Azure / Azure/Azure-Landing-Zones

override firewall policy location in hub_networks azure_firewall settings

Open
#463 1 comment 5 reactions 0 assignees View on GitHub
Transfer From: caf-enterprise-scale :arrow_right:
Dominant language
PowerShell
Stars
96
Forks
70
Avg merge
3d 1h
Merged PRs (30d)
7

Description

### Community Note

- Please vote on this issue by adding a 👍 [reaction](https://blog.github.com/2016-03-10-add-reactions-to-pull-requests-issues-and-comments/) to the original issue to help the community and maintainers prioritize this request
- Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
- If you are interested in working on this issue or have submitted a pull request, please leave a comment

### Description

Add firewall policy location override in the configure_connectivity_resources.

#### Is your feature request related to a problem?

Azure allows chaining firewall policies. However, parent policies must reside in the same location as child policies in order to be eligible for chaining.

![Image](https://github.com/user-attachments/assets/4c1a05a9-9d02-4c27-a81e-6c2340b0988e)

#### Describe the solution you'd like

Add a "firewall_policy_location" override argument to the config block of the azurerm_firewall in hub_networks

![Image](https://github.com/user-attachments/assets/bc763f54-5da0-41ec-ae01-dd27fe888d0e)

This would allow us to deploy all firewall policies to one location (with firewalls themselves in various regions), enabling selection the same parent firewall policy for all.

Firewall policies support cross-region assignment, so this would not cause any issues.

![Image](https://github.com/user-attachments/assets/dc7f9b3f-394a-4ade-a9b4-9ad927d34164)

I understand it is possible to set firewall_policy_id and deploy this separately, but this would be a cleaner solution to the problem, allowing the policies to still be created and managed by the CAF ES module.

Azure firewalls need a policy assigned at creation. If creating and managing the firewall policy externally, this can lead to a circular dependency situation whereby the CAF ES module cannot be deployed, and neither can the external policy due to reliance on CAF ES deployed resources.

Contributor guide

Open the contributing guide

Research direction

Start by locating configure_connectivity_resources and the hub_networks azurerm_firewall configuration, then inspect how firewall_policy_id is currently handled. Confirm how the requested firewall_policy_location override should interact with policy creation and regional firewalls. Done means firewall policies can be deployed in the selected location while remaining managed by the CAF ES module.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, terraform
Domain
cloud, infrastructure
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.