Build an auditable Azure change-management pipeline that gates every production change behind Work Item approval, executes it with a self-validating Python runbook, and logs it automatically to Confluence.
Organizations operating on Azure frequently encounter a critical operational risk: ad-hoc, undocumented changes that silently introduce configuration drift, service outages, and failed rollbacks. This tutorial addresses that gap using Python 3.10 runbooks running on a self-hosted Azure DevOps agent.
| The Problem | The Solution |
|---|---|
| Manual changes via CLI/Portal with zero documentation | All changes tracked in Azure DevOps Work Items with full audit trail |
| Configuration drift undetected until outages occur | Azure Monitor + Python runbooks detect and alert on drift |
| Rollback fails because prior state was never recorded | Runbook saves pre-change snapshot enabling reliable rollback |
| No approval gate - anyone changes production anytime | DevOps Environment approval gates enforce manager review |
| Runbook docs scattered, no audit trail | Confluence auto-updated after every pipeline execution |
How do you make every production change to an Azure resource requested, approved, executed, validated, and documented through one auditable pipeline, instead of an engineer running ad-hoc CLI or Portal commands that nobody tracked?
An undocumented change is a change nobody can trust. When a production VMSS gets scaled by hand from the CLI, there's no record of who did it, why, what the prior state was, or whether anyone reviewed it first. The first sign of trouble is usually an outage, at which point rollback fails too, because the prior state was never captured.
This use case replaces that with a single pipeline that intake, approves, executes, validates, and documents every change end to end.
The solution integrates four Azure and Atlassian services. All automation logic is in Python 3.10 running on a self-hosted Azure DevOps agent pool.
| # | Service | Role | Key capability |
|---|---|---|---|
| 1 | Azure DevOps | Change intake, approval workflow, pipeline execution | Work Items, Pipelines, Environments, PAT auth |
| 2 | Azure Automation | Python 3.10 runbooks: validate, execute, rollback | Python runbooks, Managed Identity, Variables |
| 3 | Azure Monitor | Drift detection, alerting (Flexible VMSS compatible) | Activity Log Alerts, Action Groups, KQL Workbooks |
| 4 | Confluence Cloud | Change log auto-updated via REST API after each run | REST API, Basic Auth, Storage Format, Table Rows |
| Tool | Purpose |
|---|---|
| Azure CLI | Create the VMSS, Automation Account, and run commands from Cloud Shell |
| Python 3.10 | Runtime for the Automation runbook and the Confluence update script |
| A self-hosted Azure DevOps agent | Required to run python3.10 and pip3.10 directly on the agent machine — Microsoft-hosted agents won't have this pinned Python version by default |
requests (Python package) | Used by update_confluence.py; installed on the agent during the pipeline run |
az boards callsThe step by step build and conclusion are part of a ByteLabs bundle. Enrol once to unlock every gated section in it for 3 months.
Browse ByteLabsAlready bought this? Sign in to open it.
The step by step build and conclusion are part of a ByteLabs bundle. Enrol once to unlock every gated section in it for 3 months.
Browse ByteLabsAlready bought this? Sign in to open it.