Design and implement an MLOps infrastructure
Infrastructure as Code and Secure Automation for Machine Learning
CoreProvision workspaces and their dependencies from Bicep and Azure CLI, run that provisioning from GitHub Actions without stored secrets, keep project code in Git, and restrict network paths to the workspace.
Aligned to the live AI-300 guide, which publishes no skills-measured date; guide and product behavior verified October 10, 2026.
Why this matters
Hand-built workspaces drift and cannot be reproduced across environments. Declarative templates in Git, deployed by workflows that authenticate with short-lived tokens, give every environment the same reviewed configuration, while network isolation keeps training data and endpoints off the public internet.
Must Know
- Bicep declares Azure resources; a workspace is the Microsoft.MachineLearningServices/workspaces resource type and references its storage account, key vault, and Application Insights by resource ID, while a container registry is optional at creation.
- Deploy Bicep with az deployment group create, and create workspace assets such as compute, environments, and jobs with az ml commands and YAML files.
- GitHub Actions can sign in to Azure with OpenID Connect: a federated identity credential on a Microsoft Entra app registration or user-assigned managed identity trusts tokens from a specific repository, branch, environment, or pull request.
- With OpenID Connect the workflow stores only client, tenant, and subscription IDs, not a client secret, and the workflow needs the id-token: write permission.
- Scope the deployment identity with the least-privileged Azure role at the resource group that holds the workspace rather than at the subscription.
- A managed virtual network isolates workspace compute. Allow internet outbound permits general outbound traffic, while Allow only approved outbound blocks everything except required services and the outbound rules you add.
- A private endpoint gives clients private inbound access to the workspace; disabling public network access then blocks access from the internet.
- Keep training code, YAML definitions, and Bicep in a Git repository; jobs submitted from a local Git clone record repository, branch, and commit information.
Compare and Distinguish
- OpenID Connect federated credential versus service principal secret: short-lived token exchange with nothing to rotate versus a long-lived secret stored in GitHub.
- Bicep versus az ml YAML: Azure resource provisioning versus workspace-level assets and jobs.
- Managed virtual network outbound modes versus private endpoint: control of what workspace compute can reach versus how clients reach the workspace.
- Allow internet outbound versus Allow only approved outbound: simpler connectivity versus data exfiltration protection that needs explicit rules for package feeds.
Scenario examples
- Scenario: A workflow must deploy a workspace without any long-lived Azure secret in GitHub. Think: OpenID Connect with a federated credential scoped to the repository and environment.
- Scenario: Compliance requires that training compute cannot send data to arbitrary internet hosts but still installs packages from PyPI. Think: Allow only approved outbound plus an outbound rule for the package feed.
- Scenario: Analysts must reach the workspace only from the corporate network. Think: a private endpoint and disabled public network access.
Exam traps
- Storing a client secret in a GitHub secret works, but it is not the secret-free option a stem asking for no stored credentials wants.
- A federated credential scoped to the main branch will reject tokens from a pull request or another environment.
- Allow only approved outbound without a rule for a required package repository causes environment builds or installs to fail.
- Creating a private endpoint alone does not stop public access; public network access must also be disabled.
Key takeaways
- Declare infrastructure in Bicep and assets in YAML, all kept in Git.
- Authenticate GitHub Actions with OpenID Connect and least-privilege role scope.
- Use managed network outbound modes for compute and private endpoints for inbound access.
How it works
- GitHub issues a signed token for the workflow run; Microsoft Entra ID exchanges it for an Azure access token when the issuer, subject, and audience match the federated credential.
- Managed virtual network rules are enforced on Microsoft-managed networking for workspace compute, with private endpoints created for approved Azure resources.
Objects and administrative surfaces
- Bicep files and parameter files deployed with Azure CLI.
- GitHub Actions workflows using the azure/login action, GitHub environments, and repository variables.
- Workspace Networking settings for managed virtual network mode, outbound rules, private endpoints, and public network access.
When to use it
- Use workflow environments with required approvals when deployments to production need approval.
- Use Allow internet outbound for open experimentation and Allow only approved outbound for regulated data.
Security and governance implications
- Create separate federated credentials per environment so a development workflow cannot deploy production.
- Keep Bicep changes behind pull request review and branch protection.
Troubleshooting signals
- An OpenID Connect sign-in error about a subject mismatch means the federated credential does not match the branch, environment, or event that ran.
- A job that cannot reach a package repository in an isolated workspace needs an outbound rule or a private feed.
More detail
- Configure GitHub Actions authentication to Azure with OpenID Connect.
- Deploy workspaces and dependent resources with Bicep and Azure CLI.
- Automate provisioning in workflows triggered by repository events.
- Restrict inbound and outbound network access for workspaces.
- Manage machine learning project source control with Git.
Ready for the quiz?
- What does a federated identity credential trust?
- Which managed virtual network mode protects against data exfiltration?
- Which command deploys a Bicep file to a resource group?
- What must be true besides a private endpoint to block internet access to a workspace?
Related objectives
- D1.3.S1 — Configure GitHub integration with Machine Learning to enable secure access
- D1.3.S2 — Deploy Machine Learning workspaces and resources by using Bicep and Azure CLI
- D1.3.S3 — Automate resource provisioning by using GitHub Actions workflows
- D1.3.S4 — Restrict network access to Machine Learning workspaces
- D1.3.S5 — Manage source control for machine learning projects by using Git