SqlServer¶
The SqlServer resource creates a managed SQL logical server (PaaS) — on Azure, an Azure SQL logical server (New-AzSqlServer). It is the parent resource for one or more SqlDatabase resources.
Naming and credentials:
- The server name is set in the template (
serverName). Azure SQL logins must present<serverName>.database.windows.net, so the name is an explicit choice — it must be globally unique across Azure. - The administrator password is auto-generated and stored in Vault — it is never part of the template and is not exposed through expressions.
- The administrator login (
administratorLogin) is set in the template — use a template parameter to make it configurable per deployment.
Structure¶
- type: sqlServer
name: sqlsrv # unique identifier within the RGT
displayName: App SQL Server # optional
serverName: zh0042 # Azure SQL server name (globally unique)
administratorLogin: sqladmin # SQL administrator login name
alias: # optional, DNS CNAME records -> server FQDN
- sql-app11
privateLink: true # optional, default false
subnet: db-subnet # optional, subnet for the private endpoint (CIDR or display name)
location: switzerlandnorth # optional, override default location
tags: # optional
env: prod
providerConfig: # optional, provider-specific settings
azure:
serverVersion: "12.0"
minimalTlsVersion: "1.2"
publicNetworkAccess: false
identity:
type: SystemAssigned
entraAdmin:
displayName: sql-admins-aad-group
objectId: 00000000-0000-0000-0000-000000000000
| Key | Required | Description |
|---|---|---|
type |
Yes | Must be sqlServer |
name |
Yes | Unique identifier within the RGT (used in expressions) |
displayName |
No | Display name of the Dune resource |
description |
No | Description of the Dune resource |
serverName |
Yes | Azure SQL logical server name — becomes <serverName>.database.windows.net. Globally unique across Azure; 1–63 lowercase letters, digits and hyphens. |
administratorLogin |
Yes | SQL administrator login name. The password is auto-generated and written to Vault. |
alias |
No | List of DNS CNAME records created in the default DNS zone, pointing at the server FQDN. Removed again when the resource is removed. |
privateLink |
No | true creates a private endpoint with a pre-reserved static IP and binds the private DNS zone (privatelink.database.windows.net). Default false. |
subnet |
No | Subnet for the private endpoint (CIDR or display name). Only used when privateLink: true. Defaults to the resource group subnet. |
location |
No | Override the default location |
tags |
No | Tags applied to the provider resource |
providerConfig |
No | Provider-specific settings, see below |
providerConfig.azure¶
| Key | Required | Default | Description |
|---|---|---|---|
serverVersion |
No | 12.0 |
Azure SQL logical server version |
minimalTlsVersion |
No | 1.2 |
Minimal inbound TLS version (1.0–1.3) |
publicNetworkAccess |
No | derived | Boolean. Defaults to false when privateLink: true, otherwise true. An explicit value always wins — a private endpoint and public access can coexist. |
identity.type |
No | SystemAssigned |
Managed identity: None, SystemAssigned or UserAssigned |
identity.userAssignedIdentityIds |
Yes (UserAssigned) | — | Resource IDs of user-assigned managed identities. The first entry becomes the primary identity. |
entraAdmin.displayName / entraAdmin.objectId |
No | — | Bind an Entra ID (Azure AD) principal as SQL administrator. Both values must be provided together; omitted entirely, no Entra admin is set. |
Administrator Credentials¶
The administrator password is generated during deployment and stored in Vault:
- Path:
deployments/<DeploymentName>/sqlServer - Key:
administrator_password
Password is not available in expressions
Unlike the service account's svcpassword, the SQL administrator password is not exposed through template expressions — {{sqlserver.<name>.administratorPassword}} does not resolve. Config tasks that need it must read it from Vault.
Private Link¶
With privateLink: true:
- A free IP is reserved in the selected subnet and assigned to the private endpoint as a static address.
- The private endpoint is created for the SQL server and joined to the private DNS zone (
privatelink.database.windows.net), so the server FQDN resolves to the private IP inside the network. - Public network access defaults to disabled (override via
providerConfig.azure.publicNetworkAccess: true).
Connecting via alias
Azure SQL only accepts logins that present the original server hostname. When connecting through an alias CNAME (or any other DNS name), SQL logins fail with error 40532 unless the username is given as <user>@<serverName> (e.g. sqladmin@zh0042).
Reference Format¶
Use {{sqlserver.<name>.<property>}} to reference the SQL server in expressions.
| Expression | Type | Example output |
|---|---|---|
{{sqlserver.sqlsrv}} |
string | zh0042.database.windows.net (FQDN) |
{{sqlserver.sqlsrv.fqdn}} |
string | zh0042.database.windows.net |
{{sqlserver.sqlsrv.servername}} |
string | zh0042 |
{{sqlserver.sqlsrv.administratorlogin}} |
string | sqladmin |
{{sqlserver.sqlsrv.privateipaddress}} |
string | 10.10.4.20 (only with privateLink: true) |
{{sqlserver.sqlsrv.alias[0]}} |
string | sql-app11 |
Note
{{sqlserver.<name>}} resolves to the FQDN — what connection strings need. This differs from compute nodes, where {{computenode.<name>}} resolves to the short hostname.
Modifiers (Variables)¶
All variables are resolved on the ResourceGroup scope but can be defined anywhere up the hierarchy (e.g. on the Tenant) — an explicit template value always wins.
| Variable | Type | Required | Level | Default | Description |
|---|---|---|---|---|---|
CUSTOM_SUBNET_NAME |
string | No | ResourceGroup | — | Override the subnet used for the private endpoint |
DEFAULT_DNS_RESOURCEPROVIDER |
string | Yes (alias) | Variable | — | DNS resource provider used to create the alias CNAME records |
Example¶
An Azure SQL server with private endpoint, an Entra admin group and a database (see SqlDatabase):
resources:
- type: sqlServer
name: sqlsrv
displayName: App SQL Server
serverName: zh0042
administratorLogin: sqladmin
privateLink: true
subnet: db-subnet
alias:
- sql-app11
providerConfig:
azure:
entraAdmin:
displayName: sql-admins-aad-group
objectId: 00000000-0000-0000-0000-000000000000
- type: sqlDatabase
name: appdb
server: sqlsrv
databaseName: App11_Main
providerConfig:
azure:
sku: GP_S_Gen5_2
maxSize: 100GB
Next: SqlDatabase