Skip to content

SqlServer

The SqlServer resource creates a managed SQL logical server (PaaS) — on Azure, an Azure SQL logical server (New-AzSqlServer). It is the parent resource for one or more SqlDatabase resources.

Naming and credentials:

  • The server name is set in the template (serverName). Azure SQL logins must present <serverName>.database.windows.net, so the name is an explicit choice — it must be globally unique across Azure.
  • The administrator password is auto-generated and stored in Vault — it is never part of the template and is not exposed through expressions.
  • The administrator login (administratorLogin) is set in the template — use a template parameter to make it configurable per deployment.

Structure

- type: sqlServer
  name: sqlsrv                          # unique identifier within the RGT
  displayName: App SQL Server           # optional
  serverName: zh0042                    # Azure SQL server name (globally unique)
  administratorLogin: sqladmin          # SQL administrator login name
  alias:                                # optional, DNS CNAME records -> server FQDN
    - sql-app11
  privateLink: true                     # optional, default false
  subnet: db-subnet                     # optional, subnet for the private endpoint (CIDR or display name)
  location: switzerlandnorth            # optional, override default location
  tags:                                 # optional
    env: prod
  providerConfig:                       # optional, provider-specific settings
    azure:
      serverVersion: "12.0"
      minimalTlsVersion: "1.2"
      publicNetworkAccess: false
      identity:
        type: SystemAssigned
      entraAdmin:
        displayName: sql-admins-aad-group
        objectId: 00000000-0000-0000-0000-000000000000
Key Required Description
type Yes Must be sqlServer
name Yes Unique identifier within the RGT (used in expressions)
displayName No Display name of the Dune resource
description No Description of the Dune resource
serverName Yes Azure SQL logical server name — becomes <serverName>.database.windows.net. Globally unique across Azure; 1–63 lowercase letters, digits and hyphens.
administratorLogin Yes SQL administrator login name. The password is auto-generated and written to Vault.
alias No List of DNS CNAME records created in the default DNS zone, pointing at the server FQDN. Removed again when the resource is removed.
privateLink No true creates a private endpoint with a pre-reserved static IP and binds the private DNS zone (privatelink.database.windows.net). Default false.
subnet No Subnet for the private endpoint (CIDR or display name). Only used when privateLink: true. Defaults to the resource group subnet.
location No Override the default location
tags No Tags applied to the provider resource
providerConfig No Provider-specific settings, see below

providerConfig.azure

Key Required Default Description
serverVersion No 12.0 Azure SQL logical server version
minimalTlsVersion No 1.2 Minimal inbound TLS version (1.0–1.3)
publicNetworkAccess No derived Boolean. Defaults to false when privateLink: true, otherwise true. An explicit value always wins — a private endpoint and public access can coexist.
identity.type No SystemAssigned Managed identity: None, SystemAssigned or UserAssigned
identity.userAssignedIdentityIds Yes (UserAssigned) — Resource IDs of user-assigned managed identities. The first entry becomes the primary identity.
entraAdmin.displayName / entraAdmin.objectId No — Bind an Entra ID (Azure AD) principal as SQL administrator. Both values must be provided together; omitted entirely, no Entra admin is set.

Administrator Credentials

The administrator password is generated during deployment and stored in Vault:

  • Path: deployments/<DeploymentName>/sqlServer
  • Key: administrator_password

Password is not available in expressions

Unlike the service account's svcpassword, the SQL administrator password is not exposed through template expressions — {{sqlserver.<name>.administratorPassword}} does not resolve. Config tasks that need it must read it from Vault.

With privateLink: true:

  1. A free IP is reserved in the selected subnet and assigned to the private endpoint as a static address.
  2. The private endpoint is created for the SQL server and joined to the private DNS zone (privatelink.database.windows.net), so the server FQDN resolves to the private IP inside the network.
  3. Public network access defaults to disabled (override via providerConfig.azure.publicNetworkAccess: true).

Connecting via alias

Azure SQL only accepts logins that present the original server hostname. When connecting through an alias CNAME (or any other DNS name), SQL logins fail with error 40532 unless the username is given as <user>@<serverName> (e.g. sqladmin@zh0042).

Reference Format

Use {{sqlserver.<name>.<property>}} to reference the SQL server in expressions.

Expression Type Example output
{{sqlserver.sqlsrv}} string zh0042.database.windows.net (FQDN)
{{sqlserver.sqlsrv.fqdn}} string zh0042.database.windows.net
{{sqlserver.sqlsrv.servername}} string zh0042
{{sqlserver.sqlsrv.administratorlogin}} string sqladmin
{{sqlserver.sqlsrv.privateipaddress}} string 10.10.4.20 (only with privateLink: true)
{{sqlserver.sqlsrv.alias[0]}} string sql-app11

Note

{{sqlserver.<name>}} resolves to the FQDN — what connection strings need. This differs from compute nodes, where {{computenode.<name>}} resolves to the short hostname.

Modifiers (Variables)

All variables are resolved on the ResourceGroup scope but can be defined anywhere up the hierarchy (e.g. on the Tenant) — an explicit template value always wins.

Variable Type Required Level Default Description
CUSTOM_SUBNET_NAME string No ResourceGroup — Override the subnet used for the private endpoint
DEFAULT_DNS_RESOURCEPROVIDER string Yes (alias) Variable — DNS resource provider used to create the alias CNAME records

Example

An Azure SQL server with private endpoint, an Entra admin group and a database (see SqlDatabase):

resources:
  - type: sqlServer
    name: sqlsrv
    displayName: App SQL Server
    serverName: zh0042
    administratorLogin: sqladmin
    privateLink: true
    subnet: db-subnet
    alias:
      - sql-app11
    providerConfig:
      azure:
        entraAdmin:
          displayName: sql-admins-aad-group
          objectId: 00000000-0000-0000-0000-000000000000
  - type: sqlDatabase
    name: appdb
    server: sqlsrv
    databaseName: App11_Main
    providerConfig:
      azure:
        sku: GP_S_Gen5_2
        maxSize: 100GB

Next: SqlDatabase