Azure / Azure/Azure-Landing-Zones

ASC (MDFC) export to Azure Monitor is not reliable due to DINE policy race condition

Open
#540 5 comments 1 reaction 1 assignee View on GitHub

@lachaves is already working on this.

Since Nov 29, 2022.

Transfer From: caf-enterprise-scale :arrow_right:
Dominant language
PowerShell
Stars
97
Forks
70
Avg merge
3d 1h
Merged PRs (30d)
7

Description

Community Note
  • Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
  • Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment
Versions

terraform: 1.2.2

azure provider: 3.20

module: 3.1.2

Description
Describe the bug

MDFC export to LAW policy does not enable the functionality due to race condition.

Steps to Reproduce
  1. Deploy default architecture with configure_management_resources
  2. Observe subscription MDFC continuous export configuration not correct
  3. Observe Deploy-MDFC-Config policy not compliant
Screenshots

image

Additional context

Recommend declaring azurerm_security_center_automation resource to prevent this happening.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.