Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added zero trust configs for storage & virtual machines #815

Merged
merged 28 commits into from
Jan 22, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
28 commits
Select commit Hold shift + click to select a range
7407de0
Added storage pvt endpoints & customer managed keys, Fixed idempotency
jamasten Jan 21, 2024
e6df34a
Fixed pvt endpoint names
jamasten Jan 21, 2024
9dd2f25
Fixed storage pvt endpoint name
jamasten Jan 21, 2024
2a01043
Added pvt endpoint for key vault
jamasten Jan 21, 2024
c837a91
Updated nic name for storage pvt endpoint
jamasten Jan 21, 2024
9f0b40d
Added CMK for VMs, Fixed VM settings
jamasten Jan 21, 2024
068d6e9
Added pvt endpoints for table storage
jamasten Jan 21, 2024
c84f4b7
Fixed deployment name
jamasten Jan 21, 2024
7b19729
Fixed deployment name
jamasten Jan 21, 2024
1e4c6c6
Removed comment
jamasten Jan 21, 2024
2253191
Fixed role assignment for DES
jamasten Jan 21, 2024
03d645c
Fixed hybrid use benefit for linux vm
jamasten Jan 22, 2024
4e6b221
Updated images to G2 for trusted launch support
jamasten Jan 22, 2024
2145edb
Updated API version, Organized code
jamasten Jan 22, 2024
e05e2e7
Fixed group ID for pvt endpoint
jamasten Jan 22, 2024
18c87d5
Compiled bicep changes
jamasten Jan 22, 2024
fb6006a
Updated API version, Added custom name for the NIC
jamasten Jan 22, 2024
3bab613
Added location abbreviation to naming convention
jamasten Jan 22, 2024
49df646
Compiled bicep changes
jamasten Jan 22, 2024
024cc88
Fixed pvt endpoint & NIC name
jamasten Jan 22, 2024
feac9f7
Added guest attestation for trusted launch
jamasten Jan 22, 2024
615f7a0
Fixed resource naming
jamasten Jan 22, 2024
7ff1e1c
Added settings, Updated API versions
jamasten Jan 22, 2024
7b3570a
Fixed network access
jamasten Jan 22, 2024
f5861c3
Compiled bicep changes
jamasten Jan 22, 2024
74e393f
Added dependency
jamasten Jan 22, 2024
bf431ce
Moved hybrid use benefit input
jamasten Jan 22, 2024
bcb9fb2
Updated names for Azure Monitor deployment
jamasten Jan 22, 2024
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
58 changes: 58 additions & 0 deletions src/bicep/core/hub-diagnostics.bicep
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
param firewallDiagnosticsLogs array
param firewallDiagnosticsMetrics array
param firewallName string
param hubStorageAccountResourceId string
param logAnalyticsWorkspaceResourceId string
param networkSecurityGroupDiagnosticsLogs array
param networkSecurityGroupDiagnosticsMetrics array
param networkSecurityGroupName string
param publicIPAddressDiagnosticsLogs array
param publicIPAddressDiagnosticsMetrics array
param publicIPAddressNames array
param virtualNetworkDiagnosticsLogs array
param virtualNetworkDiagnosticsMetrics array
param virtualNetworkName string

module networkSecurityGroupDiagnostics '../modules/network-security-group-diagnostics.bicep' = {
name: 'networkSecurityGroupDiagnostics'
params: {
logAnalyticsWorkspaceResourceId: logAnalyticsWorkspaceResourceId
logs: networkSecurityGroupDiagnosticsLogs
logStorageAccountResourceId: hubStorageAccountResourceId
metrics: networkSecurityGroupDiagnosticsMetrics
name: networkSecurityGroupName
}
}

module virtualNetworkDiagnostics '../modules/virtual-network-diagnostics.bicep' = {
name: 'virtualNetworkDiagnostics'
params: {
logAnalyticsWorkspaceResourceId: logAnalyticsWorkspaceResourceId
logs: virtualNetworkDiagnosticsLogs
logStorageAccountResourceId: hubStorageAccountResourceId
metrics: virtualNetworkDiagnosticsMetrics
name: virtualNetworkName
}
}

module publicIpAddressDiagnostics '../modules/public-ip-address-diagnostics.bicep' = [for publicIPAddressName in publicIPAddressNames: {
name: 'publicIPAddressDiagnostics_${publicIPAddressName}'
params: {
hubStorageAccountResourceId: hubStorageAccountResourceId
logAnalyticsWorkspaceResourceId: logAnalyticsWorkspaceResourceId
name: publicIPAddressName
publicIPAddressDiagnosticsLogs: publicIPAddressDiagnosticsLogs
publicIPAddressDiagnosticsMetrics: publicIPAddressDiagnosticsMetrics
}
}]

module firewallDiagnostics '../modules/firewall-diagnostics.bicep' = {
name: 'firewallDiagnostics'
params: {
logAnalyticsWorkspaceResourceId: logAnalyticsWorkspaceResourceId
logs: firewallDiagnosticsLogs
logStorageAccountResourceId: hubStorageAccountResourceId
metrics: firewallDiagnosticsMetrics
name: firewallName
}
}
Loading
Loading