Skip to content

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

Terraform Assessment - OpenWebUI on Azure Container Apps

This repository deploys Open WebUI on Azure Container Apps using Terraform, including:

  • Resource Group
  • Storage Account with two Azure File Shares
  • Container Apps Environment
  • User-assigned managed identity
  • Container App with persistent mounts, external ingress, custom domain, managed certificate, autoscaling, and health probes
  • Key Vault secret references via managed identity (no plaintext secrets in Terraform code)

Architecture

  • azurerm_storage_share.models mounted at /app/chat_frontend/models
  • azurerm_storage_share.backend_data mounted at /app/backend/data
  • External ingress enabled on port 8080
  • Custom domain bound via azurerm_container_app_custom_domain with Azure-managed TLS certificate (certificate_binding_type = Auto behavior managed by Azure)
  • Scaling configured between 1 and 10 replicas
  • CPU custom scale rule with 75% utilization target
  • Liveness and readiness probes on /health

Security Notes

  • Secrets are not hardcoded in .tf files.
  • Secret values are not read by Terraform. The app uses Key Vault Secret Identifier URIs through:
    • Container App secret { key_vault_secret_id = ... identity = ... }
    • User-assigned managed identity
    • Key Vault Secrets User RBAC assignment on the existing Key Vault
  • .tfvars and state files are ignored by .gitignore.

Note: Azure Container Apps environment storage currently requires an Azure Files access key in the environment storage resource. This value is provider-managed and sensitive, but may still appear in Terraform state metadata depending on provider behavior.

Files

  • versions.tf - Terraform and provider versions
  • providers.tf - AzureRM provider configuration
  • variables.tf - documented inputs
  • main.tf - base infrastructure resources
  • container_app.tf - Open WebUI container app (identity, secrets, probes, scaling, mounts, ingress)
  • dns_custom_domain.tf - custom domain binding and optional Azure DNS records
  • outputs.tf - useful outputs for validation/demo
  • terraform.tfvars.example - sample variable values

Prerequisites

  • Terraform >= 1.5
  • Azure CLI logged in (az login)
  • Sufficient permissions to create:
    • Resource group resources
    • Role assignments
    • Container Apps resources
    • Storage resources
  • Existing Azure Key Vault with RBAC enabled and at least one secret (for example WEBUI_SECRET_KEY)
  • A domain name for custom domain binding

Deployment Steps

  1. Copy the example variables:
cp terraform.tfvars.example terraform.tfvars
  1. Edit terraform.tfvars:

    • Set subscription_id, resource_group_name, location
    • Set key_vault_id
    • Set key_vault_secrets with secret URIs and environment variable mapping
    • Set custom_domain
    • If DNS zone is in Azure and you want Terraform to create records, set:
      • create_azure_dns_records = true
      • dns_zone_name
      • dns_zone_resource_group_name
  2. Initialize and deploy:

terraform init
terraform plan -out tfplan
terraform apply tfplan

DNS and TLS

If create_azure_dns_records = true, Terraform creates:

  • TXT: asuid.<subdomain> with custom_domain_verification_id
  • CNAME: <subdomain> -> Container App FQDN

If DNS is outside Azure:

  • Use terraform output custom_domain_verification_id to create TXT record manually
  • Use terraform output container_app_default_fqdn for CNAME target
  • Re-run terraform apply after DNS propagates

Azure provisions the managed certificate asynchronously after domain validation.

Validation Checklist (Assessment)

  • terraform plan and terraform apply run successfully
  • Open WebUI reachable at https://<custom_domain>
  • Data persists after app restart:
    • files under /app/backend/data
    • files under /app/chat_frontend/models
  • Autoscaling:
    • min replicas = 1
    • max replicas = 10
    • CPU rule target 75
  • Secrets:
    • loaded from Key Vault URI references
    • exposed as env vars through container app secret mapping
  • Health probes:
    • liveness /health
    • readiness /health

Useful Commands

terraform output
terraform state list
az containerapp show -g <resource_group> -n <app_name> --query "properties.configuration.ingress.fqdn" -o tsv

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages