Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

💡 Feature Request - APIM missing DDOS recommendation check #543

Open
cbezenco opened this issue Dec 2, 2024 · 0 comments
Open

💡 Feature Request - APIM missing DDOS recommendation check #543

cbezenco opened this issue Dec 2, 2024 · 0 comments
Labels
Enhancement 🆕 New feature or request

Comments

@cbezenco
Copy link
Contributor

cbezenco commented Dec 2, 2024

Describe the solution you'd like

I recently went through a resiliency review where I found out my customer did not configure APIM DDOS protection. Their APIM was not configured with vnet-injected and therefore Azure DDOS protection could not be enabled on their APIM instances. In my customer case, there are 2 mission critical applications (including their e-commerce web site) leveraging this API server and this is clearly a potential resiliency weakness that should be raised through APRL to be consistent with other DDOS recommendation in the library.
Reference : https://learn.microsoft.com/en-us/azure/api-management/protect-with-ddos-protection

Describe alternatives you've considered

NA, we need a rule that detect APIM configured without vnet injection and ensure customer there is no way to enable DDOS protection

Additional context

Add any other context or screenshots about the feature request here. 📷

@microsoft-github-policy-service microsoft-github-policy-service bot added the Enhancement 🆕 New feature or request label Dec 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Enhancement 🆕 New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant