【问题标题】:Azure Policy (deployifnotexists) not behaving as expectedAzure Policy (deployifnotexists) 未按预期运行
【发布时间】:2020-10-12 01:01:23
【问题描述】:

这是我在这里的第一篇文章。如果未启用某些设置,我在 Azure 中尝试为存储帐户部署 ifnotexists。我附上了我的代码。我想做的是这样的:

  1. 检查是否启用了安全传输
  2. 仅检查 TLS1_2
  3. 检查固件
  4. 在 FW 上,接受 Azure 服务(例如 nsg 流日志等)

如果其中任何一个条件不满足,则通过 ARM 模板进行部署。吸引我的是,我故意设置了不良设置以使其正常工作,并且不会说它们不合规。

{
  "mode": "All",
  "policyRule": {
    "if": {
      "field": "type",
      "equals": "Microsoft.Storage/storageAccounts"
    },
    "then": {
      "effect": "deployIfNotExists",
      "details": {
        "type": "Microsoft.Storage/storageAccounts",
        "roleDefinitionIds": [
          "/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c"
        ],
        "existenceCondition": {
          "allOf": [
            {
              "field": "Microsoft.Storage/storageAccounts/supportsHttpsTrafficOnly",
              "equals": true
            },
            {
              "field": "Microsoft.Storage/storageAccounts/minimumTlsVersion",
              "equals": "TLS1_2"
            },
            {
              "field": "Microsoft.Storage/storageAccounts/networkAcls.defaultAction",
              "equals": "deny"
            },
            {
              "field": "Microsoft.Storage/storageAccounts/networkAcls.bypass",
              "contains": "AzureServices"
            }
          ]
        },
        "deployment": {
          "properties": {
            "mode": "incremental",
            "template": {
              "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#",
              "contentVersion": "1.0.0.0",
              "parameters": {
                "storageAccountName": {
                  "type": "String",
                  "metadata": {
                    "description": "storageAccountName"
                  }
                },
                "location": {
                  "type": "String",
                  "metadata": {
                    "description": "location"
                  }
                }
              },
              "variables": {},
              "resources": [
                {
                  "type": "Microsoft.Storage/storageAccounts",
                  "apiVersion": "2019-06-01",
                  "name": "[parameters('storageAccountName')]",
                  "location": "[parameters('location')]",
                  "properties": {
                    "minimumTlsVersion": "TLS1_2",
                    "networkAcls": {
                      "bypass": "AzureServices",
                      "defaultAction": "Deny"
                    },
                    "supportsHttpsTrafficOnly": true
                  }
                }
              ],
              "outputs": {}
            },
            "parameters": {
              "storageAccountName": {
                "value": "[field('Name')]"
              },
              "location": {
                "value": "[field('location')]"
              }
            }
          }
        }
      }
    }
  },
  "parameters": {}
}

谢谢大家

【问题讨论】:

    标签: azure-storage azure-policy


    【解决方案1】:

    因此,通过进一步阅读并与更有经验的同事交谈,我确定“deployIfNotExists”条件不适用于资源自己的设置。

    我的意思是我不能“deployIfNotExists”到存储帐户存储帐户设置(如上所述),但我可以将诊断日志记录部署到 SA。我正在结束这个问题。我会尝试追加,如果我做任何好的事情,我会将它循环回到这个问题中,以获得敏锐的眼光。

    【讨论】:

      猜你喜欢
      • 2014-11-12
      • 1970-01-01
      • 2020-06-28
      • 2012-02-18
      • 2018-01-18
      • 2012-06-14
      • 2019-03-03
      • 2012-09-21
      • 2014-07-19
      相关资源
      最近更新 更多