microsoft / microsoft/AzureTRE
Azure network security perimeter
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 235
- Forks
- 192
- Avg merge
- 1d 23h
- Merged PRs (30d)
- 13
Description
Is your feature request related to a problem? Please describe.
As a TRE Admin I want to prevent data exfiltration while maintaining necessary connectivity for required applications
Now Azure Network Security Perimeter is GA I am interested to hear if this would benefit and should be adopted by the TRE?
Describe the solution you'd like
Azure Network Security Perimeter creates logical network boundaries around your platform-as-a-service (PaaS) resources that are deployed outside your virtual networks. Network security perimeter helps you control public network access to resources like Azure Storage accounts and Azure Key Vault by establishing a secure perimeter.
https://learn.microsoft.com/en-us/azure/private-link/network-security-perimeter-concepts
Features of a network security perimeter include:
- Resource to resource access communication within perimeter members, preventing data exfiltration to nonauthorized destinations.
- External public access management with explicit rules for PaaS resources associated with the perimeter.
- Access logs for audit and compliance.
- Unified experience across PaaS resources.
Describe alternatives you've considered
Leave as-is / not implementing it
Additional context
N/A
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files or tests are identified. Start by reviewing the linked Azure Network Security Perimeter concepts and determine how its resource boundaries, access rules, and audit logs would apply to the TRE's PaaS resources. Done means documenting a decision on whether the TRE should adopt it and defining the required scope.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- cloud, networking, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100