Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[AVM Module Issue]: avm/res/operational-insights/workspace does not support deploy of SQLAuditing solution #3378

Closed
1 task done
jikuja opened this issue Sep 29, 2024 · 11 comments · Fixed by #3667
Closed
1 task done
Assignees
Labels
Class: Resource Module 📦 This is a resource module Type: AVM 🅰️ ✌️ Ⓜ️ This is an AVM related issue Type: Bug 🐛 Something isn't working

Comments

@jikuja
Copy link

jikuja commented Sep 29, 2024

Check for previous/existing GitHub issues

  • I have checked for previous/existing GitHub issues

Issue Type?

Bug

Module Name

avm/res/operations-management/solution

(Optional) Module Version

No response

Description

Following code fails:

module law 'br/public:avm/res/operational-insights/workspace:0.7.0' = {
  name: logAnalyticsWorspaceName
  params: {
    name: logAnalyticsWorspaceName
    enableTelemetry: false
    gallerySolutions: [
      {
        name: 'SQLAuditing'
        product: 'SQLAuditing'
        publisher: 'Microsoft'
      }
    ]
  }
}

Error message:

Solution product name cannot start with 'OMSGallery/' as it is reserved for Microsoft first party solutions. Operation Id: '8aab36af321b604584069fe60e602148' (Code: InvalidParameter, Target: plan.product)

Solution can be added by using solutions resource:

var solutionName = 'SQLAuditing(${logAnalyticsWorspaceName})'
resource solution 'Microsoft.OperationsManagement/solutions@2015-11-01-preview' = {
  name: solutionName
  location: location
  properties: {
    workspaceResourceId: law.outputs.resourceId
  }
  plan: {
    name: solutionName
    promotionCode: ''
    product: 'SQLAuditing'
    publisher: 'Microsoft'
  }
}

For me it looks like SQLAudit solution is not available on OMSGallery namespace,

https://github.com/Azure/bicep-registry-modules/blob/main/avm/res/operations-management/solution/main.bicep#L48:

var solutionProduct = publisher == 'Microsoft' ? 'OMSGallery/${name}' : product

For a reference Portal creates following resource(not the call but resulting stete of the resource) when turning on auditing to LAW on Azure SQL:

{
  "plan": {
    "name": "SQLAuditing[law-law]",
    "publisher": "Microsoft",
    "promotionCode": "",
    "product": "SQLAuditing",
    "version": "1.0"
  },
  "properties": {
    "workspaceResourceId": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RgName/providers/Microsoft.OperationalInsights/workspaces/law-law",
    "provisioningState": "Succeeded",
    "creationTime": "Thu, 26 Sep 2024 14:55:20 GMT",
    "lastModifiedTime": "Thu, 26 Sep 2024 14:55:20 GMT",
    "containedResources": [
      "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RgName/providers/Microsoft.OperationalInsights/workspaces/law-law/views/SQLSecurityInsights",
      "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RgName/providers/Microsoft.OperationalInsights/workspaces/law-law/views/SQLAccessToSensitiveData"
    ],
    "referencedResources": []
  },
  "location": "westeurope",
  "tags": {},
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RgName/providers/Microsoft.OperationsManagement/solutions/SQLAuditing[law-law]",
  "name": "SQLAuditing[law-law]",
  "type": "Microsoft.OperationsManagement/solutions"
}

(Optional) Correlation Id

No response

@jikuja jikuja added Needs: Triage 🔍 Maintainers need to triage still Type: AVM 🅰️ ✌️ Ⓜ️ This is an AVM related issue labels Sep 29, 2024
Copy link

@jikuja, thanks for submitting this issue for the avm/res/operations-management/solution module!

Important

A member of the @Azure/avm-res-operationsmanagement-solution-module-owners-bicep or @Azure/avm-res-operationsmanagement-solution-module-contributors-bicep team will review it soon!

@avm-team-linter avm-team-linter bot added the Class: Resource Module 📦 This is a resource module label Sep 29, 2024
@github-project-automation github-project-automation bot moved this to Needs: Triage in AVM - Module Issues Sep 29, 2024

Important

The "Needs: Triage 🔍" label must be removed once the triage process is complete!

Tip

For additional guidance on how to triage this issue/PR, see the BRM Issue Triage documentation.

@microsoft-github-policy-service microsoft-github-policy-service bot added the Type: Bug 🐛 Something isn't working label Sep 29, 2024

Warning

Tagging the AVM Core Team (@Azure/avm-core-team-technical-bicep) due to a module owner or contributor having not responded to this issue within 3 business days. The AVM Core Team will attempt to contact the module owners/contributors directly.

Tip

  • To prevent further actions to take effect, the "Status: Response Overdue 🚩" label must be removed, once this issue has been responded to.
  • To avoid this rule being (re)triggered, the ""Needs: Triage 🔍" label must be removed as part of the triage process (when the issue is first responded to)!

@microsoft-github-policy-service microsoft-github-policy-service bot added the Status: Response Overdue 🚩 When an issue/PR has not been responded to for X amount of days label Oct 3, 2024

Warning

Tagging the AVM Core Team (@Azure/avm-core-team-technical-bicep) due to a module owner or contributor having not responded to this issue within 3 business days. The AVM Core Team will attempt to contact the module owners/contributors directly.

Tip

  • To prevent further actions to take effect, the "Status: Response Overdue 🚩" label must be removed, once this issue has been responded to.
  • To avoid this rule being (re)triggered, the ""Needs: Triage 🔍" label must be removed as part of the triage process (when the issue is first responded to)!

Caution

**This issue requires the AVM Core Team's (@Azure/avm-core-team-technical-bicep) immediate attention as it hasn't been responded to within 6 business days. **

Tip

  • To avoid this rule being (re)triggered, the "Needs: Triage 🔍" and "Status: Response Overdue 🚩" labels must be removed when the issue is first responded to!
  • Remove the "Needs: Immediate Attention ‼️" label once the issue has been responded to.

@microsoft-github-policy-service microsoft-github-policy-service bot added the Needs: Immediate Attention ‼️ Immediate attention of module owner / AVM team is needed label Oct 9, 2024

Warning

Tagging the AVM Core Team (@Azure/avm-core-team-technical-bicep) due to a module owner or contributor having not responded to this issue within 3 business days. The AVM Core Team will attempt to contact the module owners/contributors directly.

Tip

  • To prevent further actions to take effect, the "Status: Response Overdue 🚩" label must be removed, once this issue has been responded to.
  • To avoid this rule being (re)triggered, the ""Needs: Triage 🔍" label must be removed as part of the triage process (when the issue is first responded to)!

Caution

**This issue requires the AVM Core Team's (@Azure/avm-core-team-technical-bicep) immediate attention as it hasn't been responded to within 6 business days. **

Tip

  • To avoid this rule being (re)triggered, the "Needs: Triage 🔍" and "Status: Response Overdue 🚩" labels must be removed when the issue is first responded to!
  • Remove the "Needs: Immediate Attention ‼️" label once the issue has been responded to.

Warning

Tagging the AVM Core Team (@Azure/avm-core-team-technical-bicep) due to a module owner or contributor having not responded to this issue within 3 business days. The AVM Core Team will attempt to contact the module owners/contributors directly.

Tip

  • To prevent further actions to take effect, the "Status: Response Overdue 🚩" label must be removed, once this issue has been responded to.
  • To avoid this rule being (re)triggered, the ""Needs: Triage 🔍" label must be removed as part of the triage process (when the issue is first responded to)!

Caution

**This issue requires the AVM Core Team's (@Azure/avm-core-team-technical-bicep) immediate attention as it hasn't been responded to within 6 business days. **

Tip

  • To avoid this rule being (re)triggered, the "Needs: Triage 🔍" and "Status: Response Overdue 🚩" labels must be removed when the issue is first responded to!
  • Remove the "Needs: Immediate Attention ‼️" label once the issue has been responded to.

@krbar krbar removed Needs: Triage 🔍 Maintainers need to triage still Needs: Immediate Attention ‼️ Immediate attention of module owner / AVM team is needed Status: Response Overdue 🚩 When an issue/PR has not been responded to for X amount of days labels Oct 22, 2024
@krbar
Copy link
Contributor

krbar commented Oct 22, 2024

@jikuja Thank you for reporting the issue, I will look into it.

@krbar
Copy link
Contributor

krbar commented Oct 30, 2024

@jikuja Quick update on this. You were right, the SQLAuditing solution seems not to follow the standard naming patterns and expects the product name in a format of a 3rd party solution.

This will be a two-step fix. First, we need to merge the #3671 and publish a new version of the avm/res/operations-management/solution module. This version doesn't attempt to compose the names expected by the resource provider based on the user's input. Instead, the user input must be in a format expected by the resource provider. This will require to update the parameters, but will allow more flexibility.

Once the avm/res/operations-management/solution module is updated, we will update the avm/res/operational-insights/workspace module to use the new solutions module.

AlexanderSehr pushed a commit that referenced this issue Oct 30, 2024
…ment/solution` (#3671)

## Description

This PR addresses the issue with some solutions, which don't follow the
naming patterns described in the [template
reference](https://learn.microsoft.com/en-us/azure/templates/microsoft.operationsmanagement/solutions?pivots=deployment-language-bicep).
To address this, the module passes the parameters to the resource
provider without attempting to compose the names. It is the
responsibility of the user to provide parameters expected by the
resource provider. See parameter descriptions for more details.
Please note that this is a breaking change, the parameters of the
existing deployments have to be updated to match the new format.

Related to #3378 (first part of the fix).

## Pipeline Reference

<!-- Insert your Pipeline Status Badge below -->

| Pipeline |
| -------- |
|
[![avm.res.operations-management.solution](https://github.com/krbar/bicep-registry-modules/actions/workflows/avm.res.operations-management.solution.yml/badge.svg?branch=users%2Fkrbar%2FsolutionModuleUpdate)](https://github.com/krbar/bicep-registry-modules/actions/workflows/avm.res.operations-management.solution.yml)
|

## Type of Change

<!-- Use the checkboxes [x] on the options that are relevant. -->

- [ ] Update to CI Environment or utilities (Non-module affecting
changes)
- [x] Azure Verified Module updates:
- [ ] Bugfix containing backwards-compatible bug fixes, and I have NOT
bumped the MAJOR or MINOR version in `version.json`:
- [x] Someone has opened a bug report issue, and I have included "Closes
#{bug_report_issue_number}" in the PR description.
- [ ] The bug was found by the module author, and no one has opened an
issue to report it yet.
- [ ] Feature update backwards compatible feature updates, and I have
bumped the MINOR version in `version.json`.
- [x] Breaking changes and I have bumped the MAJOR version in
`version.json`.
  - [ ] Update to documentation

## Checklist

- [x] I'm sure there are no other open Pull Requests for the same
update/change
- [x] I have run `Set-AVMModule` locally to generate the supporting
module files.
- [x] My corresponding pipelines / checks run clean and green without
any errors or warnings

<!-- Please keep up to date with the contribution guide at
https://aka.ms/avm/contribute/bicep -->
@github-project-automation github-project-automation bot moved this from Needs: Triage to Done in AVM - Module Issues Nov 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Class: Resource Module 📦 This is a resource module Type: AVM 🅰️ ✌️ Ⓜ️ This is an AVM related issue Type: Bug 🐛 Something isn't working
Projects
2 participants