Aspire.Hosting.Azure.Provisioning
13.6.0-preview.1.26479.8
Prefix Reserved
dotnet add package Aspire.Hosting.Azure.Provisioning --version 13.6.0-preview.1.26479.8
NuGet\Install-Package Aspire.Hosting.Azure.Provisioning -Version 13.6.0-preview.1.26479.8
<PackageReference Include="Aspire.Hosting.Azure.Provisioning" Version="13.6.0-preview.1.26479.8" />
<PackageVersion Include="Aspire.Hosting.Azure.Provisioning" Version="13.6.0-preview.1.26479.8" />
<PackageReference Include="Aspire.Hosting.Azure.Provisioning" />
paket add Aspire.Hosting.Azure.Provisioning --version 13.6.0-preview.1.26479.8
#r "nuget: Aspire.Hosting.Azure.Provisioning, 13.6.0-preview.1.26479.8"
#:package Aspire.Hosting.Azure.Provisioning@13.6.0-preview.1.26479.8
#addin nuget:?package=Aspire.Hosting.Azure.Provisioning&version=13.6.0-preview.1.26479.8&prerelease
#tool nuget:?package=Aspire.Hosting.Azure.Provisioning&version=13.6.0-preview.1.26479.8&prerelease
Azure Provisioning hosting integration
This package is experimental and emits ASPIREAZUREPROVISIONING001.
Use this integration to compose Bicep values and expressions in polyglot Aspire AppHosts that reference an opt-in Azure Provisioning integration.
Resource-specific provisioning integrations reference this package for the shared expression runtime. Each opt-in provisioning package still projects its own Azure Provisioning model proxies, including common models such as user-assigned identities.
Use the generated Bicep factories to compose deployment-time values from literals, resource properties, operators, functions, and interpolated strings. These values can be assigned to generated properties backed by BicepValue<T>.
Obtain the factory from the infrastructure callback. For example, the Key Vault provisioning integration can assign a computed integer from a generated TypeScript SDK:
import { BinaryBicepOperator, createBuilder } from "./.aspire/modules/aspire.mjs";
const builder = await createBuilder();
const vault = await builder.addAzureKeyVault("vault");
await vault.configureInfrastructure(async infrastructure => {
const service = await infrastructure.getKeyVaultService();
const properties = await service.properties.get();
const bicep = infrastructure.bicep();
const value = bicep.binary(
bicep.integer(20),
BinaryBicepOperator.Add,
bicep.integer(10));
await properties.softDeleteRetentionInDays.set(value);
});
The factory supports literals, common Bicep functions, member and index access, unary and binary operators, conditional expressions, and interpolated string construction. The integration also exposes Bicep parameters, variables, outputs, and user-assigned identities used across multiple Azure Provisioning SDKs.
Hosting-to-provisioning inventory
These opt-in integrations are bounded SDK configuration overlays, not new resource lifecycle integrations. Each SDK proxy references its corresponding existing hosting project, this shared runtime, and the private generator analyzer. Adding a hosting integration does not automatically opt into its SDK proxies.
The tables below map Azure hosting integrations to their provisioning SDK proxies and describe the base hosting, shared runtime, and generator projects.
Hosting integrations
Hosting suffixes below expand to Aspire.Hosting.Azure.{suffix}. SDK and proxy suffixes expand to Azure.Provisioning.{suffix} and Aspire.Hosting.Azure.Provisioning.{suffix}, respectively. The primary column maps the hosting resource to its SDK overlay; the last column lists supporting overlays needed only when customizing those SDK models, not additional requirements for ordinary hosting API use.
All hosting integrations also use base Azure provisioning support, including shared Key Vault infrastructure where needed. This common dependency is not repeated in every row. A companion resource can have its own infrastructure callback; installing its proxy does not make it appear in the primary resource's callback.
| Hosting integration | Primary SDK / opt-in proxy | Supporting SDK / proxy dependencies and scope |
|---|---|---|
| AppConfiguration | AppConfiguration |
App Configuration store. |
| AppContainers | AppContainers |
ContainerRegistry, OperationalInsights, Storage, KeyVault; separately modeled networking uses Network and, for private DNS, PrivateDns. |
| AppService | AppService |
ContainerRegistry, ApplicationInsights, OperationalInsights; separately modeled subnets use Network and private DNS uses PrivateDns. |
| ApplicationInsights | ApplicationInsights |
OperationalInsights for the workspace. |
| CognitiveServices | CognitiveServices |
Includes Azure OpenAI accounts and deployments. |
| ConnectorNamespace | Base provisioning support | Uses internal custom ConnectorGateway models for Microsoft.Web/connectorGateways and its children. These are not a standalone Azure Provisioning SDK and are not projected by an SDK proxy. |
| ContainerRegistry | ContainerRegistry |
Registry and task models. |
| CosmosDB | CosmosDB |
KeyVault for supporting secrets. |
| EventHubs | EventHubs |
Storage for storage-backed scenarios. |
| FrontDoor | Cdn |
Front Door profiles and routing models are in the CDN SDK. |
| Functions | Storage (shared) |
Host storage uses the Storage integration; deployment to Container Apps uses AppContainers and its dependencies. No Functions SDK proxy is needed. |
| KeyVault | KeyVault |
Vaults and secrets. |
| Kubernetes | ContainerService |
ContainerRegistry, Network, PrivateDns, OperationalInsights; Kubernetes/Helm deployment is not a separate Azure Provisioning SDK. |
| Kusto | Kusto |
Cluster and database models. |
| Network | Network, PrivateDns |
Private DNS is a separate SDK; private endpoint targets use their service's own proxy. |
| OperationalInsights | OperationalInsights |
Log Analytics workspace. |
| PostgreSQL | PostgreSql |
KeyVault for password authentication; SDK spelling differs from the hosting suffix. |
| Redis | Redis, RedisEnterprise |
Redis covers legacy Azure Cache for Redis; RedisEnterprise covers Azure Managed Redis. KeyVault supports access-key authentication. |
| Sandboxes | ContainerRegistry; base support |
Uses internal custom SandboxGroup provisioning and sandbox endpoint handling, not a standalone Azure SDK assembly. These internal models are not projected by an SDK proxy. |
| Search | Search |
Search service. |
| ServiceBus | ServiceBus |
Namespace and messaging entities. |
| SignalR | SignalR |
SignalR service. |
| Sql | Sql |
Storage, Network, and PrivateDns for supporting storage and networking scenarios. |
| Storage | Storage |
Accounts, blob, queue, table, and file models; also reused by Functions. |
| WebPubSub | WebPubSub |
Service and hub models. |
SDK proxy projects
Each linked suffix is an exact Aspire.Hosting.Azure.Provisioning.{suffix} project and uses Azure.Provisioning.{suffix}. "No-argument lookup roots" lists the types marked as infrastructure roots in AtsTypeMappings.cs, not an exhaustive supported-model list. Compatible types from the selected SDK assembly are also considered; other resources use identifier-based lookup.
| SDK proxy | Referenced hosting suffix | No-argument lookup roots |
|---|---|---|
| AppConfiguration | AppConfiguration |
AppConfigurationStore |
| AppContainers | AppContainers |
ContainerAppManagedEnvironment; apps and jobs use identifier-based lookup. |
| AppService | AppService |
None; plans and sites use identifier-based lookup. |
| ApplicationInsights | ApplicationInsights |
ApplicationInsightsComponent |
| Cdn | FrontDoor |
CdnProfile |
| CognitiveServices | CognitiveServices |
CognitiveServicesAccount |
| ContainerRegistry | ContainerRegistry |
ContainerRegistryService |
| ContainerService | Kubernetes |
ContainerServiceManagedCluster |
| CosmosDB | CosmosDB |
CosmosDBAccount |
| EventHubs | EventHubs |
EventHubsNamespace |
| KeyVault | KeyVault |
KeyVaultService |
| Kusto | Kusto |
KustoCluster |
| Network | Network |
VirtualNetwork, NetworkSecurityGroup, NatGateway, PublicIPAddress, PrivateEndpoint, NetworkSecurityPerimeter |
| OperationalInsights | OperationalInsights |
OperationalInsightsWorkspace |
| PostgreSql | PostgreSQL |
PostgreSqlFlexibleServer |
| PrivateDns | Network |
PrivateDnsZone |
| Redis | Redis |
Azure.Provisioning.Redis.RedisResource |
| RedisEnterprise | Redis |
RedisEnterpriseCluster |
| Search | Search |
SearchService |
| ServiceBus | ServiceBus |
ServiceBusNamespace |
| SignalR | SignalR |
SignalRService |
| Sql | Sql |
SqlServer |
| Storage | Storage |
StorageAccount |
| WebPubSub | WebPubSub |
WebPubSubService |
Base, shared runtime, and generator
| Project | Role | SDK coverage |
|---|---|---|
Aspire.Hosting.Azure |
Base hosting and Azure infrastructure support | Azure.Provisioning and Azure.Provisioning.KeyVault; shared infrastructure does not require another service SDK or proxy package. |
Aspire.Hosting.Azure.Provisioning |
Shared experimental runtime | Bicep expressions, parameters, variables, outputs, and shared identity support. Service-specific Key Vault customization uses the .KeyVault proxy. |
Aspire.Hosting.Azure.Provisioning.Generators |
Private build-time analyzer | Generates bounded proxies from explicit SDK selections; not an AppHost service integration or an additional Azure SDK. |
Lookup and compatibility boundaries
No-argument root lookups match the callback's Aspire resource Bicep identifier, not the Azure resource's physical name. Use identifier-based lookup when those identifiers differ: for example, App Service plans use <environment identifier>_asplan. Lookups are confined to the current infrastructure callback, not a global application inventory.
The scope is intentionally bounded. IncludeContainingAssemblyTypes does not promise that every SDK member is supported. Unsupported members are explicitly excluded in AtsTypeMappings.cs, such as opaque BinaryData payloads. The overlays document their exclusions: ContainerService's CustomCATrustCertificates and Network/Redis AdditionalProperties. These are unavailable through the proxy, not silently converted or dropped values.
IP address lists (BicepList<IPAddress>) support IPv4/IPv6 strings and Bicep value handles, including string-typed handles from bicep.string, bicep.parameter, and bicep.referenceExpression. Raw strings and string literals in handles are parsed into SDK IP address literals, with invalid input reported as an error. Expressions and references are preserved for deployment-time evaluation, including their security metadata. Element getters return Bicep value handles that retain literal, expression, reference, and security metadata and can be reassigned to another IP address collection. SDK read-only output restrictions still apply.
Creating a provisioning proxy integration
Integration authors can create an opt-in package for another Azure Provisioning SDK without changing Aspire's general-purpose integration analyzer. Reference Aspire.Hosting.Azure.Provisioning for the shared runtime proxies and reference Aspire.Hosting.Azure.Provisioning.Generators as a private analyzer dependency. Select the Azure SDK assembly and the resource that represents the current Aspire infrastructure:
using Aspire.Hosting.Azure.Provisioning;
using Azure.Provisioning.KeyVault;
[assembly: GenerateAspireProvisioningProxy(
typeof(KeyVaultService),
IncludeContainingAssemblyTypes = true)]
The generator projects compatible public classes and read-only structs in the selected type's assembly while keeping the exported polyglot surface bounded to that SDK package. A selected resource receives a no-argument infrastructure lookup when its Bicep identifier matches the callback's hosting resource identifier. Set IsInfrastructureRoot = false when those identifiers differ; identifier-based lookup and creation methods remain available where supported. Use ExcludedMemberNames for unsupported members rather than assuming assembly-wide selection makes every property representable.
Additional documentation
- https://aspire.dev/integrations/gallery/
- https://learn.microsoft.com/dotnet/azure/sdk/provisioning/
- https://learn.microsoft.com/azure/azure-resource-manager/bicep/
Feedback & contributing
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 was computed. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. net10.0 was computed. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
-
net8.0
- Aspire.Hosting.Azure (>= 13.6.0)
- AspNetCore.HealthChecks.Uris (>= 9.0.0)
- Azure.Core (>= 1.62.0)
- Azure.Identity (>= 1.21.0)
- Azure.Provisioning (>= 1.6.0)
- Azure.Provisioning.KeyVault (>= 1.1.0)
- Azure.ResourceManager.Authorization (>= 1.1.7)
- Azure.ResourceManager.KeyVault (>= 1.4.0)
- Azure.ResourceManager.Resources.Deployments (>= 1.0.0)
- Azure.Security.KeyVault.Secrets (>= 4.11.1)
- Google.Protobuf (>= 3.36.1)
- Grpc.AspNetCore (>= 2.83.0)
- Grpc.Net.ClientFactory (>= 2.83.0)
- Grpc.Tools (>= 2.83.0)
- Hex1b (>= 0.168.0)
- KubernetesClient (>= 19.0.2)
- MessagePack (>= 2.5.302)
- Microsoft.Extensions.Configuration.Abstractions (>= 10.0.12)
- Microsoft.Extensions.Configuration.Binder (>= 10.0.12)
- Microsoft.Extensions.Configuration.EnvironmentVariables (>= 10.0.12)
- Microsoft.Extensions.DependencyInjection.Abstractions (>= 10.0.12)
- Microsoft.Extensions.Diagnostics.HealthChecks (>= 8.0.31)
- Microsoft.Extensions.FileSystemGlobbing (>= 10.0.12)
- Microsoft.Extensions.Hosting (>= 10.0.12)
- Microsoft.Extensions.Hosting.Abstractions (>= 10.0.12)
- Microsoft.Extensions.Http (>= 10.0.12)
- Microsoft.Extensions.Logging (>= 10.0.12)
- Microsoft.Extensions.Logging.Abstractions (>= 10.0.12)
- Microsoft.Extensions.Options (>= 10.0.12)
- Microsoft.Extensions.Primitives (>= 10.0.12)
- ModelContextProtocol (>= 1.4.1)
- Newtonsoft.Json (>= 13.0.4)
- OpenTelemetry.Exporter.OpenTelemetryProtocol (>= 1.17.0)
- OpenTelemetry.Extensions.Hosting (>= 1.17.0)
- Polly.Core (>= 8.7.0)
- Semver (>= 3.0.0)
- StreamJsonRpc (>= 2.25.29)
- System.IO.Hashing (>= 10.0.12)
- System.Text.Json (>= 10.0.12)
- YamlDotNet (>= 18.1.0)
NuGet packages (24)
Showing the top 5 NuGet packages that depend on Aspire.Hosting.Azure.Provisioning:
| Package | Downloads |
|---|---|
|
Aspire.Hosting.Azure.Provisioning.AppContainers
Opt-in Azure Provisioning Container Apps APIs for polyglot Aspire AppHosts. |
|
|
Aspire.Hosting.Azure.Provisioning.CosmosDB
Opt-in Azure Provisioning Cosmos DB APIs for polyglot Aspire AppHosts. |
|
|
Aspire.Hosting.Azure.Provisioning.RedisEnterprise
Opt-in Azure Provisioning Redis Enterprise APIs for polyglot Aspire AppHosts. |
|
|
Aspire.Hosting.Azure.Provisioning.Cdn
Opt-in Azure Provisioning CDN and Front Door APIs for polyglot Aspire AppHosts. |
|
|
Aspire.Hosting.Azure.Provisioning.ContainerRegistry
Opt-in Azure Provisioning Container Registry APIs for polyglot Aspire AppHosts. |
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 13.6.0-preview.1.26479.8 | 192 | 9/29/2026 |