Evaluating updates to ALZ/SLZ a bit easier

If you’re using Azure, there is a fair chance you (or some consultant) have implemented an Azure Landing Zones-architecture to split your workloads into a bunch of different subscriptions. it’s also a pretty good guess that you have done this with either Terraform/Opentofu or Bicep. And if you’re really unlucky, you (or the consultant who did the setup) pinned the version of the module and haven’t thought much about it ever since.

But the thing is. These modules get updates, on a fairly regular basis. New policies are added, some are deprecated and then removed, others are simply updated because their parameters were getting outdated (like that “require at least TLS 1.2”-policy that would throw an error if you wanted to use TLS 1.3 because the policy definition used = instead of >=).

So maybe dependabot or renovate has been nagging, or you check the release notes yourself, or that consultant sends you a message and says “hey, we should update this thing".

This week, one of my team member did just that. Realized that we haven’t documented how we do this upgrade, made sure to write it down, and created a pull request to review the changes before we merge and deploy them. And I was quickly reminded of just how much of a pain it can be to review these.

I don’t know about you, but I prefer to be somewhat confident that changes won’t break things and ruin everyone’s weekend. But reading through a bunch of JSON diffs isn’t exacly my idea of fun work.

Surely there must be a better way to quickly evaluate the changes from one release to another right? So that evening, while watching some trash tv in my hotel room I figured out I might as well put my GitHub Copilot-credits to use and see what it came up with.

The result is the “Landing Zone Release Brief”-app where you can select your current release and your update target, hit “Compare releases” and get a table of changes in a more human friendly format, and it looks like this:

Landding Zone Release Brief
Landding Zone Release Brief

The app is far from perfect. But it is enough to be helpful when you want the big picture first and decide if you need to drill into the nitty gritty details of something you suspect will cause problems.

It’s also open source, available at sjovang/landingzones-diff-reports-for-humans, and all meaningful contributions are welcome. It only compares the releases from Azure/azure-landing-zones-library and I have on purpose not tried to extend it into reading from actual Azure environments (though that would be a pretty cool feature to have for something similar you could self-host)

ps: if the report for the combination of releases you select is slow the most likely cause is that the cache isn’t fully hydrated yet. Across ALZ and SLZ the number of combinations are ~1100 (and yes, you can evaluate a “downgrade” to an older release if you really want to). Each report takes about 1 minute to compile, and then gets cached for as long as the backend infrastructure lives.