SPARK Private Endpoints
Private Endpoints allow Azure services to communicate over a private IP address inside a Virtual Network instead of using public service endpoints. In this design, Azure SQL is placed behind a Private Endpoint so database traffic stays on the private network path and public SQL exposure can be removed. The application path uses an Azure Function App connected to the VNet so it can resolve and reach the Azure SQL Private Endpoint. The automation path requires a different pattern because Azure Automation cloud-hosted runbook jobs cannot directly access Azure resources that are secured only by Private Endpoints. Microsoft documents this limitation and states that the supported workaround is to use a Hybrid Runbook Worker.
For Azure Automation, the runbook must execute on a VM that is deployed inside, or network-connected to, the private VNet where the SQL Private Endpoint is reachable. That VM is registered as a Hybrid Runbook Worker, and the runbook is configured to run on that worker group instead of running in the default Azure Automation cloud sandbox. The default Azure Automation cloud execution environment is not attached to the customer VNet, so it cannot reach private IP addresses created by Private Endpoints. In this model, the Hybrid Worker VM becomes the execution plane for automation tasks that need private access to Azure SQL.
Requirements
The Azure Administrator will be required for this step. The user must have:
- Global Administrator Role
- Owner role for the resource group
- Access to the Azure Portal
- PnP.PowerShell installed
- PnP App Certificate generated during Step 5 of the Pre-Deployment Guide
The user assigned managed identity (UAMI) must be updated to use a system assigned managed idenitity (SAMI)1 for the hybrid worker.
The required permissions2 for the PnP.PowerShell script will require at a minimum:
- AppRoleAssignment.ReadWrite.All
- Application.Read.All
Configuration Steps
We will break out the configuration to setup the Virtual Network, Azure Automation and Function Apps separately.