Skip to content
Rowsafe
Docs
Connect a cloud account

Connect Azure

Coming soon, not available yet. Create a resource group and an app registration (service principal) with access to that resource group only, so Rowsafe can create database servers (virtual machines) there. The role, the custom role alternative, and how to revoke it.

Coming soon: you can't connect Azure yet

Rowsafe can't create servers in Azure yet: it has only been tested against a stand-in for Azure's API, not a real account, so the dashboard shows Azure as coming soon. This page describes how connecting it will work. Today, use DigitalOcean, AWS or OVHcloud, or Rowsafe Cloud.

To create servers for you in Azure, Rowsafe needs an app registration with access to one resource group. You create both in the Azure portal and paste five values into the dashboard once. It takes about five minutes.

Create the resource group and the app

Create a resource group

In the Azure portal, open Resource groups and click Create. Name it (for example rowsafe), pick a region and create it. Rowsafe will only work inside this resource group.

Register the resource providers

Open Subscriptions, choose your subscription, then Resource providers. Make sure Microsoft.Compute and Microsoft.Network say Registered (select them and click Register if not).

Register the app

Open Microsoft Entra ID, then App registrations, and click New registration. Name it Rowsafe, keep the defaults and click Register. Copy the Application (client) ID and the Directory (tenant) ID from its overview.

Create a client secret

In the app, open Certificates & secrets, click New client secret, pick an expiry and click Add. Copy the secret's Value right away (not its ID): Azure shows it only once.

Give the app the resource group, and only that

Go back to your resource group, open Access control (IAM), click Add, Add role assignment. Choose Contributor (or the custom role below), click Next, select the Rowsafe app as the member, then Review + assign.

Paste it into Rowsafe

On the resource group's Overview page, copy the Subscription ID. In the Rowsafe dashboard, open Settings → Cloud accounts (or Create a server for me), click Connect a cloud account, choose Microsoft Azure, paste the tenant ID, client ID, client secret, subscription ID and the resource group's name, give the account a name your team will recognize, and click Connect.

Rowsafe checks the credentials before it saves them: that they work, that the resource group exists, and that the app may do everything it needs there, without creating anything. If something is missing, it says what.

What access this gives Rowsafe

Contributor on one resource group lets the app create, change and delete anything in that resource group, and nothing outside it. For less, create a custom role (in the subscription's Access control (IAM), Add, Add custom role, Start from JSON) and assign it on the resource group instead of Contributor. Replace the two placeholders with your subscription ID and resource group:

{
  "Actions": [
    "Microsoft.Resources/subscriptions/resourceGroups/read",
    "Microsoft.Compute/virtualMachines/read",
    "Microsoft.Compute/virtualMachines/write",
    "Microsoft.Compute/virtualMachines/delete",
    "Microsoft.Compute/virtualMachines/start/action",
    "Microsoft.Compute/virtualMachines/deallocate/action",
    "Microsoft.Compute/virtualMachines/vmSizes/read",
    "Microsoft.Compute/disks/read",
    "Microsoft.Compute/disks/write",
    "Microsoft.Compute/disks/delete",
    "Microsoft.Network/virtualNetworks/read",
    "Microsoft.Network/virtualNetworks/write",
    "Microsoft.Network/virtualNetworks/subnets/read",
    "Microsoft.Network/virtualNetworks/subnets/write",
    "Microsoft.Network/virtualNetworks/subnets/join/action",
    "Microsoft.Network/networkSecurityGroups/read",
    "Microsoft.Network/networkSecurityGroups/write",
    "Microsoft.Network/networkSecurityGroups/delete",
    "Microsoft.Network/networkSecurityGroups/join/action",
    "Microsoft.Network/publicIPAddresses/read",
    "Microsoft.Network/publicIPAddresses/write",
    "Microsoft.Network/publicIPAddresses/delete",
    "Microsoft.Network/publicIPAddresses/join/action",
    "Microsoft.Network/networkInterfaces/read",
    "Microsoft.Network/networkInterfaces/write",
    "Microsoft.Network/networkInterfaces/delete",
    "Microsoft.Network/networkInterfaces/join/action",
    "Microsoft.Authorization/permissions/read"
  ],
  "AssignableScopes": [
    "/subscriptions/<subscription-id>/resourceGroups/<resource-group>"
  ],
  "Description": "Lets Rowsafe create, resize and delete database servers in one resource group.",
  "Name": "Rowsafe servers",
  "NotActions": []
}

Rowsafe itself creates, in that resource group and tagged rowsafe=1: for each server, a Debian 12 virtual machine with its disk, a network interface, a static public IP address and a network security group that lets in only the addresses you chose; and one virtual network per region, shared by your servers there. Your SSH keys go on the VM (for the user rowsafe) only if you give them, and Rowsafe never adds its own. Password logins are off. It creates them only when someone in your organization clicks and confirms. The credentials are stored encrypted, never shown again, and used only for those servers. See what Rowsafe does with your cloud account.

Revoke it

  • In Azure: in the app registration, Certificates & secrets, delete the secret. Or remove the role assignment on the resource group, or delete the app.
  • In Rowsafe: Settings → Cloud accounts, Remove. Rowsafe forgets the credentials; nothing in your subscription changes. You can remove an account once its servers are deleted.

After you revoke it, or when the secret expires, your servers keep running and stay protected, but Rowsafe can no longer resize them, change their firewall or delete them. Do that in the Azure portal.

Good to know

  • Prices in the dashboard are "about": estimates from Azure's pay-as-you-go list prices in one region. Other regions differ, and your Azure bill is what counts.
  • Deleting a server removes its VM, disk, network interface, public IP address and network security group. The region's virtual network stays, for your other servers; delete it in the portal if you no longer need it.
  • Azure limits CPUs and public IP addresses per region. If you reach a limit, Rowsafe says so: ask for more under Subscriptions, Usage + quotas.
  • An Azure Policy in your subscription can block what Rowsafe creates. Rowsafe says so; ask your Azure admin to allow it for the resource group.
Edit on GitHub