Skip to content

Instantly share code, notes, and snippets.

View matt-FFFFFF's full-sized avatar
🙀

Matt White matt-FFFFFF

🙀
View GitHub Profile
@matt-FFFFFF
matt-FFFFFF / apim-appinsights
Created August 18, 2020 21:21
azure-apim-appinsights.json
{
"$schema": "http://schema.management.azure.com/schemas/2014-04-01-preview/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"name": {
"type": "String"
},
"location": {
"type": "String"
},
@matt-FFFFFF
matt-FFFFFF / .localrc
Created August 14, 2020 14:22
.localrc
export KEYVAULT=<<<CHANGEME>>>
# Configure ssh forwarding
export SSH_AUTH_SOCK=$HOME/.ssh/agent.sock
# need `ps -ww` to get non-truncated command for matching
# use square brackets to generate a regex match for the process we want but that doesn't match the grep command running it!
ALREADY_RUNNING=$(ps -auxww | grep -q "[n]piperelay.exe -ei -s //./pipe/openssh-ssh-agent"; echo $?)
if [[ $ALREADY_RUNNING != "0" ]]; then
if [[ -S $SSH_AUTH_SOCK ]]; then
# not expecting the socket to exist as the forwarding command isn't running (http://www.tldp.org/LDP/abs/html/fto.html)
@matt-FFFFFF
matt-FFFFFF / deploy-azure-backup.json
Created July 27, 2020 22:12
Azure Backup Policy Sample
{
"mode": "All",
"policyRule": {
"if": {
"allOf": [
{
"equals": "Microsoft.Compute/virtualMachines",
"field": "type"
},
{
@matt-FFFFFF
matt-FFFFFF / NSG-Flow-Log-Analytics-policydef.json
Last active July 21, 2020 10:56
NSG flow logs and traffic analytics policy def
{
"mode": "All",
"policyRule": {
"if": {
"equals": "Microsoft.Network/networkSecurityGroups",
"field": "type"
},
"then": {
"details": {
"deployment": {
{
"$schema": "http://schema.management.azure.com/schemas/2015-01-01/deploymentParameters.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"input": {
"value": {
"Name": "0fb51766-9c3f-422c-a5c7-322d7ef8afa8",
"ResourceType": "Microsoft.Management/managementGroups",
"ExtensionResourceType": "Microsoft.Authorization/roleDefinitions",
"Location": "northeurope",
#!/bin/bash
# Script to clean up after Enterprise-Scale - DO NOT RUN IN PRODUCTION
echo "THIS SCRIPT WILL DESTROY YOUR AZURE ENVIRONMENT"
read -n 4 -p "Are you SURE you want to do this? (type 'yes' to continue): " YES
if [ ! "$YES" == "yes" ]; then
echo "Confirmation denied - quitting"
exit 0
@matt-FFFFFF
matt-FFFFFF / win10kvmguest.xml
Created March 16, 2020 22:48
KVM Windows 10 Guest w/ UEFI, HPET, USB3, more
<domain type="kvm">
<name>Windows10</name>
<uuid>ccae4198-1930-4f33-9e73-8edda15e89ba</uuid>
<title>Windows10</title>
<metadata>
<libosinfo:libosinfo xmlns:libosinfo="http://libosinfo.org/xmlns/libvirt/domain/1.0">
<libosinfo:os id="http://microsoft.com/win/10"/>
</libosinfo:libosinfo>
</metadata>
<memory unit="KiB">6291456</memory>
@matt-FFFFFF
matt-FFFFFF / ketkvsecret.sh
Last active February 26, 2020 10:37
Get Key Vault secret
#!/bin/sh
# matt.white@microsoft.com
# Gets a secret from Azure key vault.
# See usage()
COMMANDS="az basename"
for COMMAND in $COMMANDS; do
@matt-FFFFFF
matt-FFFFFF / akscreate.sh
Last active February 21, 2020 10:00
az aks create
#! /bin/bash
az aks create \
--resource-group $RESOURCE_GROUP \
--network-plugin azure \
--vnet-subnet-id /subscriptions/$ARM_SUBSCRIPTION_ID/resourceGroups/$RESOURCE_GROUP/providers/Microsoft.Network/virtualNetworks/$VNET_NAME/subnets/$SUBNET_NAME \
--docker-bridge-address 172.17.0.1/16 \
--dns-service-ip 172.18.0.10 \
--service-cidr 172.18.0.0/16 \
--generate-ssh-keys \
--vm-set-type VirtualMachineScaleSets \
@matt-FFFFFF
matt-FFFFFF / GovWifi.8021x
Created February 11, 2020 09:39
GovWifi Linux connection with iwd
[Security]
EAP-Method=PEAP
EAP-Identity=anonymous
EAP-PEAP-CACert=/etc/ca-certificates/extracted/cadir/DigiCert_Global_Root_CA.pem
EAP-PEAP-ServerDomainMask=wifi.service.gov.uk
EAP-PEAP-Phase2-Method=MSCHAPV2
EAP-PEAP-Phase2-Identity=<username>
EAP-PEAP-Phase2-Password=<password>
[Settings]