Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ALZ Policy Version Pinning Update #1853

Merged

Conversation

Springstone
Copy link
Member

@Springstone Springstone commented Nov 29, 2024

Overview/Summary

This pull request includes updates to multiple policy assignment templates to include a new policyVersion variable and to update the apiVersion for each policy assignment resource. The changes ensure that the policy assignments reference the correct policy versions and use the latest API versions.

Key changes include:

Policy Version Updates:

  • Added policyVersion variable to each policy assignment template to specify the version of the policy definition being used. (AUDIT-AppGwWafPolicyAssignment.json, AUDIT-ResourceRGLocationPolicyAssignment.json, AUDIT-ZoneResilientPolicyAssignment.json, DENY-AksPrivEscalationPolicyAssignment.json, DENY-AksPrivilegedPolicyAssignment.json, DENY-AksWithoutHttpsPolicyAssignment.json, DENY-ClassicResourceTypesPolicyAssignment.json, DENY-HybridNetworkingPolicyAssignment.json, DENY-IPForwardingPolicyAssignment.json, DENY-PublicIpAddressOnNICPolicyAssignment.json, DENY-PublicIpAddressPolicyAssignment.json, DENY-StorageWithoutHttpsPolicyAssignment.json, DENY-VMUnmanagedDiskPolicyAssignment.json) [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13]

API Version Updates:

  • Updated apiVersion for each policy assignment resource to 2024-04-01 to ensure compatibility with the latest Azure API. (AUDIT-AppGwWafPolicyAssignment.json, AUDIT-ResourceRGLocationPolicyAssignment.json, AUDIT-ZoneResilientPolicyAssignment.json, DENY-AksPrivEscalationPolicyAssignment.json, DENY-AksPrivilegedPolicyAssignment.json, DENY-AksWithoutHttpsPolicyAssignment.json, DENY-ClassicResourceTypesPolicyAssignment.json, DENY-HybridNetworkingPolicyAssignment.json, DENY-IPForwardingPolicyAssignment.json, DENY-PublicIpAddressOnNICPolicyAssignment.json, DENY-PublicIpAddressPolicyAssignment.json, DENY-StorageWithoutHttpsPolicyAssignment.json, DENY-VMUnmanagedDiskPolicyAssignment.json) [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] [11] [12] [13]

Testing URLs

Azure Public

Deploy To Azure

…versions for PostgreSQL, Container Instance, MySQL, Compute, Key Vault, Container Apps, and Virtual Desktop guardrails
…versions for Decommissioned, Sandbox, SQL Security, ACSB, and Backup policies
…yVersion variable for enhanced version control
@Springstone Springstone requested a review from a team as a code owner November 29, 2024 18:23
@Springstone Springstone merged commit 4458a51 into Azure:policy-refresh-q2fy25 Nov 29, 2024
4 checks passed
@Springstone Springstone deleted the ALZPolicyVersioningUpdate branch November 29, 2024 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant