Skip to content

Instantly share code, notes, and snippets.

@korkridake
Created January 23, 2026 08:19
Show Gist options
  • Select an option

  • Save korkridake/adfc2a7596561cc6d2d6961fc79bcb29 to your computer and use it in GitHub Desktop.

Select an option

Save korkridake/adfc2a7596561cc6d2d6961fc79bcb29 to your computer and use it in GitHub Desktop.
AML Sandbox ARM Template
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"workspaceName": {
"type": "string",
"metadata": {
"description": "Specifies the name of the Azure Machine Learning workspace."
}
},
"friendlyName": {
"type": "string",
"defaultValue": "[parameters('workspaceName')]"
},
"description": {
"type": "string",
"defaultValue": ""
},
"kind": {
"type": "string",
"defaultValue": "Default",
"allowedValues": [
"Default",
"FeatureStore",
"Hub",
"Project"
]
},
"location": {
"type": "string",
"metadata": {
"description": "Specifies the location for all resources."
}
},
"resourceGroupName": {
"type": "string",
"metadata": {
"description": "Specifies the resource group name of the Azure Machine Learning workspace."
}
},
"appInsightsLogWorkspaceName": {
"type": "string",
"defaultValue": "[concat('ai', uniqueString(parameters('resourceGroupName'), parameters('workspaceName')))]",
"metadata": {
"description": "Specifies log workspace name of the log workspace created for the Application Insights."
}
},
"sku": {
"type": "string",
"defaultValue": "Basic",
"allowedValues": [
"Basic",
"Enterprise"
],
"metadata": {
"description": "Specifies the sku, also referred as 'edition' of the Azure Machine Learning workspace."
}
},
"identityType": {
"type": "string",
"defaultValue": "systemAssigned",
"allowedValues": [
"systemAssigned",
"userAssigned"
],
"metadata": {
"description": "Specifies the identity type of the Azure Machine Learning workspace."
}
},
"primaryUserAssignedIdentityResourceGroup": {
"type": "string",
"defaultValue": "[parameters('resourceGroupName')]",
"metadata": {
"description": "Specifies the resource group of user assigned identity that represents the Azure Machine Learing workspace."
}
},
"primaryUserAssignedIdentityName": {
"type": "string",
"defaultValue": "",
"metadata": {
"description": "Specifies the name of user assigned identity that represents the Azure Machine Learing workspace."
}
},
"storageAccountOption": {
"type": "string",
"defaultValue": "new",
"allowedValues": [
"new",
"existing"
],
"metadata": {
"description": "Determines whether or not a new storage should be provisioned."
}
},
"storageAccountName": {
"type": "string",
"defaultValue": "[concat('sa', uniqueString(parameters('resourceGroupName'), parameters('workspaceName')))]",
"metadata": {
"description": "Name of the storage account."
}
},
"storageAccountType": {
"type": "string",
"defaultValue": "Standard_LRS",
"allowedValues": [
"Standard_LRS",
"Standard_GRS",
"Standard_RAGRS",
"Standard_ZRS",
"Standard_GZRS",
"Standard_RAGZRS"
]
},
"storageAccountBehindVNet": {
"type": "string",
"defaultValue": "false",
"allowedValues": [
"true",
"false"
],
"metadata": {
"description": "Determines whether or not to put the storage account behind VNet"
}
},
"storageAccountResourceGroupName": {
"type": "string",
"defaultValue": "[parameters('resourceGroupName')]"
},
"storageAccountLocation": {
"type": "string",
"defaultValue": "[parameters('location')]"
},
"storageAccountHnsEnabled": {
"type": "bool",
"defaultValue": false
},
"enableServiceSideCMKEncryption": {
"type": "bool",
"defaultValue": false
},
"managedKeyVaultType": {
"type": "string",
"defaultValue": "managedKeyVault",
"allowedValues": [
"managedKeyVault",
"byoKeyVault"
],
"metadata": {
"description": "Specifies whether or not managed key vault is used."
}
},
"keyVaultOption": {
"type": "string",
"defaultValue": "new",
"allowedValues": [
"new",
"existing"
],
"metadata": {
"description": "Determines whether or not a new key vault should be provisioned."
}
},
"keyVaultName": {
"type": "string",
"defaultValue": "[concat('kv', uniqueString(parameters('resourceGroupName'), parameters('workspaceName')))]",
"metadata": {
"description": "Name of the key vault."
}
},
"keyVaultBehindVNet": {
"type": "string",
"defaultValue": "false",
"allowedValues": [
"true",
"false"
],
"metadata": {
"description": "Determines whether or not to put the storage account behind VNet"
}
},
"keyVaultResourceGroupName": {
"type": "string",
"defaultValue": "[parameters('resourceGroupName')]"
},
"keyVaultLocation": {
"type": "string",
"defaultValue": "[parameters('location')]"
},
"applicationInsightsOption": {
"type": "string",
"defaultValue": "none",
"allowedValues": [
"new",
"existing",
"none"
],
"metadata": {
"description": "Determines whether or not new ApplicationInsights should be provisioned."
}
},
"applicationInsightsName": {
"type": "string",
"defaultValue": "[concat('ai', uniqueString(parameters('resourceGroupName'), parameters('workspaceName')))]",
"metadata": {
"description": "Name of ApplicationInsights."
}
},
"applicationInsightsResourceGroupName": {
"type": "string",
"defaultValue": "[parameters('resourceGroupName')]"
},
"applicationInsightsLocation": {
"type": "string",
"defaultValue": "[parameters('location')]"
},
"containerRegistryOption": {
"type": "string",
"defaultValue": "none",
"allowedValues": [
"new",
"existing",
"none"
],
"metadata": {
"description": "Determines whether or not a new container registry should be provisioned."
}
},
"containerRegistryName": {
"type": "string",
"defaultValue": "[concat('cr', uniqueString(parameters('resourceGroupName'), parameters('workspaceName')))]",
"metadata": {
"description": "The container registry bind to the workspace."
}
},
"containerRegistrySku": {
"type": "string",
"defaultValue": "Standard",
"allowedValues": [
"Basic",
"Standard",
"Premium"
]
},
"containerRegistryResourceGroupName": {
"type": "string",
"defaultValue": "[parameters('resourceGroupName')]"
},
"containerRegistryBehindVNet": {
"type": "string",
"defaultValue": "false",
"allowedValues": [
"true",
"false"
],
"metadata": {
"description": "Determines whether or not to put container registry behind VNet."
}
},
"containerRegistryLocation": {
"type": "string",
"defaultValue": "[parameters('location')]"
},
"vnetOption": {
"type": "string",
"defaultValue": "[if(equals(parameters('privateEndpointType'), 'none'), 'none', 'new')]",
"allowedValues": [
"new",
"existing",
"none"
],
"metadata": {
"description": "Determines whether or not a new VNet should be provisioned."
}
},
"vnetName": {
"type": "string",
"defaultValue": "[concat('vn',uniqueString(parameters('resourceGroupName'), parameters('workspaceName')))]",
"metadata": {
"description": "Name of the VNet"
}
},
"vnetResourceGroupName": {
"type": "string",
"defaultValue": "[parameters('resourceGroupName')]"
},
"delegateSubnetId": {
"type": "string",
"defaultValue": "[parameters('delegateSubnetId')]"
},
"delegateSubnetName": {
"type": "string",
"defaultValue": "[parameters('delegateSubnetName')]"
},
"addressPrefixes": {
"type": "array",
"defaultValue": [
"10.0.0.0/16"
],
"metadata": {
"description": "Address prefix of the virtual network"
}
},
"subnetOption": {
"type": "string",
"defaultValue": "[if(or(not(equals(parameters('privateEndpointType'), 'none')), equals(parameters('vnetOption'), 'new')), 'new', 'none')]",
"allowedValues": [
"new",
"existing",
"none"
],
"metadata": {
"description": "Determines whether or not a new subnet should be provisioned."
}
},
"subnetName": {
"type": "string",
"defaultValue": "[concat('sn',uniqueString(parameters('resourceGroupName'), parameters('workspaceName')))]",
"metadata": {
"description": "Name of the subnet"
}
},
"subnetPrefix": {
"type": "string",
"defaultValue": "10.0.0.0/24",
"metadata": {
"description": "Subnet prefix of the virtual network"
}
},
"adbWorkspace": {
"type": "string",
"defaultValue": "",
"metadata": {
"description": "Azure Databrick workspace to be linked to the workspace"
}
},
"confidential_data": {
"type": "string",
"defaultValue": "false",
"allowedValues": [
"false",
"true"
],
"metadata": {
"description": "Specifies that the Azure Machine Learning workspace holds highly confidential data."
}
},
"encryption_status": {
"type": "string",
"defaultValue": "Disabled",
"allowedValues": [
"Enabled",
"Disabled"
],
"metadata": {
"description": "Specifies if the Azure Machine Learning workspace should be encrypted with customer managed key."
}
},
"cmk_keyvault": {
"type": "string",
"defaultValue": "",
"metadata": {
"description": "Specifies the customer managed keyVault arm id."
}
},
"resource_cmk_uri": {
"type": "string",
"defaultValue": "",
"metadata": {
"description": "Specifies if the customer managed keyvault key uri."
}
},
"privateEndpointType": {
"type": "string",
"defaultValue": "none",
"allowedValues": [
"AutoApproval",
"ManualApproval",
"none"
]
},
"tagValues": {
"type": "object"
},
"privateEndpointName": {
"type": "string",
"defaultValue": "pe",
"metadata": {
"description": "Name of the private end point added to the workspace"
}
},
"privateEndpointResourceGroupName": {
"type": "string",
"defaultValue": "[parameters('resourceGroupName')]",
"metadata": {
"description": "Name of the resource group where the private end point is added to"
}
},
"privateEndpointSubscription": {
"type": "string",
"defaultValue": "[subscription().subscriptionId]",
"metadata": {
"description": "Id of the subscription where the private end point is added to"
}
},
"systemDatastoresAuthMode": {
"type": "string",
"defaultValue": "accessKey",
"metadata": {
"description": "Identity type of storage account services."
}
},
"allowSharedKeyAccess": {
"type": "string",
"defaultValue": "false",
"allowedValues": [
"true",
"false"
],
"metadata": {
"description": "Determines whether or not to disable shared key based access to storage account"
}
},
"managedNetwork": {
"type": "object",
"defaultValue": {
"isolationMode": "Disabled"
},
"metadata": {
"description": "Managed network settings to be used for the workspace. If not specified, isolation mode Disabled is the default"
}
},
"provisionNetworkNow": {
"type": "String",
"defaultValue": "false",
"allowedValues": [
"true",
"false"
],
"metadata": {
"description": "Set to trigger the provisioning of managed vnet when creating a workspace"
}
},
"publicNetworkAccess": {
"type": "string",
"defaultValue": "Enabled",
"metadata": {
"description": "Specifies whether the workspace can be accessed by public networks or not."
}
}
},
"variables": {
"tenantId": "[subscription().tenantId]",
"storageAccount": "[resourceId(parameters('storageAccountResourceGroupName'), 'Microsoft.Storage/storageAccounts', parameters('storageAccountName'))]",
"keyVault": "[resourceId(parameters('keyVaultResourceGroupName'), 'Microsoft.KeyVault/vaults', parameters('keyVaultName'))]",
"containerRegistry": "[resourceId(parameters('containerRegistryResourceGroupName'), 'Microsoft.ContainerRegistry/registries', parameters('containerRegistryName'))]",
"applicationInsights": "[resourceId(parameters('applicationInsightsResourceGroupName'), 'Microsoft.Insights/components', parameters('applicationInsightsName'))]",
"vnet": "[resourceId(parameters('privateEndpointSubscription'), parameters('vnetResourceGroupName'), 'Microsoft.Network/virtualNetworks', parameters('vnetName'))]",
"subnet": "[resourceId(parameters('privateEndpointSubscription'), parameters('vnetResourceGroupName'), 'Microsoft.Network/virtualNetworks/subnets', parameters('vnetName'), parameters('subnetName'))]",
"networkRuleSetBehindVNet": {
"defaultAction": "deny",
"virtualNetworkRules": [
{
"action": "Allow",
"id": "[variables('subnet')]"
}
]
},
"privateEndpointSettings": {
"name": "[concat(parameters('workspaceName'), '-PrivateEndpoint')]",
"properties": {
"privateLinkServiceId": "[resourceId('Microsoft.MachineLearningServices/workspaces', parameters('workspaceName'))]",
"groupIds": [
"amlworkspace"
]
}
},
"defaultPEConnections": "[array(variables('privateEndpointSettings'))]",
"privateEndpointDeploymentName": "[concat('DeployPrivateEndpoint-', uniqueString(parameters('privateEndpointName')))]",
"userAssignedIdentities": {
"[variables('primaryUserAssignedIdentity')]": {}
},
"primaryUserAssignedIdentity": "[resourceId(parameters('primaryUserAssignedIdentityResourceGroup'), 'Microsoft.ManagedIdentity/userAssignedIdentities', parameters('primaryUserAssignedIdentityName'))]"
},
"resources": [
{
"condition": "[equals(parameters('storageAccountOption'), 'new')]",
"type": "Microsoft.Storage/storageAccounts",
"apiVersion": "2019-04-01",
"name": "[parameters('storageAccountName')]",
"tags": "[parameters('tagValues')]",
"location": "[parameters('storageAccountLocation')]",
"sku": {
"name": "[parameters('storageAccountType')]"
},
"kind": "StorageV2",
"properties": {
"encryption": {
"services": {
"blob": {
"enabled": true
},
"file": {
"enabled": true
}
},
"keySource": "Microsoft.Storage"
},
"supportsHttpsTrafficOnly": true,
"allowBlobPublicAccess": false,
"networkAcls": "[if(equals(parameters('storageAccountBehindVNet'), 'true'), variables('networkRuleSetBehindVNet'), json('null'))]",
"isHnsEnabled": "[parameters('storageAccountHnsEnabled')]",
"allowSharedKeyAccess": "[parameters('allowSharedKeyAccess')]",
"minimumTlsVersion": "TLS1_2"
}
},
{
"condition": "[and(equals(parameters('managedKeyVaultType'), 'byoKeyVault'), equals(parameters('keyVaultOption'), 'new'))]",
"type": "Microsoft.KeyVault/vaults",
"apiVersion": "2019-09-01",
"tags": "[parameters('tagValues')]",
"name": "[parameters('keyVaultName')]",
"location": "[parameters('keyVaultLocation')]",
"properties": {
"tenantId": "[variables('tenantId')]",
"sku": {
"name": "standard",
"family": "A"
},
"accessPolicies": [],
"networkAcls": "[if(equals(parameters('keyVaultBehindVNet'), 'true'), variables('networkRuleSetBehindVNet'), json('null'))]"
}
},
{
"condition": "[equals(parameters('containerRegistryOption'), 'new')]",
"type": "Microsoft.ContainerRegistry/registries",
"apiVersion": "2019-05-01",
"tags": "[parameters('tagValues')]",
"name": "[parameters('containerRegistryName')]",
"location": "[parameters('containerRegistryLocation')]",
"sku": {
"name": "[parameters('containerRegistrySku')]"
},
"properties": {
"adminUserEnabled": true,
"networkRuleSet": "[if(equals(parameters('containerRegistryBehindVNet'), 'true'), variables('networkRuleSetBehindVNet'), json('null'))]"
}
},
{
"condition": "[equals(parameters('applicationInsightsOption'), 'new')]",
"type": "Microsoft.OperationalInsights/workspaces",
"tags": "[parameters('tagValues')]",
"apiVersion": "2020-08-01",
"name": "[parameters('appInsightsLogWorkspaceName')]",
"location": "[\n if(\n or(\n equals(parameters('applicationInsightsLocation'),'westcentralus'),\n equals(parameters('applicationInsightsLocation'),'eastus2euap'),\n equals(parameters('applicationInsightsLocation'),'centraluseuap')),\n 'southcentralus',\n parameters('applicationInsightsLocation'\n )\n )\n]"
},
{
"condition": "[equals(parameters('applicationInsightsOption'), 'new')]",
"type": "Microsoft.Insights/components",
"tags": "[parameters('tagValues')]",
"apiVersion": "2020-02-02-preview",
"location": "[\n if(\n or(\n equals(parameters('applicationInsightsLocation'),'westcentralus'),\n equals(parameters('applicationInsightsLocation'),'eastus2euap'),\n equals(parameters('applicationInsightsLocation'),'centraluseuap')),\n 'southcentralus',\n parameters('applicationInsightsLocation'\n )\n )\n]",
"name": "[parameters('applicationInsightsName')]",
"dependsOn": [
"[resourceId('Microsoft.OperationalInsights/workspaces', parameters('appInsightsLogWorkspaceName'))]"
],
"properties": {
"ApplicationId": "[parameters('applicationInsightsName')]",
"Application_Type": "web",
"Flow_Type": "Redfield",
"Request_Source": "IbizaMachineLearningExtension",
"WorkspaceResourceId": "[resourceId('Microsoft.OperationalInsights/workspaces', parameters('appInsightsLogWorkspaceName'))]"
}
},
{
"type": "Microsoft.MachineLearningServices/workspaces",
"apiVersion": "2024-10-01-preview",
"tags": "[parameters('tagValues')]",
"name": "[parameters('workspaceName')]",
"location": "[parameters('location')]",
"kind": "[parameters('kind')]",
"dependsOn": [
"[resourceId('Microsoft.Storage/storageAccounts', parameters('storageAccountName'))]",
"[resourceId('Microsoft.KeyVault/vaults', parameters('keyVaultName'))]",
"[resourceId('Microsoft.Insights/components', parameters('applicationInsightsName'))]",
"[resourceId('Microsoft.ContainerRegistry/registries', parameters('containerRegistryName'))]"
],
"identity": {
"type": "[parameters('identityType')]",
"userAssignedIdentities": "[if(equals(parameters('identityType'), 'userAssigned'), variables('userAssignedIdentities'), json('null'))]"
},
"sku": {
"tier": "[parameters('sku')]",
"name": "[parameters('sku')]"
},
"properties": {
"friendlyName": "[parameters('friendlyName')]",
"description": "[parameters('description')]",
"storageAccount": "[variables('storageAccount')]",
"keyVault": "[if(equals(parameters('managedKeyVaultType'), 'byoKeyVault'), variables('keyVault'), json('null'))]",
"applicationInsights": "[if(not(equals(parameters('applicationInsightsOption'), 'none')), variables('applicationInsights'), json('null'))]",
"containerRegistry": "[if(not(equals(parameters('containerRegistryOption'), 'none')), variables('containerRegistry'), json('null'))]",
"primaryUserAssignedIdentity": "[if(equals(parameters('identityType'), 'userAssigned'), variables('primaryUserAssignedIdentity'), json('null'))]",
"systemDatastoresAuthMode": "[if(not(equals(parameters('systemDatastoresAuthMode'), 'accessKey')), parameters('systemDatastoresAuthMode'), json('null'))]",
"managedNetwork": "[parameters('managedNetwork')]",
"provisionNetworkNow": "[parameters('provisionNetworkNow')]",
"publicNetworkAccess": "[parameters('publicNetworkAccess')]"
}
},
{
"condition": "[not(equals(parameters('delegateSubnetId'), 'none'))]",
"dependsOn": [
"[resourceId('Microsoft.MachineLearningServices/workspaces', parameters('workspaceName'))]"
],
"type": "Microsoft.MachineLearningServices/workspaces/capabilityHosts",
"apiVersion": "2024-10-01-preview",
"name": "[concat(parameters('workspaceName'), '/', parameters('delegateSubnetName'))]",
"location": "[parameters('location')]",
"properties": {
"customerSubnet": "[parameters('delegateSubnetId')]"
}
},
{
"condition": "[not(equals(parameters('privateEndpointType'), 'none'))]",
"type": "Microsoft.Resources/deployments",
"apiVersion": "2020-06-01",
"name": "[variables('privateEndpointDeploymentName')]",
"resourceGroup": "[parameters('privateEndpointResourceGroupName')]",
"subscriptionId": "[parameters('privateEndpointSubscription')]",
"dependsOn": [
"[resourceId('Microsoft.MachineLearningServices/workspaces', parameters('workspaceName'))]"
],
"properties": {
"mode": "Incremental",
"template": {
"$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"resources": [
{
"apiVersion": "2020-06-01",
"name": "[parameters('privateEndpointName')]",
"type": "Microsoft.Network/privateEndpoints",
"location": "[parameters('location')]",
"tags": "[parameters('tagValues')]",
"properties": {
"privateLinkServiceConnections": "[if(equals(parameters('privateEndpointType'), 'AutoApproval'), variables('defaultPEConnections'), json('null'))]",
"manualPrivateLinkServiceConnections": "[if(equals(parameters('privateEndpointType'), 'ManualApproval'), variables('defaultPEConnections'), json('null'))]",
"subnet": {
"id": "[variables('subnet')]"
}
}
}
]
}
}
}
],
"outputs": {}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment