This section will configure the Azure Automation accounts to use a private endpoint with SQL.
Manual Steps:
Step 1: Assign Azure Role to System Assigned Managed Identity (SAMI)
Type in automation in the top search box
Select Automation Accounts
Select aa-automation-00
Select Identity under the Account Settings navigation menu
Select Azure role assignements for the System Assigned Managed Identity
Select the subscription associated with this account
Select + Add role assignment
Fill out the values to add the roles to the aa-spark-automation0 account
Select Save to add the role
Name
Value
Scope
Resource Group
Subscription
The subscription associated with this account
Resource Group
The Resource Group created for SPARK
Role
Automation Operator & Storage Blob Data Contributor
Step 2: Configure Azure Automation Network
Type in automation in the top search box
Select Automation Accounts
Select aa-automation-00
Select Networking under the Account Settings navigation menu
Select the Private access tab
Select + Private endpoint
Fill in the values and select Next
Name
Value
Subscription
The subscription associated with this account
Resource Group
The Resource Group created for SPARK
Name
pe-spark-automation0
Select DSCAndHybridWorker for the Target sub-resource
Select Next
Fill in the values
Select Next
Name
Value
Subscription
The subscription associated with this account
Resource Group
The Resource Group created for SPARK
Private IP Configuration
Statically allocate IP address
Name
pipAgentService
Private IP
10.0.0.11
Name
pipJRDS
Private IP
10.0.0.12
Fill in the values
Select Next until you get to Review + Create
Select Create
Name
Value
Subscription
The subscription associated with this account
Resource Group
The Resource Group created for SPARK
Select Networking under the Account Settings navigation menu
Select Disable and then Apply to remove public network access
Step 3: Create Hybrid Worker Group
Select Hybrid Worker Groups under the Process Automation navigation menu
Select + Create Hybrid Worker Group
Set the Name to hwg-aa-spark-automation0
Select Next until you get to Review + Create
We will create the Virtual Machine in the next step and associate it with this Hybrid Worker Group afterwards.
Select + Add Machine
Select Add
Step 4: Create Virtual Machine
Type in virtual machine in the top search box
Select Virtual Machines
Select Virtual Machines from the left navigation menu
Select + Create and then Virtual Machine
Fill in the values
Select See all images under Image
Name
Value
Subscription
The subscription associated with this account
Resource Group
The Resource Group created for SPARK
Virtual Machine Name
vm-spark-aa0
Region
The Region associated with the Resource Group
Search for windows server
Find Windows Server 2022
Select Windows Server 2022 Datacenter: Azure Edition Core - x64 Gen 2
Select See all sizes under Size
Select D2lds_v7
Set the Username to sparkAdmin
Set the Password to a strong value
If you already have a license, then select and confirm license option
Select Next until you get to Review + Create
Select Create
Select vnet-pe-spark for the Virtual Network
Select the option to create a public ip, and then Next
Check Enable system assigned managed identity under Identity
Select Next until you get to Review + create
Select Create
Step 5: Associate Virtual Network with Hybrid Worker Group
Select Hybrid Worker Groups under the Process Automation navigation menu
Select spark-hwg-automation0
When you associate the VM with the hybrid worker group, it will automatically add the Hybrid Worker Extension to the VM. We must have this complete before testing the runbook.
Select Hybrid Workers from the left navigation
Select + Add
Select the vm-spark-aa0 virtual machine
Select Add
Click on the Azure Virutal Machine link to view the virtual machine
Select Extensions + applications
View the provisioning status
The virtual machine extension must succeed before testing the runbooks.
Step 6: Virtual Machine Modules
Select Connect from the left navigation
Select Configure JIT + Request access
Select Download RDP file
Wait for the JIT request to complete before connecting to the virtual machine.