Azure
Here are the steps to manually set up your Azure integration with Amberflo.
Prerequisites
- Azure Portal Access: Ensure you have sufficient permissions in the Azure portal to create exports and access billing scopes.
- Global Admin Access: If you do not see specific billing scopes or subscriptions, you may need Global Administrator privileges.
During the setup process, you will define the following values. Be sure to record them, as you will need to share these with Amberflo to complete the integration. Thee are two types of values; Credentials and Report Details.
Credentials
These values allow Amberflo to securely access the exported data from your Azure environment.
Application (client) ID: The unique identifier for the application you registered in Azure.
Directory (tenant) ID: The identifier for your Microsoft Entra ID (formerly Azure Active Directory) tenant.
Client secret: The secret used to authenticate the application. If the secret has an expiration date, be sure to rotate it and update Amberflo before it expires.
Report Details
These values determine where your cost export will be stored and how Amberflo retrieves it.
Storage Account: The name of the Azure Storage Account where the export will be delivered.
Container Name: The specific container inside the storage account that will hold the export files.
Directory Path: Similar to a folder path, this defines the virtual subdirectory inside the container where the report files will be stored.
- Important: Azure will automatically create this structure when the report is generated. You do not need to manually create the folders. Choose a clear and descriptive path to make it easier to identify and manage in the future. Do not include leading or trailing slashes (e.g., use amberflo_reports, not /amberflo_reports/).
Export Name: The label you assign to this cost export within Azure. This will be used for identification of the report in the portal.
Step 1: Create a Service Principal
- In the Azure portal, search for and select Microsoft Entra ID (formerly Azure Active Directory).
- Select App registrations, then click New registration.
- Name the application (e.g., “Amberflo”).
- Leave the default values for other parameters and click Register.
- On the Overview page, save the Application (client) ID and the Directory (tenant) ID. These will be needed later for Amberflo.
Step 2: Set Up Authentication
For Amberflo integration, use password-based authentication (an application secret):
- Under your new app registration, select Certificates & secrets from the left-hand menu.
- Click + New client secret to create a new client secret.
- Important: When the secret is set to expire, you must renew it before expiration and provide the updated value to Amberflo.
- Copy the Value of the newly created client secret. Save it somewhere safe to share with Amberflo, along with the Application (client) ID and the Directory (tenant) ID from Step 1.
Step 3: Access Cost Management + Billing
- Log in to the Azure Portal and navigate to Cost Management + Billing.
- Select the Billing Scope you want to export.
- If you do not see the billing scope or subscription, ensure you have the correct permissions or enable Global administrator access if needed.
Step 4: Create the Focus Export
- From the Cost Management + Billing page, select Exports.
- Click + New Export.
- Configure the Export settings:
- Export Type: Select Focus. (This should use FOCUS version 1.2)
- Storage Account: Choose Create New Storage Account.
- Name: Enter a unique name for the storage account.
- Container Name: Enter any desired name (e.g., amberflo-exports).
- Directory Path: Enter a descriptive directory name of your choice. This should not be the same as the storage account name or container name as this can cause confusion later on.
- Format: Select Parquet.
- Compression: Select Snappy.
- Click Review + Create to finalize the export
Step 5: Grant Amberflo Access to the Container
- In your Storage account, select Containers and open the container you created for the export. Note: If you are not seeing the container it is because it can take time for the container to be created when you set up a new export, sometimes up to 30 minutes.
- Click Access control (IAM).
- Click + Add and then select Add role assignment.
- Search for Storage Blob Data Reader, select it, and click Next.
- Click + Select members and find the Amberflo service principal you created.
- Select the Amberflo service principal and click Select.
- Click Review + Assign to complete the role assignment.
Step 6: Provide Details to Amberflo
Credentials:
- Application (client) ID
- Directory (tenant) ID
- Client secret
Report Details:
- Storage Account
- Container Name
- Directory Path
- Export Name
Amberflo will use this information to setup the integration with Azure.
Optional Steps:
To Whitelist IPs in Azure blob storage:
- Open the Azure Portal
- Go to the Storage Account in which the container has the FOCUS data for Amberflo. This will narrow Amberflo access to just your storage container.
- In the left pane, go to Security + Networking then Networking
- Select Enabled from selected virtual networks and IP addresses under Public network access
- Under Firewall, enter the Amberflo VPC NAT IP addresses: 54.68.31.10, 52.41.247.250
- Click Save