Azure / Azure/Azure-Landing-Zones
ASC (MDFC) export to Azure Monitor is not reliable due to DINE policy race condition
Open
@lachaves is already working on this.
Since Nov 29, 2022.
Transfer From: caf-enterprise-scale :arrow_right:
- Dominant language
- PowerShell
- Stars
- 97
- Forks
- 70
- Avg merge
- 3d 1h
- Merged PRs (30d)
- 7
Description
Community Note
- Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
- Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
- If you are interested in working on this issue or have submitted a pull request, please leave a comment
Versions
terraform: 1.2.2
azure provider: 3.20
module: 3.1.2
Description
Describe the bug
MDFC export to LAW policy does not enable the functionality due to race condition.
Steps to Reproduce
- Deploy default architecture with
configure_management_resources - Observe subscription MDFC continuous export configuration not correct
- Observe Deploy-MDFC-Config policy not compliant
Screenshots
Additional context
Recommend declaring azurerm_security_center_automation resource to prevent this happening.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.