Skill v1.0.1
currentAutomated scan100/100+2 new
version: "1.0.1" name: apim-bicep description: Guide for building Bicep files for Azure API Management (APIM) and related Azure services. Use when users want to create, modify, or understand Bicep templates for APIM instances, APIs, backends, subscriptions, policies, products, loggers, and diagnostics. This skill provides Bicep syntax and patterns based on the shared modules in this repository.
APIM Bicep
This skill provides guidance for creating Azure Bicep templates for API Management and related services.
Do not add tool, module, CLI extension, container feature, or package installation that bypasses the repository's seven-day release waiting period. Any new dependency must use an eligible exact version and the repository's guarded install flow.
When this workflow creates or updates Markdown, follow .markdownlint.json and .github/markdown.instructions.md without flattening semantic structure. Before completion, run npx --no-install markdownlint-cli2 "**/*.md" "#**/.venv/**" "#**/node_modules/**" from the repository root and require zero violations.
Quick Start - Basic APIM Instance
@description('The name of the API Management service instance')param apiManagementServiceName string = 'apim-${uniqueString(resourceGroup().id)}'@description('The email address of the publisher')param publisherEmail string@description('The name of the publisher')param publisherName string@description('The pricing tier of this API Management service')@allowed(['Consumption', 'Developer', 'Basic', 'Basicv2', 'Standard', 'Standardv2', 'Premium', 'Premiumv2'])param sku string = 'Basicv2'@description('Location for all resources')param location string = resourceGroup().locationresource apimService 'Microsoft.ApiManagement/service@2024-06-01-preview' = {name: apiManagementServiceNamelocation: locationsku: {name: skucapacity: 1}identity: {type: 'SystemAssigned'}properties: {publisherEmail: publisherEmailpublisherName: publisherName}}output apimId string = apimService.idoutput apimName string = apimService.nameoutput gatewayUrl string = apimService.properties.gatewayUrloutput principalId string = apimService.identity.principalId
Resource Types Reference
| Resource Type | API Version | Purpose | |
|---|---|---|---|
Microsoft.ApiManagement/service | 2024-06-01-preview | APIM service instance | |
Microsoft.ApiManagement/service/apis | 2024-06-01-preview | API definitions | |
Microsoft.ApiManagement/service/apis/operations | 2024-06-01-preview | API operations | |
Microsoft.ApiManagement/service/apis/policies | 2024-06-01-preview | API-level policies | |
Microsoft.ApiManagement/service/backends | 2024-06-01-preview | Backend services | |
Microsoft.ApiManagement/service/subscriptions | 2024-06-01-preview | API subscriptions | |
Microsoft.ApiManagement/service/products | 2024-06-01-preview | API products | |
Microsoft.ApiManagement/service/loggers | 2024-06-01-preview | Logging configuration | |
Microsoft.ApiManagement/service/apis/diagnostics | 2024-06-01-preview | API diagnostics |
Essential Patterns
Backend with Managed Identity
resource backend 'Microsoft.ApiManagement/service/backends@2024-06-01-preview' = {name: 'my-backend'parent: apimServiceproperties: {description: 'Backend with managed identity auth'url: 'https://my-service.azure.com'protocol: 'http'credentials: {managedIdentity: {resource: 'https://cognitiveservices.azure.com'}}}}
Backend Pool (Load Balancing)
resource backendPool 'Microsoft.ApiManagement/service/backends@2024-06-01-preview' = {name: 'inference-backend-pool'parent: apimServiceproperties: {description: 'Load balancer for multiple backends'type: 'Pool'pool: {services: [for (config, i) in backendsConfig: {id: '/backends/${backends[i].name}'priority: config.?priority ?? 1weight: config.?weight ?? 1}]}}}
API with OpenAPI Spec
resource api 'Microsoft.ApiManagement/service/apis@2024-06-01-preview' = {name: 'my-api'parent: apimServiceproperties: {displayName: 'My API'description: 'API description'path: 'api/v1'protocols: ['https']subscriptionRequired: truesubscriptionKeyParameterNames: {header: 'api-key'query: 'api-key'}format: 'openapi+json'value: string(loadJsonContent('./openapi.json'))}}
API Policy from File
resource apiPolicy 'Microsoft.ApiManagement/service/apis/policies@2024-06-01-preview' = {name: 'policy'parent: apiproperties: {format: 'rawxml'value: loadTextContent('policy.xml')}}
Subscription
@batchSize(1)resource subscription 'Microsoft.ApiManagement/service/subscriptions@2024-06-01-preview' = [for sub in subscriptionsConfig: {name: sub.nameparent: apimServiceproperties: {displayName: sub.displayNamescope: '/apis' // or '/apis/{apiId}' or '/products/{productId}'state: 'active'allowTracing: true}}]
Diagnostics and Logging
Azure Monitor Logger
resource apimLogger 'Microsoft.ApiManagement/service/loggers@2024-06-01-preview' = {parent: apimServicename: 'azuremonitor'properties: {loggerType: 'azureMonitor'isBuffered: false}}
Application Insights Logger
resource appInsightsLogger 'Microsoft.ApiManagement/service/loggers@2024-06-01-preview' = {name: 'appinsights-logger'parent: apimServiceproperties: {loggerType: 'applicationInsights'credentials: {instrumentationKey: appInsightsInstrumentationKey}description: 'APIM Logger for Application Insights'isBuffered: falseresourceId: appInsightsId}}
API Diagnostics with LLM Logging
resource apiDiagnostics 'Microsoft.ApiManagement/service/apis/diagnostics@2024-06-01-preview' = {parent: apiname: 'azuremonitor'properties: {alwaysLog: 'allErrors'verbosity: 'verbose'logClientIp: trueloggerId: apimLogger.idsampling: {samplingType: 'fixed'percentage: 100}largeLanguageModel: {logs: 'enabled'requests: {messages: 'all'maxSizeInBytes: 262144}responses: {messages: 'all'maxSizeInBytes: 262144}}}}
Bicep Best Practices
Use Existing Resources
resource apim 'Microsoft.ApiManagement/service@2024-06-01-preview' existing = {name: apimServiceName}
Parameter Validation
@description('The pricing tier')@allowed(['Consumption', 'Developer', 'Basic', 'Basicv2', 'Standard', 'Standardv2', 'Premium', 'Premiumv2'])param sku string = 'Basicv2'@minLength(1)@maxLength(50)param apiManagementName string
Load External Content
// Load JSON for OpenAPI specsvalue: string(loadJsonContent('./specs/openapi.json'))// Load XML for policiesvalue: loadTextContent('policy.xml')// Load and parameterize policyvar updatedPolicy = replace(loadTextContent('policy.xml'), '{backend-id}', backendName)
Output Secrets Safely
#disable-next-line outputs-should-not-contain-secretsoutput subscriptionKey string = subscription.listSecrets().primaryKey
Reference Documentation
- Shared modules in this repo:
shared/bicep/modules/apim/v1/(api, apim, backend, backend-pool, diagnostics, named-value, policy-fragment, product)