fix: Add missing dns zones in relevant policy assignment and adjust workflow permissions #1574
bicep-build-to-validate.yml
on: pull_request
Bicep Build & Lint All Modules
4m 35s
Test Azure Well-Architected Framework (PSRule)
3m 3s
Annotations
10 errors and 10 warnings
Test Azure Well-Architected Framework (PSRule)
Failed to expand bicep source '/home/runner/work/ALZ-Bicep/ALZ-Bicep/infra-as-code/bicep/modules/hubNetworking/samples/baseline.sample.bicep'. Exception calling "GetBicepResources" with "2" argument(s): "Unable to expand resources because the source file '/home/runner/work/ALZ-Bicep/ALZ-Bicep/infra-as-code/bicep/modules/hubNetworking/samples/baseline.sample.bicep' was not valid. An error occurred evaluating expression '[if(equals(toLower(variables('varGwConfig')[copyIndex()].gatewayType), 'vpn'), createObject('vpnClientAddressPool', coalesce(tryGet(variables('varGwConfig')[copyIndex()].vpnClientConfiguration, 'vpnClientAddressPool'), ''), 'vpnClientProtocols', coalesce(tryGet(variables('varGwConfig')[copyIndex()].vpnClientConfiguration, 'vpnClientProtocols'), ''), 'vpnAuthenticationTypes', coalesce(tryGet(variables('varGwConfig')[copyIndex()].vpnClientConfiguration, 'vpnAuthenticationTypes'), ''), 'aadTenant', coalesce(tryGet(variables('varGwConfig')[copyIndex()].vpnClientConfiguration, 'aadTenant'), ''), 'aadAudience', coalesce(tryGet(variables('varGwConfig')[copyIndex()].vpnClientConfiguration, 'aadAudience'), ''), 'aadIssuer', coalesce(tryGet(variables('varGwConfig')[copyIndex()].vpnClientConfiguration, 'aadIssuer'), ''), 'vpnClientRootCertificates', coalesce(tryGet(variables('varGwConfig')[copyIndex()].vpnClientConfiguration, 'vpnClientRootCertificates'), ''), 'radiusServerAddress', coalesce(tryGet(variables('varGwConfig')[copyIndex()].vpnClientConfiguration, 'radiusServerAddress'), ''), 'radiusServerSecret', coalesce(tryGet(variables('varGwConfig')[copyIndex()].vpnClientConfiguration, 'radiusServerSecret'), '')), null())]' line 12445. The language expression property 'vpnClientConfiguration' doesn't exist."
|
Test Azure Well-Architected Framework (PSRule)
AZR-000399: contoso-azfwpolicy-westus-centralus failed Azure.Firewall.PolicyMode. Deny high confidence malicious IP addresses, domains and URLs.
|
Test Azure Well-Architected Framework (PSRule)
AZR-000104: alz-azfwpolicy-[parameters('parLocation')] failed Azure.Firewall.PolicyName. Firewall policy names should meet naming requirements.
|
Test Azure Well-Architected Framework (PSRule)
AZR-000399: alz-azfwpolicy-[parameters('parLocation')] failed Azure.Firewall.PolicyMode. Deny high confidence malicious IP addresses, domains and URLs.
|
Test Azure Well-Architected Framework (PSRule)
AZR-000103: alz-fw-[parameters('parLocation')] failed Azure.Firewall.Name. Firewall names should meet naming requirements.
|
Test Azure Well-Architected Framework (PSRule)
AZR-000425: alz-log-analytics failed Azure.LogAnalytics.Replication. Log Analytics workspaces should have workspace replication enabled to improve service availability.
|
Test Azure Well-Architected Framework (PSRule)
AZR-000425: alz-log-analytics failed Azure.LogAnalytics.Replication. Log Analytics workspaces should have workspace replication enabled to improve service availability.
|
Test Azure Well-Architected Framework (PSRule)
AZR-000359: baseline managementGroups failed Azure.Deployment.Name. Nested deployments should meet naming requirements of deployments.
|
Test Azure Well-Architected Framework (PSRule)
AZR-000359: minimum managementGroups failed Azure.Deployment.Name. Nested deployments should meet naming requirements of deployments.
|
Test Azure Well-Architected Framework (PSRule)
AZR-000395: pip-minimum-ip failed Azure.PublicIP.MigrateStandard. Use the Standard SKU for Public IP addresses as the Basic SKU will be retired.
|
Test Azure Well-Architected Framework (PSRule)
Using invariant culture may cause rule infomation to be displayed incorrectly. Consider using -Culture or set the Output.Culture option.
|
Test Azure Well-Architected Framework (PSRule)
The option 'Execution.NotProcessedWarning' is deprecated and will be removed with PSRule v3. See http://aka.ms/ps-rule/deprecations for more detail.
|
Test Azure Well-Architected Framework (PSRule)
Rule 'PSRule.Rules.Azure\Azure.PublicIP.AvailabilityZone' was suppressed by suppression group '.\ALZ.MinimumSample' for 'vnet-spoke'. Ignore the minimum sample configuration.
|
Test Azure Well-Architected Framework (PSRule)
Rule 'PSRule.Rules.Azure\Azure.VNG.VPNAvailabilityZoneSKU' was suppressed by suppression group '.\ALZ.MinimumSample' for 'vnet-spoke'. Ignore the minimum sample configuration.
|
Test Azure Well-Architected Framework (PSRule)
Rule 'PSRule.Rules.Azure\Azure.VNET.UseNSGs' was suppressed by suppression group '.\ALZ.MinimumSample' for 'vnet-spoke'. Ignore the minimum sample configuration.
|
Test Azure Well-Architected Framework (PSRule)
Rule 'PSRule.Rules.Azure\Azure.PublicIP.StandardSKU' was suppressed by suppression group '.\ALZ.MinimumSample' for 'vnet-spoke'. Ignore the minimum sample configuration.
|
Test Azure Well-Architected Framework (PSRule)
Rule 'PSRule.Rules.Azure\Azure.VNG.VPNActiveActive' was suppressed by suppression group '.\ALZ.MinimumSample' for 'vnet-spoke'. Ignore the minimum sample configuration.
|
Test Azure Well-Architected Framework (PSRule)
Rule 'PSRule.Rules.Azure\Azure.Firewall.Mode' was suppressed by suppression group '.\ALZ.MinimumSample' for 'vnet-spoke'. Ignore the minimum sample configuration.
|
Test Azure Well-Architected Framework (PSRule)
Rule 'PSRule.Rules.Azure\Azure.PublicIP.AvailabilityZone' was suppressed by suppression group '.\ALZ.MinimumSample' for 'alz-fw-[parameters('parLocation')]'. Ignore the minimum sample configuration.
|
Test Azure Well-Architected Framework (PSRule)
Rule 'PSRule.Rules.Azure\Azure.VNG.VPNAvailabilityZoneSKU' was suppressed by suppression group '.\ALZ.MinimumSample' for 'alz-fw-[parameters('parLocation')]'. Ignore the minimum sample configuration.
|