Bicep — Container Apps Patterns
Container Apps-specific Bicep patterns. For shared patterns (skeleton, naming, tags, security defaults, data modules), see bicep-patterns.md.
Two-Phase Wiring
Container Apps + ACR requires two-phase deployment (circular dependency: CA needs ACR image, ACR needs CA identity for AcrPull):
- Phase 1: Deploy Container App with placeholder image (
mcr.microsoft.com/azuredocs/containerapps-helloworld:latest). ⛔ Noregistriesblock, no KVsecretRef. The placeholder image is pulled from MCR (public). Useregistries: []andsecrets: []. RBAC role assignments (AcrPull, KV Secrets User) ARE created in Phase 1 — they don't affect the placeholder deployment and need 1–2 minutes to propagate before Phase 2. - Phase 2: Build + push app image to ACR, redeploy with real image +
registries+ KVsecretRefentries. RBAC is already propagated from Phase 1.
⛔ Placeholder image listens on port 80, not your app's port. Set
targetPortconditionally:var effectivePort = containerImage == 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest' ? 80 : appPort. Mismatched ports cause "Operation expired" (health probe can't reach container).
⛔
containerImageparam must exist in BOTHmain.bicepAND the container app module. Phase 2 passes--parameters containerImage='...'via CLI — ifmain.biceplacks the param, the override is silently ignored and the placeholder persists.
// In main.bicep: thread containerImage to module
param containerImage string = 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'
module containerApp './modules/containerapp.bicep' = {
params: { containerImage: containerImage /* ...other params... */ }
}
// In containerapp.bicep:
param containerImage string = 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'
var isPlaceholder = containerImage == 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'
resource containerApp 'Microsoft.App/containerApps@2024-03-01' = {
identity: { type: 'SystemAssigned' }
properties: {
configuration: {
ingress: {
external: true
targetPort: isPlaceholder ? 80 : appPort
allowInsecure: false // ⛔ MANDATORY
}
registries: isPlaceholder ? [] : [{ server: acr.properties.loginServer, identity: 'system' }]
secrets: isPlaceholder ? [] : [ /* KV secretRefs here */ ]
}
template: {
containers: [{
image: containerImage
env: [{ name: 'PORT', value: string(isPlaceholder ? 80 : appPort) }]
}]
}
}
}⛔ Do NOT set
revisionSuffix. Omit it entirely — ARM auto-generates unique revision names. HardcodingrevisionSuffix: 'v1'causes Phase 2 redeploy to fail with "revision with suffix v1 already exists."
AcrPull Role Assignment
⛔ AcrPull role GUID:
7f951dda-4ed3-4680-a7ca-43fe172d538d. Copy verbatim — wrong GUIDs causeRoleDefinitionDoesNotExist.
resource acrPullRole 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
name: guid(acr.id, containerApp.id, '7f951dda-4ed3-4680-a7ca-43fe172d538d')
scope: acr
properties: {
roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', '7f951dda-4ed3-4680-a7ca-43fe172d538d')
principalId: containerApp.identity.principalId
principalType: 'ServicePrincipal'
}
}Log Analytics Workspace Key
⛔ Use
resource.listKeys(), NOTreference().reference()does not exposeprimarySharedKey.
// ✅ Correct
var laKey = logAnalyticsWorkspace.listKeys().primarySharedKey
// ❌ Wrong
var laKey = reference(logAnalyticsWorkspace.id, '2023-09-01').primarySharedKeyLog Analytics customerId vs resource ID
⛔ Output BOTH
idandcustomerIdfrom the log-analytics module. Container Apps Environment needs the GUIDcustomerId. App Insights needs the ARM resource ID. Do NOT usesplit(workspaceId, '/')[8]— that extracts the workspace name, not the GUID.
// log-analytics.bicep outputs:
output id string = logAnalyticsWorkspace.id // ARM resource ID
output customerId string = logAnalyticsWorkspace.properties.customerId // GUID
output sharedKey string = logAnalyticsWorkspace.listKeys().primarySharedKey
// container-app-environment.bicep:
param workspaceCustomerId string // GUID, NOT resource ID
// ⛔ MUST nest under appLogsConfiguration.destination='log-analytics' — a bare top-level logAnalyticsConfiguration fails deploy (ManagedEnvironmentInvalidSchema). This nesting is the ONLY valid location at EVERY API version (the flat shape was never valid — NOT version drift, so do not chase API-version pins). This is the CA's only log path (no diagnostic-settings module).
properties: {
appLogsConfiguration: {
destination: 'log-analytics'
logAnalyticsConfiguration: {
customerId: workspaceCustomerId
sharedKey: workspaceSharedKey
}
}
}
// ❌ WRONG: customerId: split(workspaceId, '/')[8]Ingress & Port Mapping
⛔ Container resource limits: Use decimal format for memory:
'0.5Gi','1Gi','2Gi'— NOT Kubernetes-style'512Mi'. CPU must be typestring:'0.25','0.5','1'. Valid combos:0.25/0.5Gi,0.5/1Gi,0.75/1.5Gi,1/2Gi,1.25/2.5Gi,1.5/3Gi,1.75/3.5Gi,2/4Gi.
⛔ ACR module:
retentionPolicyis Premium-only. For Basic/Standard ACR, omitretentionPolicyentirely — ARM rejects it.
Key Vault Secret References
⛔ Container Apps does NOT support
@Microsoft.KeyVault(SecretUri=...)syntax. That is App Service-only. Container Apps usessecretRefwith managed identity.
Correct pattern — Container Apps secrets from Key Vault:
❌ WRONG —
environment().suffixes.keyvaultDnsproduces double-dot URL:keyVaultUrl: 'https://${kvName}${environment().suffixes.keyvaultDns}/secrets/...'That function returns.vault.azure.net(WITH leading dot) →kv-name..vault.azure.net→ContainerAppSecretKeyVaultUrlInvalid. ✅ UsekeyVault.name+.vault.azure.net(hardcoded domain) orkeyVaultModule.outputs.vaultUri.
⛔ Every
secrets[].keyVaultUrlin a Container App MUST have a matchingMicrosoft.KeyVault/vaults/secretschild resource in the KV module. If the CA referencessshpassvia secretRef, the KV module must create that secret. Missing secrets →SecretNotFoundat Phase 2 deploy.
resource containerApp 'Microsoft.App/containerApps@2024-03-01' = {
identity: {
type: 'SystemAssigned'
}
properties: {
configuration: {
secrets: [
{
name: 'db-connection-string'
// ⛔ Do NOT replace vault.azure.net with environment().suffixes.keyvaultDns — it adds a leading dot → double-dot URL
#disable-next-line no-hardcoded-env-urls
keyVaultUrl: 'https://${keyVault.name}.vault.azure.net/secrets/db-connection-string'
identity: 'system' // Uses the CA's system-assigned managed identity
}
]
}
template: {
containers: [{
env: [
{
name: 'DATABASE_URL'
secretRef: 'db-connection-string' // References the secret defined above
}
]
}]
}
}
}⛔ Never use conditional logic (
??, ternary,empty(),union()) to mix plain and secret env vars in a single Bicep loop or array. ARM evaluates ALL property paths in conditional expressions —envVar.secretReferrors on items that don't have that property, producingInvalidTemplate. Instead, define plain and secret env vars as separate arrays and concatenate:env: concat( [ { name: 'PORT', value: '8000' } { name: 'NODE_ENV', value: 'production' } ], [ { name: 'DATABASE_URL', secretRef: 'db-connection-string' } { name: 'REDIS_URL', secretRef: 'redis-connection-string' } ] )
⛔ KV Secrets User role scoped to Key Vault resource — NOT
resourceGroup(). Scoping toresourceGroup()causes 403.
resource kvRole 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
scope: keyVault // ⛔ scope to KV resource, not RG
properties: {
roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', '4633458b-17de-408a-b874-0445c86b69e6') // Key Vault Secrets User
principalId: containerApp.identity.principalId // ⛔ object ID, NOT clientId
principalType: 'ServicePrincipal'
}
}❌ WRONG:
principalId: .clientId(not the object ID) oridentity: containerApp.idin secrets[] (use'system'for system-assigned MI).
For KV secret seeding and dependency chain, see env-var-secrets.md.
Multi-Container Internal DNS
Container Apps in the same environment communicate via internal DNS: http://{container-app-name}. Set via env vars:
env: [
{ name: 'API_URL', value: 'http://${apiContainerApp.name}' }
{ name: 'WORKER_URL', value: 'http://${workerContainerApp.name}' }
]No ingress needed for internal-only services — set ingress.external: false or omit ingress entirely.
Networking
⛔ Subnets MUST be defined inline in VNet
properties.subnets[], NOT as separateMicrosoft.Network/virtualNetworks/subnetschild resources. Separate child resources causeInUseSubnetCannotBeDeletedon redeploy when NICs are attached.