Case study Infrastructure as code & CI/CD

Zero-Downtime Cloud Deployment Pipeline

A fully automated infrastructure-as-code pipeline built with Azure Bicep and Azure DevOps — replacing manual deployment steps with consistent, immutable environments and zero-downtime releases.

The problem

Releases depended on manual deployment steps. Environments drifted apart as people applied changes by hand, a release could take days, and differences between environments surfaced in production as frequent rollbacks.

The fix had to address both halves of the problem: how infrastructure is defined, and how changes reach production.

Architecture

I engineered a fully automated infrastructure-as-code pipeline: environments are declared in Azure Bicep and deployed through Azure DevOps, so every environment is provisioned from the same templates and arrives in a consistent, immutable state.

Pipeline: commit, build and test, Bicep provisioning, then deployment to staging and production Commit Build & test Bicep Staging Production
Simplified pipeline. Stage names are illustrative of a typical multi-stage Azure DevOps flow.

What the pipeline does

  • Build and test the application on every change in multi-stage YAML pipelines.
  • Provision infrastructure from Bicep — the same templates for every environment, so there is nothing to configure by hand.
  • Promote through environments with approval gates, and release without taking the service down.

Related work from the same toolset: Bicep templates for VMs, VNets, Key Vaults and App Services across environments, ARM templates where legacy pipelines needed them, and staging/production slot swaps on App Service.

Engineering decisions

Infrastructure versioned alongside the application

When infrastructure lives in the same repository and review process as the code, every environment can be rebuilt from a known commit — which is what removes drift.

Trade-off: changes made directly in the portal are overwritten on the next deployment, so the team has to treat the templates as the only source of truth.

Immutable environments: redeploy, don’t patch

Rather than editing servers in place, a change produces a fresh deployment from the templates. Rollback becomes “redeploy the previous version”.

Trade-off: stateful resources such as databases need separate handling so redeployments never replace data.

Bicep over hand-written ARM JSON

Bicep compiles to ARM templates but is far shorter and easier to review, while keeping full coverage of Azure resource types.

Trade-off: it is Azure-specific, which suits an Azure-only estate but doesn’t carry over to other clouds.

Outcomes

  • Deployment time reduced from 2 days to 15 minutes.
  • Zero-downtime releases.
  • Manual configuration errors eliminated by removing manual steps altogether.

Skills demonstrated

Infrastructure as code with Azure Bicep and ARM templates, CI/CD design in Azure DevOps, and release engineering for zero-downtime delivery. See how these pieces fit into a wider system in the architecture lab.

control plane · access granted

You found the control plane.

Everything is healthy. Nothing is on fire. Here is the whole stack in one breath:

Client APIM Functions Logic Apps Data deployed by Bicep + Azure DevOps · secured by Managed Identity

Secret commands also work in the terminal. Try sudo.