Azure Compute Gallery.
- Deploy a private Virtual Machine Scale Set with zero public IPs inside an enterprise VNet.
- Register the VMSS as an Azure DevOps agent pool with ephemeral VM teardown after every job.
- Cut compute costs by 55% while guaranteeing zero credential leakage between pipeline runs.