Policy Remediation Task (DeployIfNotExists) works on existing and new resources, but not after 1st remediation if configuration changes back to not compliant.
- Dominant language
- Open Policy Agent
- Stars
- 1.7k
- Forks
- 1.2k
- Avg merge
- 2d 54m
- Merged PRs (30d)
- 3
Description
I have enabled a Remediation Task for a Policy (Configure diagnostic settings for Azure Network Security Groups to Log Analytics workspace) and ensured that the "Create a remediation task" is selected. I used the default System Identity with no changes.
After 1st scan the Policy found 2 not compliant resources and the proper Diagnostic Setting Rule was applied as configured in the Remediation Task. I deleted the newly created rule "setByPolicy" from 1 of the NSG hoping the Policy would recreate again after next scan it would find the resource not compliant. However, the Policy did find the resource not compliant, but the remediation was not applied. Does this mean that DeployifNotExists runs only one time on a remediated resource?
Contributor guide
No contributing guide indexed for this repository
Research direction
Review the reported Azure Policy DeployIfNotExists remediation flow for the diagnostic-settings policy on Network Security Groups and Log Analytics. Reproduce the sequence of an initial remediation, deleting the setByPolicy rule, and a later non-compliance scan; done means determining whether the remediation is reapplied or documenting the confirmed limitation.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- cloud
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100