Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[AVM Module Issue]: Redis Cache - WAF-Aligned Example is not WAF Aligned due to enableNonSSLPort #3812

Closed
1 task done
jtracey93 opened this issue Nov 20, 2024 · 2 comments · Fixed by #3823
Closed
1 task done
Assignees
Labels
Class: Resource Module 📦 This is a resource module Needs: Triage 🔍 Maintainers need to triage still Type: AVM 🅰️ ✌️ Ⓜ️ This is an AVM related issue Type: Security Bug 🔒 This is a security bug

Comments

@jtracey93
Copy link
Contributor

Check for previous/existing GitHub issues

  • I have checked for previous/existing GitHub issues

Issue Type?

Security Bug

Module Name

avm/res/cache/redis

(Optional) Module Version

No response

Description

The WAF Aligned test/example sets the enableNonSSLPort property to true which goes against the WAF Security Pillar Recommendations https://github.com/Azure/bicep-registry-modules/blob/main/avm/res/cache/redis/tests/e2e/waf-aligned/main.test.bicep#L84

Can we update the test/example to not set this property or set it to false

(Optional) Correlation Id

No response

@jtracey93 jtracey93 added Needs: Triage 🔍 Maintainers need to triage still Type: AVM 🅰️ ✌️ Ⓜ️ This is an AVM related issue labels Nov 20, 2024
@github-project-automation github-project-automation bot moved this to Needs: Triage in AVM - Module Issues Nov 20, 2024

Important

The "Needs: Triage 🔍" label must be removed once the triage process is complete!

Tip

For additional guidance on how to triage this issue/PR, see the BRM Issue Triage documentation.

@avm-team-linter avm-team-linter bot added the Class: Resource Module 📦 This is a resource module label Nov 20, 2024
Copy link

@jtracey93, thanks for submitting this issue for the avm/res/cache/redis module!

Important

A member of the @Azure/avm-res-cache-redis-module-owners-bicep or @Azure/avm-res-cache-redis-module-contributors-bicep team will review it soon!

@hundredacres hundredacres mentioned this issue Nov 20, 2024
11 tasks
jtracey93 added a commit that referenced this issue Nov 22, 2024
## Description
Fixing WAF test


Fixes #3812 
Fixes #3824
Closes #3812 
Closes #3824

## Pipeline Reference

<!-- Insert your Pipeline Status Badge below -->

| Pipeline |
| -------- |
|
[![avm.res.cache.redis](https://github.com/hundredacres/bicep-registry-modules/actions/workflows/avm.res.cache.redis.yml/badge.svg?branch=fix%2Fissues%2F3812)](https://github.com/hundredacres/bicep-registry-modules/actions/workflows/avm.res.cache.redis.yml)
|

## Type of Change

<!-- Use the checkboxes [x] on the options that are relevant. -->

- [ ] Update to CI Environment or utilities (Non-module affecting
changes)
- [x] Azure Verified Module updates:
- [x] Bugfix containing backwards-compatible bug fixes, and I have NOT
bumped the MAJOR or MINOR version in `version.json`:
- [x] Someone has opened a bug report issue, and I have included "Closes
#{bug_report_issue_number}" in the PR description.
- [ ] The bug was found by the module author, and no one has opened an
issue to report it yet.
- [ ] Feature update backwards compatible feature updates, and I have
bumped the MINOR version in `version.json`.
- [ ] Breaking changes and I have bumped the MAJOR version in
`version.json`.
  - [ ] Update to documentation

## Checklist

- [x] I'm sure there are no other open Pull Requests for the same
update/change
- [x] I have run `Set-AVMModule` locally to generate the supporting
module files.
- [x] My corresponding pipelines / checks run clean and green without
any errors or warnings

<!-- Please keep up to date with the contribution guide at
https://aka.ms/avm/contribute/bicep -->

---------

Co-authored-by: Jack Tracey <[email protected]>
@github-project-automation github-project-automation bot moved this from Needs: Triage to Done in AVM - Module Issues Nov 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Class: Resource Module 📦 This is a resource module Needs: Triage 🔍 Maintainers need to triage still Type: AVM 🅰️ ✌️ Ⓜ️ This is an AVM related issue Type: Security Bug 🔒 This is a security bug
Projects
Development

Successfully merging a pull request may close this issue.

2 participants