OPEN SOURCE

Azure Blueprints.

Production-ready Azure IaC modules. Bicep and Terraform.
Free to use, practical to extend, and aligned to regulated delivery.

What You Get
  • Modules: reusable Bicep + Terraform for landing zones, security, and governance.
  • Blueprints: reference architectures you can deploy and extend.
  • Compliance: CIS, NIST 800-53, and CMMC alignment built in.
15+
Modules
3
Blueprints
Bicep
& Terraform
Apache
License
Module Catalog

Landing Zone

management-groups

CAF-aligned management group hierarchy

hub-spoke-network

Enterprise hub-spoke topology with Azure Firewall

azure-firewall

Azure Firewall Premium with IDPS

policy-baseline

CIS benchmark policy sets

identity-baseline

Entra ID hardening and RBAC

Security

defender-for-cloud

Microsoft Defender configuration

sentinel

Azure Sentinel SIEM deployment

key-vault

Key Vault with private endpoints

private-endpoints

Private Link configurations

Governance

azure-policy-sets

Regulatory compliance policy sets

cost-management

Budgets and anomaly detection

tagging-standard

Enforced tagging policies

AI Infrastructure

ai-foundry-private

Private AI Foundry deployment

openai-private

Azure OpenAI with Private Link

cognitive-services

AI services baseline

Reference Architectures

Commercial Landing Zone

Complete CAF-aligned landing zone for commercial enterprises. Hub-spoke networking, governance, and identity baseline.

CAFHub-SpokeGovernance

Federal Landing Zone (Lite)

Azure Government foundation with NIST 800-53 policy set. Full version includes CMMC Level 2 controls.

Azure GovNISTIL4/IL5

Private AI Enclave (Lite)

Basic private AI infrastructure with zero public IP. Full version includes agent governance and compliance docs.

AI FoundryPrivate LinkZero Trust
Public vs Premium
FeaturePublicPremium
Core modulesIncludedIncluded
Advanced configurationsBasicFull
Compliance documentationMapping onlyFull SSP/POAM
Implementation supportCommunityDedicated architect
Priority updatesN/AIncluded
Need enterprise features?
Start with a RECON audit to convert these patterns into a scoped implementation plan with clear controls, ownership, and timeline.
Star on GitHub
Fork & contribute
Use freely

Built by Azure Architects

These modules power our production deployments. Battle-tested and compliance-ready.