IBM's Azure Foundry Enterprise Kit

Bicep Module Reference

27 production-grade Bicep modules — each module documents the Azure resources provisioned, key parameters, security configurations, compliance policies, and outputs. Click any module to expand full details.

Showing 25 of 25 modules

Provisions the user-assigned managed identity (UAMI) used as the primary workload identity for the Foundry platform, plus all subscription/resource-level RBAC assignments.

ZT-01Identity

Provisions the private network fabric — VNet, subnets (agent, private-endpoint, MCP), NSGs with service-tag rules, and Private DNS zones for all PaaS services.

ZT-03Networking

Provisions a Standard-tier Azure Key Vault with RBAC authorization, soft-delete, purge protection, CMK keys, and pre-seeded placeholder secrets.

ZT-04Security

Provisions a Cosmos DB NoSQL account in serverless mode with vector search, three purpose-built containers (agent-memory, decision-ledger, agent-scorecards), and CMK encryption.

ZT-04ZT-07Data

Provisions an Azure AI Search service (Standard S1) with semantic ranking, CMK encryption via Key Vault, RBAC data-plane access, and optional private endpoint.

ZT-03ZT-04AI Services

Provisions the RAG pipeline — search index with vector fields, skillset (chunking + embedding + PII redaction), blob data source, and scheduled indexer.

ZT-01ZT-04AI Services

Provisions the Azure AI Foundry Hub and child Project workspace with AgentService, Evaluations, Tracing, and Control Plane feature flags enabled.

ZT-01AI Services

Publishes a Foundry agent as an ARM-native Agent Application with its own stable endpoint, Entra agent identity, independent RBAC, and Responses/Activity Protocol support.

ZT-01ZT-02Agent Runtime

Provisions Log Analytics Workspace, Application Insights (workspace-based), and three Action Groups with alert rules for guardrails, eval score drift, and token usage spikes.

ZT-08Observability

Deploys Azure API Management as the unified API/AI/Model/MCP Gateway — JWT validation, rate limiting, content safety policies, token metrics, and VNet integration.

ZT-02ZT-06ZT-07Networking

Deploys Azure AI Content Safety for prompt shields, content moderation (hate/sexual/self-harm/violence), PII detection, task adherence, and protected material checks.

ZT-03Security

Configures Foundry guardrails with controls for content safety severity, PII detection, task adherence, prompt attack detection, and tool call/response scanning.

ZT-03Security

Configures Foundry Toolbox governance — centralized, versioned, MCP-compatible tool registry with managed authentication, approval gates, and APIM AI Gateway routing.

ZT-12Agent Runtime

Provisions infrastructure for evaluation-driven recertification — Cosmos container for eval results, alert rules for quality degradation, and recertification triggers.

ZT-14Observability

Defines and assigns the "Foundry Agent Governance Baseline" policy initiative with 5 custom policies enforcing managed identity, App Insights, Key Vault, network, and CMK controls.

ZT-09Governance

Provisions the Entra Agent Identity Blueprint — a user-assigned managed identity with federated credentials for GitHub Actions OIDC and Foundry Agent Service token exchange.

ZT-01Identity

Deploys the Zero Trust Runtime Interceptor as a Container App — intercepts every agent action and validates against policy before execution, with kill switch and circuit breakers.

ZT-05Agent Runtime

Provisions Azure API Center as the organization-scoped Private Tool Catalog for MCP server discovery, governance, versioning, and access management.

ZT-12ZT-15Governance

Provisions Azure Consumption budgets with tiered alert thresholds (50%/80%/100% actual + 120% forecast) and action groups for cost anomaly notifications.

Provisions a hub-spoke VNet topology with Azure Firewall (threat intel deny, IDS), optional Bastion, UDR route tables, and bi-directional VNet peering.

ZT-09Networking

Helper module that creates the spoke-to-hub direction of VNet peering, deployed in the spoke VNet resource group scope.

Creates Azure Policy assignments enforcing data residency — restricts all resource and resource group creation to approved Azure regions only.

ZT-04Governance

Provisions Chaos Studio experiments for resilience testing — network disruption and CPU pressure experiments targeting Container Apps and Cosmos DB.

ZT-11Observability

Provisions Azure Traffic Manager for multi-region agent endpoint failover — priority-based routing with health probes and automatic DR failover.

ZT-11Networking

Provisions Azure Managed HSM (FIPS 140-3 Level 3) for sovereign key management in regulated industries — hardware-isolated cryptographic key governance.

ZT-04Security