Bernie White
Bernie White
Currently baselines can select rules to run: - Include by name - Exclude by name - Include by tag - Include by label These filters are powerful when clear tags...
### Existing rule _No response_ ### Suggested rule When service bus replication is configured any configured locations should be in the allowed location list if configured. ### Pillar Security ###...
### Existing rule _No response_ ### Suggested rule Any configured additional locations of fleet resources should be within allowed locations if configured. ### Pillar Security ### Additional context This is...
### Existing rule Azure.VNG.MaintenanceConfig ### Suggested rule Promote `Azure.VNG.MaintenanceConfig` to GA rule set because it is no longer in preview. ### Pillar Reliability ### Additional context _No response_
### Existing rule _No response_ ### Suggested rule Now that Entra ID auth is available for use in MongoDB vCore clusters (in preview) for `Microsoft.DocumentDB/mongoClusters`, this should be used instead...
### Existing rule _No response_ ### Suggested rule When pulling in external files that will be executed such as scripts a pinned URL should be used, to prevent the file...
### Existing rule Azure.VM.PublicKey ### Suggested rule Add support for `Microsoft.AzureFleet/fleets` with a new rule similar to `Azure.VM.PublicKey`. ### Pillar Security ### Additional context https://learn.microsoft.com/en-us/azure/templates/microsoft.azurefleet/fleets?pivots=deployment-language-bicep
### Existing rule _No response_ ### Suggested rule Check for cases when a sensitive value is set on a non-secure property. ### Pillar Security ### Additional context _No response_
### Existing rule _No response_ ### Suggested rule Check if `zoneRedundancy` is `Enabled` in a region that support AZ. Currently provider information does not expose zones for the `Azure Managed...
### Your suggestion The rule `Azure.KeyVault.AutoRotationPolicy` requires reading the key rotation policy but that is only available from the data plane API. Currently the export process doesn't handle this option,...