Skip to content

Add GSA proxy bicep templates for private network agent setup#527

Draft
shyamshd wants to merge 1 commit intomicrosoft-foundry:mainfrom
shyamshd:add_gsa_bicep_templates
Draft

Add GSA proxy bicep templates for private network agent setup#527
shyamshd wants to merge 1 commit intomicrosoft-foundry:mainfrom
shyamshd:add_gsa_bicep_templates

Conversation

@shyamshd
Copy link

Add bicep modules to deploy a GSA AI Connector proxy VM into the existing agent VNet, enabling egress traffic inspection and authentication for network-secured AI Foundry agent deployments.

New files:

  • deploy-gsa-proxy.bicep: Orchestrator template for GSA proxy deployment
  • deploy-gsa-proxy.bicepparam: Parameter file with defaults
  • modules-network-secured/gsa-proxy.bicep: Core module deploying:
    • GSA proxy subnet with NSG (allows VirtualNetwork traffic)
    • VM from GSA AI Connector marketplace image with managed identity
    • NIC with IP forwarding enabled
    • UDR routing 0/0 from agent subnet to proxy, with exceptions for AzureActiveDirectory, AzureResourceManager, AzureMonitor, GuestAndHybridManagement, AzureContainerRegistry, AzureKeyVault, and Storage service tags
  • modules-network-secured/agent-subnet-udr-association.bicep: Associates the UDR with the agent subnet while preserving existing delegation and NSG configuration

Add bicep modules to deploy a GSA AI Connector proxy VM into the
existing agent VNet, enabling egress traffic inspection and authentication
for network-secured AI Foundry agent deployments.

New files:
- deploy-gsa-proxy.bicep: Orchestrator template for GSA proxy deployment
- deploy-gsa-proxy.bicepparam: Parameter file with defaults
- modules-network-secured/gsa-proxy.bicep: Core module deploying:
  - GSA proxy subnet with NSG (allows VirtualNetwork traffic)
  - VM from GSA AI Connector marketplace image with managed identity
  - NIC with IP forwarding enabled
  - UDR routing 0/0 from agent subnet to proxy, with exceptions for
    AzureActiveDirectory, AzureResourceManager, AzureMonitor,
    GuestAndHybridManagement, AzureContainerRegistry, AzureKeyVault,
    and Storage service tags
- modules-network-secured/agent-subnet-udr-association.bicep: Associates
  the UDR with the agent subnet while preserving existing delegation
  and NSG configuration
@shyamshd shyamshd force-pushed the add_gsa_bicep_templates branch from afe6b09 to e009176 Compare February 12, 2026 01:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant