Closing the September run with the unglamorous engine room: the scheduled scripts that keep an estate tidy and the patching that keeps it defensible. Azure Automation and its modern companion Update Manager are where those responsibilities live, and both reward being set up once, properly.
Runbooks Done Properly
An Automation account runs PowerShell and Python runbooks on schedules, webhooks, or alert triggers. The modernization that matters most: authentication is the account’s managed identity now, the old Run As certificates are retired, so a runbook calls Connect-AzAccount with the identity and touches exactly what RBAC grants it, no credential assets holding secrets. The workloads that belong here are the operational chores this series has generated: deallocating dev VMs at night and weekends, rotating the secrets that resist native rotation from the Key Vault post, resizing pools on schedule, cleaning stale snapshots and untagged resource groups, and the ASR failover orchestration steps from the DR post. Source control integration syncs runbooks from your repo, which keeps the review discipline intact, scripts that can stop production VMs deserve pull requests.
param(
[string]$TagName = "autoShutdown",
[string]$TagValue = "true"
)
Connect-AzAccount -Identity | Out-Null
$vms = Get-AzVM -Status | Where-Object {
$_.Tags[$TagName] -eq $TagValue -and
$_.PowerState -eq "VM running"
}
foreach ($vm in $vms) {
Write-Output "Deallocating $($vm.Name) in $($vm.ResourceGroupName)"
Stop-AzVM -Name $vm.Name -ResourceGroupName $vm.ResourceGroupName -Force -NoWait
}
Hybrid runbook workers extend execution to machines you designate, including Arc connected servers from yesterday’s post, which is how a runbook restarts an on premises service or reaches a system with no public API. The worker is just an extension on the machine; the runbook targets the worker group, and suddenly the automation plane spans the hybrid estate.
Update Manager: Patching as a System
Azure Update Manager (which replaced the old Automation linked Update Management) assesses and patches Windows and Linux across Azure VMs, VMSS, and Arc machines with no agent beyond the platform ones. The setup that works: periodic assessment enabled everywhere by policy so compliance is always current, maintenance configurations defining the windows (dev patches Tuesday night, production in staggered waves by tier through the month, domain controllers and database servers in their own carefully sequenced configurations), machines attached to configurations dynamically by tag or subscription filters, and pre and post events wired to runbooks for the surrounding choreography, snapshot before, health check and service validation after. Hotpatching on supported Windows Server editions shrinks reboot pressure for that fleet, and reboot settings per configuration keep the always reboot versus never reboot arguments encoded rather than relitigated per cycle.
Two reports close the loop: patch compliance by tier reviewed in the monthly operations meeting, and the exception list, machines excluded from configurations, with owners and expiry dates exactly like the policy exemptions post prescribed, because unpatched by decision with a review date is governance, and unpatched by drift is the finding a pen test leads with. That is September’s run complete: networking depth, security operations, the data platform, application services, and hybrid. October continues with identity depth, IaC practices, FinOps, and advanced AKS.
Cheers
Osama
Leave a comment