Azure / Azure/template-analyzer

[BUG] - Analysis fails even when the ARM template (JSON) file is following the guidance

Open
#353 4 comments 1 reaction 0 assignees View on GitHub
🔍 needs-triage bug
Dominant language
C#
Stars
143
Forks
47
PR merge metrics
No merged PRs in 30d

Description

### Describe the bug
Here's the sample ARM template

```
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"name": {
"type": "string"
},
"resourceLocation": {
"type": "string",
"metadata": {
"description": "Location where the resource to be created"
},
"defaultValue": "[resourceGroup().location]"
},
"resourceTags": {
"type": "object",
"defaultValue": {
"Environemnt": "Dev",
"Project": "Sample"
}
}
},
"resources": [
{
"type": "Microsoft.Network/virtualNetworks",
"name": "[parameters('name')]",
"apiVersion": "2020-06-01",
"location": "[parameters('resourceLocation')]",
"properties": {},
"tags": "[parameters('resourceTags')]"
}
]
}
```

When I run this template against the Template-Analyzer, I get the following error.

```
AZR-000222: Use a location parameter for regional resources
Severity: High
Recommendation: Consider updating the resource location property to use [parameters('location)].
More information: https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.Template.ResourceLocation/
Result: Failed
Line: 1
Rules passed: 0
```

### Expected behavior

It should not report AZR-000222: Use a location parameter for regional resources.

### Reproduction Steps

Create an ARM template file with the following content,

```
{
"$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"name": {
"type": "string"
},
"resourceLocation": {
"type": "string",
"metadata": {
"description": "Location where the resource to be created"
},
"defaultValue": "[resourceGroup().location]"
},
"resourceTags": {
"type": "object",
"defaultValue": {
"Environemnt": "Dev",
"Project": "Sample"
}
}
},
"resources": [
{
"type": "Microsoft.Network/virtualNetworks",
"name": "[parameters('name')]",
"apiVersion": "2020-06-01",
"location": "[parameters('resourceLocation')]",
"properties": {},
"tags": "[parameters('resourceTags')]"
}
]
}
```

Run the template Analyzer command pointing to this file.

`dotnet TemplateAnalyzer.dll analyze-template .json --report-format Console --include-non-security-rules -v`

### Environment

I have tried this with Ubuntu and Mac OSX (M1 - Apple Silicon).
NOTE: I am using dotnet-sdk-7.0 to run the TemplateAnalyzer on Unix machines.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.