Skip to content

avm.res.container-service.managed-cluster #17

avm.res.container-service.managed-cluster

avm.res.container-service.managed-cluster #17

Manually triggered December 12, 2024 05:59
Status Success
Total duration 52m 30s
Artifacts
Initialize pipeline
7s
Initialize pipeline
Run  /  Static validation
1m 42s
Run / Static validation
Matrix: Run / job_psrule_test_waf_reliability
Matrix: Run / job_psrule_test_waf_security_cb
Matrix: Run / job_psrule_test
Matrix: Run / job_psrule_test_waf_security
Matrix: Run / job_module_deploy_validation
Run  /  Publishing
0s
Run / Publishing
Fit to window
Zoom out
Zoom in

Annotations

28 errors and 14 warnings
Run / PSRule [defaults]
AZR-000017: ***csmin001 failed Azure.AKS.PoolScaleSet. Deploy AKS clusters with nodes pools based on VM scale sets.
Run / PSRule [defaults]
AZR-000018: ***csmin001 failed Azure.AKS.NodeMinPods. Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods.
Run / PSRule [defaults]
AZR-000022: ***csmin001 failed Azure.AKS.AuditLogs. AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
Run / PSRule [defaults]
AZR-000023: ***csmin001 failed Azure.AKS.PlatformLogs. AKS clusters should collect platform diagnostic logs to monitor the state of workloads.
Run / PSRule [defaults]
AZR-000435: ***csmin001 failed Azure.AKS.NodeAutoUpgrade. Deploy AKS Clusters with Node Auto-Upgrade enabled
Run / PSRule [defaults]
AZR-000027: ***csmin001 failed Azure.AKS.NetworkPolicy. AKS clusters without inter-pod network restrictions may be permit unauthorized lateral movement.
Run / PSRule [defaults]
AZR-000030: ***csmin001 failed Azure.AKS.AuthorizedIPs. Restrict access to API server endpoints to authorized IP addresses.
Run / PSRule [defaults]
AZR-000033: ***csmin001 failed Azure.AKS.SecretStore. Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault.
Run / PSRule [defaults]
AZR-000041: ***csmin001 failed Azure.AKS.ContainerInsights. Enable Container insights to monitor AKS cluster workloads.
Run / PSRule [defaults]
AZR-000370: ***csmin001 failed Azure.AKS.DefenderProfile. Enable the Defender profile with Azure Kubernetes Service (AKS) cluster.
Run / PSRule [waf-aligned]
AZR-000022: ***cswaf001 failed Azure.AKS.AuditLogs. AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
Run / PSRule [waf-aligned]
AZR-000435: ***cswaf001 failed Azure.AKS.NodeAutoUpgrade. Deploy AKS Clusters with Node Auto-Upgrade enabled
Run / PSRule [waf-aligned]
AZR-000033: ***cswaf001 failed Azure.AKS.SecretStore. Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault.
Run / PSRule [waf-aligned]
One or more assertions failed. One or more rules reported failure.
Run / PSRule [waf-aligned]
Process completed with exit code 1.
Run / PSRule - WAF Security [defaults]
AZR-000022: ***csmin001 failed Azure.AKS.AuditLogs. AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
Run / PSRule - WAF Security [defaults]
AZR-000435: ***csmin001 failed Azure.AKS.NodeAutoUpgrade. Deploy AKS Clusters with Node Auto-Upgrade enabled
Run / PSRule - WAF Security [defaults]
AZR-000027: ***csmin001 failed Azure.AKS.NetworkPolicy. AKS clusters without inter-pod network restrictions may be permit unauthorized lateral movement.
Run / PSRule - WAF Security [defaults]
AZR-000030: ***csmin001 failed Azure.AKS.AuthorizedIPs. Restrict access to API server endpoints to authorized IP addresses.
Run / PSRule - WAF Security [defaults]
AZR-000033: ***csmin001 failed Azure.AKS.SecretStore. Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault.
Run / PSRule - WAF Security [defaults]
AZR-000370: ***csmin001 failed Azure.AKS.DefenderProfile. Enable the Defender profile with Azure Kubernetes Service (AKS) cluster.
Run / PSRule - WAF Security [defaults]
One or more assertions failed. One or more rules reported failure.
Run / PSRule - WAF Security [defaults]
Process completed with exit code 1.
Run / PSRule - WAF Security [waf-aligned]
AZR-000022: ***cswaf001 failed Azure.AKS.AuditLogs. AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
Run / PSRule - WAF Security [waf-aligned]
AZR-000435: ***cswaf001 failed Azure.AKS.NodeAutoUpgrade. Deploy AKS Clusters with Node Auto-Upgrade enabled
Run / PSRule - WAF Security [waf-aligned]
AZR-000033: ***cswaf001 failed Azure.AKS.SecretStore. Deploy AKS clusters with Secrets Store CSI Driver and store Secrets in Key Vault.
Run / PSRule - WAF Security [waf-aligned]
One or more assertions failed. One or more rules reported failure.
Run / PSRule - WAF Security [waf-aligned]
Process completed with exit code 1.
Initialize pipeline
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / PSRule - WAF Security - AVM Custom Baseline [defaults]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / PSRule - WAF Security - AVM Custom Baseline [waf-aligned]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / PSRule - WAF Reliability [defaults]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / PSRule - WAF Reliability [waf-aligned]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / Static validation
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / Deploy [defaults]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / Deploy [non-aad-cluster]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / Deploy [automatic]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / Deploy [waf-aligned]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / Deploy [priv]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / Deploy [kubenet]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / Deploy [istio]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
Run / Deploy [azure]
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636