Azure / Azure/azure-policy

Policy Remediation Task (DeployIfNotExists) works on existing and new resources, but not after 1st remediation if configuration changes back to not compliant.

Open
#1,027 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Open Policy Agent
Stars
1.7k
Forks
1.2k
Avg merge
2d 54m
Merged PRs (30d)
3

Description

I have enabled a Remediation Task for a Policy (Configure diagnostic settings for Azure Network Security Groups to Log Analytics workspace) and ensured that the "Create a remediation task" is selected. I used the default System Identity with no changes.
After 1st scan the Policy found 2 not compliant resources and the proper Diagnostic Setting Rule was applied as configured in the Remediation Task. I deleted the newly created rule "setByPolicy" from 1 of the NSG hoping the Policy would recreate again after next scan it would find the resource not compliant. However, the Policy did find the resource not compliant, but the remediation was not applied. Does this mean that DeployifNotExists runs only one time on a remediated resource?

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the reported Azure Policy DeployIfNotExists remediation flow for the diagnostic-settings policy on Network Security Groups and Log Analytics. Reproduce the sequence of an initial remediation, deleting the setByPolicy rule, and a later non-compliance scan; done means determining whether the remediation is reapplied or documenting the confirmed limitation.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
cloud
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.