Граф коммитов

197 Коммитов

Автор SHA1 Сообщение Дата
Courtney Vallentyne bc44f8a86c
Remove auto-provision for MMA, LAW solution (#412) 2024-11-14 13:39:09 -08:00
aporodnov 4fb3c81dc9
bastion: updated API and added features (#396)
Co-authored-by: Vallentyne
Co-authored-by: Barrington Willis <51492255+tredell@users.noreply.github.com>
Co-authored-by: Senthuran Sivananthan <sesivan@microsoft.com>
2024-11-07 13:53:22 -05:00
Obay 1cdd2dc594
Update la-vminsights-readonly.bicep (#408)
fix action name typo

Co-authored-by: Courtney Vallentyne <covallen@microsoft.com>
2024-11-07 13:31:52 -05:00
Barrington Willis 01d7734de6
Update BudgetIsFalse.json (#410)
Typo in the schema file was causing builds to fail.
2024-11-07 12:42:49 -05:00
Barrington Willis f3fba28b3f
Update CODEOWNERS (#409)
Removing Senthuran and adding Courtney as a code owner
2024-11-07 11:05:11 -05:00
Courtney Vallentyne 9fe82b8b4d
Update README.md (#399)
updated URL for guardrail accelerator
2024-04-05 15:44:55 -04:00
aporodnov fb13f56351
Removed #Requires -Modules from the PS scripts (#393)
Co-authored-by: @skeeler
2023-11-16 22:00:37 -05:00
Barrington Willis e5fad99585
Removed the Diagnostic Logs Audit requirement for EventGrid/eventSubscriptions (#390)
* Removed Diagnostic logging auditing for EventGrid/eventSubscriptions from the PBMM and Log Analytics policy initiatives.
2023-09-14 09:01:14 -07:00
Barrington Willis aa697c32b2
PrivateLink support for MySql Flexible Databases (#388) 2023-09-13 16:01:26 -04:00
Steve Keeler db45632283
Scripts to generate config from template, support JSON config intellisense in editors, fix bugs in deployment scripts (#379)
Fixes path normalization bug in deployment scripts #374
Fixes subscription filtering bug in deployment scripts #375
Adds CanadaPubSecALZ configuration JSON schema support for editors #376
Adds Scripts to generate CanadaPubSecALZ configuration files using existing environments as template #377
Adds Deploy landing zones to new Azure subscriptions in new primary tenant #378
2023-07-09 23:14:55 -04:00
David Christiansen 5830bcb631
Update identity.md (#365)
Updated page title to reflect content
2023-04-25 13:12:23 -07:00
Yanick Lepine 674f6cb1e7
Update DDoS.bicep (#363)
Change policySetDefinitions to policyDefinitions for the policyScopedId variable.
2023-03-16 10:13:38 -07:00
Barrington Willis 5680e6582a
Bug fixes - network routing & ADO Identity Pipelines (#362)
* Fixed Bug: missing identityPathFromRoot variable missing

* Fixed Bug: Allow Network transit thru the hub

* renamed the Subscriptions Yaml
2023-03-13 06:31:54 -07:00
Barrington Willis f13f6ec24f
Identity Archetype (#359)
* Squashed commit of the following:

commit 6d6b3e49855c365f49a4674534b985bacf9cd74c
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Feb 27 08:07:45 2023 -0800

    changed the areacode on the logging service health alerts architype

commit 86b4505c2ffd5127978883c0bc6a1f9b0e7d3268
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 24 16:39:08 2023 -0800

    prepping for testing in ESLZ test environment

commit 0f92b6bf70aee1377b4d49db436fa7024f1bfd25
Merge: 2a3584a 7749e7b
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 24 16:10:37 2023 -0800

    Merge remote-tracking branch 'origin/main' into IdentityLZ

commit 7749e7bf7a
Merge: f6555a4 5337654
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 24 16:08:54 2023 -0800

    Merge remote-tracking branch 'github-CanadaPubSecALZ/main'

commit f6555a4122
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Feb 13 12:30:20 2023 -0800

    Added the patch version to the AKS versions in the Data Archetypes

commit 8edcb63d83
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Feb 13 11:32:54 2023 -0800

    Changed hte AKS version to only have the Major.Minor

commit 37123d7162
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Feb 13 11:17:38 2023 -0800

    updated AKS version in the Data Archetypes

commit 459b3c6275
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Feb 13 08:55:13 2023 -0800

    changed the servcie health number prefix to 604

commit cccf88662c
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Feb 13 07:42:52 2023 -0800

    changed the invalid dummy service alert phone number to a valid phone number

commit 8e9628d26e
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Feb 13 07:01:36 2023 -0800

    fixed linter warnings in policy files

commit 6c2b2f7d2d
Author: Barry Willis <bawillis@microsoft.com>
Date:   Sat Feb 11 15:36:36 2023 -0800

    Commit 95556ddd: changed the extensionResourceId function to tenantResourceId for all built-in polify definitions

commit c58ba48f50
Author: Barry Willis <bawillis@microsoft.com>
Date:   Sat Feb 11 15:09:56 2023 -0800

    Fixed the AKS policy deployment

commit f9e8418b7e
Author: Barry Willis <bawillis@microsoft.com>
Date:   Sat Feb 11 14:04:22 2023 -0800

    Fixed Bug on policy defnition

commit 1a3c82e446
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 10 19:09:02 2023 -0800

    updated the linter rules

commit 20e188051a
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 10 18:52:18 2023 -0800

    fixed the remaining linter errors in the policy definitions

commit 1610a28e35
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 10 18:27:14 2023 -0800

    fixed the remaining linter warnings

commit 9f0e049fa0
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 10 17:31:21 2023 -0800

    fixed BCP321 warning

commit 466d7b0c07
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 10 17:22:46 2023 -0800

    changed the pOlicyScopedId var to be set by using the MGResourceID Function

commit 9362967e50
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 10 16:48:26 2023 -0800

    Fixed Role Definition Id References to use the ResourceId function

commit 4bcbc28212
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 10 16:07:33 2023 -0800

    Fixed BCP321 Linter warning in networking files

commit 2a3584a7cac9c5822c7a226bc8a5d44f52d69a65
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 10 15:07:43 2023 -0800

    Removed Linter exception BCP321 - will fix in the linter PR

commit a0b48ec7710a5ee8023a066e4cb5394074002c1e
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Feb 10 10:39:36 2023 -0800

    Fixed the bugs with conditionally deploying DNS Resolver

commit 4f24be78f48465b404c529b276db66496c9958db
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Feb 8 15:29:38 2023 -0800

    Updated documentation and made the DNS Resolver subnets optional

commit 03fcb5e50b0670c67d1850063dd828ffa6945cf8
Merge: dfe0d9a 0fa01e8
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Feb 6 16:58:41 2023 -0800

    Merge remote-tracking branch 'origin/main' into IdentityLZ

commit dfe0d9acab086df1d9dfbfbdae5770fbf5da999a
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Jan 11 15:52:06 2023 -0800

    added Schema validation to the identity config file

commit fb88630b5d707db6b7f4ab1aa2455ff79920d5b3
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Jan 9 10:28:13 2023 -0800

    changed the DNS Resolver ruleset to be an object-array

commit 78aaf4d6cdeff8d9832d8a309f26c10cefe97a22
Author: Barry Willis <bawillis@microsoft.com>
Date:   Sat Jan 7 13:57:37 2023 -0800

    first pass at creating conditional forwarding rulesets in the Identity LZ

commit e7b554d04daee83a55a985073ec0c59084c7f3c2
Author: Barry Willis <bawillis@microsoft.com>
Date:   Fri Jan 6 08:54:27 2023 -0800

    Configured Subnet Delegation for Az DNS Resolver

commit 978ab9925f876945ba02280493f7deba1c07e7ee
Author: Barry Willis <bawillis@microsoft.com>
Date:   Thu Jan 5 19:52:24 2023 -0800

    added Private DNS Resolver to the Identity LZ

commit 9735d58fc04d7a587a76a5387deb112c466390fe
Author: Barry Willis <bawillis@microsoft.com>
Date:   Thu Jan 5 13:19:05 2023 -0800

    Removed the optional Subnet

commit 4cd57ed41a09672b3cfbc1792c2edbdc3569a060
Author: Barry Willis <bawillis@microsoft.com>
Date:   Thu Jan 5 13:09:36 2023 -0800

    first cut at the identity LZ framework

commit a119eea02fca28a2028362f484aa2835c9313c1d
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Dec 21 11:54:58 2022 -0800

    added identitypathfromroot in the branch config file

commit 75b6ccc2ab6efd55037e0a5a938d49f2eef32de4
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Dec 21 11:35:12 2022 -0800

    Added: identity vars display
    Changed: location reference to identity param file

commit e0cfc41b5a83c4c331689fcafa5edc9928e93d39
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Dec 21 11:22:35 2022 -0800

    fixed misconfigured working directory

commit fb58b16999aeb9cc6b6b81647c76e95024e1267c
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Dec 21 11:18:46 2022 -0800

    removed schema validation to test deployment

commit 240189de7e30fa57654c3ec76ec37c762ff80133
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Dec 21 11:15:43 2022 -0800

    fixed bug - neworking region is now identity region

commit 89e63b5976cb5cdc4e85d0b25c01234ffe4853d7
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Dec 21 11:11:48 2022 -0800

    initial identity lz deployment

commit d4b40b26b893b78d7a9250dffe24c3e9ce06d690
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Dec 21 11:03:29 2022 -0800

    Added default region for Identity Subscription

commit 41e611818d09181b1a455f612425cae20f0683f7
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Dec 21 08:29:33 2022 -0800

    Changed bastion subnet range in identity subnet

commit f5a43f2d44803e80db8a043d31e5c9f72fc51675
Author: Barry Willis <bawillis@microsoft.com>
Date:   Wed Dec 21 07:33:03 2022 -0800

    Param file for Identity LZ

commit 13d084b0fe74f39ca1423b2eb9f333a2b760b1f2
Author: Barry Willis <bawillis@microsoft.com>
Date:   Tue Dec 20 15:19:23 2022 +0000

    Deleted identity.parameteres.json

commit 5ba9a12fa8e8e02f60f3f2afea43681cc84d7446
Merge: 002b2be e395307
Author: Barry Willis <bawillis@microsoft.com>
Date:   Tue Dec 20 07:18:40 2022 -0800

    Merge branch 'IdentityLZ' of https://dev.azure.com/Tredell/CanadaALZ/_git/CanadaALZ into IdentityLZ

commit 002b2be1bb5b555a334f35cbb505e7a68f321649
Author: Barry Willis <bawillis@microsoft.com>
Date:   Tue Dec 20 07:18:32 2022 -0800

    id-lz - created param section for id lz

commit e395307b1c12786cc28cf3d4b00586dde69739d5
Author: Barry Willis <bawillis@microsoft.com>
Date:   Tue Dec 20 07:13:54 2022 -0800

    id-lz - created param section for id lz

commit 7f4a43eb4fdc7f6f37ebab8e661981cccbee9f50
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 14:54:57 2022 -0800

    disabled privatelink infrastructure to be deployed in hub lz

commit db85049ac94b5c394d586b6960343bc1286997f1
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 14:46:36 2022 -0800

    Configured hub networking parameter files

commit 8d772e868803d1b712013f7db21044d48ab730d2
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 14:07:43 2022 -0800

    removed comment from json - not supported

commit 89cde8d92704f1a41a123af46da6dd90568d99cb
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 12:56:47 2022 -0800

    Configuring Policies for deployment to Test enviornment

commit ba781ee844a4abd403071e072645988b63ada494
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 12:40:53 2022 -0800

    added a default security Group

commit 1269da21e08fdf4c29a53b38a4d18722c64461e0
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 12:26:14 2022 -0800

    setting up logging for my test environment

commit 4d6a41f4133380223f5895dba270cbce4ae5a39b
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 12:13:08 2022 -0800

    testing the path to the logging configuraiton file

commit 75d0b99caf6aed5f809c28566cad35569d78be58
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 12:00:14 2022 -0800

    added the full path to the logging parameters file

commit 32e8382bcb8deaaaab0c7bc1c2791483ef439971
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 11:55:00 2022 -0800

    path to logging parameters file was incorrect

commit 5757d36a486e7f3b707f00848d19cfe64de83358
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 11:37:20 2022 -0800

    Changed MG Root to match test enviornment

commit 1fdd02db1638420decf5ab021fb617b95920aada
Author: Barry Willis <bawillis@microsoft.com>
Date:   Mon Dec 19 11:09:46 2022 -0800

    Adding config file for IdentityLZ branch

* PowerShell Deployment Files created

* GitHub Action Pipelines modified to add the Identity Archetype

* made the Identity GitHub Action optional

* put the boolean option in single quotes

* fixed a few bugs (BCP321 & references to the wrong tenant)

* changed the sub id for the logging subscription

* Removed the hardcoded reference to the LAW in the identity param file

* updated the param file with the LAW ID

* disabled private dns zone deployment in the identity sub

* removed the config files from my custom branch

* uncommented the validation in the Identity ADO Pipeline

* removed commented trigger code from ADO Identity Pipeline

* renenabled the dployment of the DNSPrivateEndPoints policyset

* removed the provider registration for containerservices in the deploy-identity-pipeline yaml

* added an explanation comment to the dnsforwardingruleset file

* Added telemetry tracking  for the identity subscription

* fixed cut and paste errors

* Updated test cases & documentation

* added the consistency check & pull request checks for github actions

* fixed spelling error
2023-03-03 07:00:06 -08:00
Barrington Willis 533765439f
Fixed Linter warnings & build errors (#354)
* Fixed BCP321 Linter warning in networking files

* Fixed Role Definition Id References to use the ResourceId function

* changed the pOlicyScopedId var to be set by using the MGResourceID Function

* fixed BCP321 warning

* fixed the remaining linter warnings

* fixed the remaining linter errors in the policy definitions

* updated the linter rules

* Fixed Bug on policy defnition

* Fixed the AKS policy deployment

* Commit 95556ddd: changed the extensionResourceId function to tenantResourceId for all built-in polify definitions

* fixed linter warnings in policy files

* changed the invalid dummy service alert phone number to a valid phone number

* changed the servcie health number prefix to 604

* updated AKS version in the Data Archetypes

* Changed hte AKS version to only have the Major.Minor

* Added the patch version to the AKS versions in the Data Archetypes
2023-02-24 12:57:36 -08:00
Luke Murray 0fa01e8b7b
Updated documents, from docs.microsoft.com - to Learn. (#350)
Updated documents, from docs.microsoft.com - to Learn.
2023-02-06 15:26:03 -08:00
Obay e44c7eabf8
Update hubnetwork-azfw.md (#345)
Having domain controllers under the "Connectivity" subscription is an anti-pattern that causes confusion to users.

Co-authored-by: Barrington Willis <51492255+tredell@users.noreply.github.com>
2022-11-30 19:14:57 -08:00
Steve Keeler 12cd557bc4
Add Barry to code owners list (#346) 2022-11-30 21:27:08 -05:00
Steve Keeler c714e65b81
Update CODEOWNERS (#344)
Adding Barry Willis and Kevin Evans to the CODEOWNERS file for the entire repo
2022-10-14 15:48:33 -04:00
Steve Keeler b8a9bc9116
Version August 2022 schema changes (#342) 2022-09-01 15:31:28 -04:00
Senthuran Sivananthan 5851a09acf
Revised Event Hub Diagnostic Settings policy (#339) 2022-08-17 18:50:15 -04:00
Senthuran Sivananthan e5fe39930e
Update diagnostic settings profile name (#337) 2022-08-17 18:37:43 -04:00
Senthuran Sivananthan db52627fe3
Suppress false positive linter warning: secure-secrets-in-params (#335) 2022-08-17 18:17:12 -04:00
Senthuran Sivananthan 2a6042d38c
Network security group support for private endpoints subnet (#333) 2022-08-17 17:59:13 -04:00
Senthuran Sivananthan e069a4b6ac
Support data collection rule (#331) 2022-08-17 17:28:39 -04:00
Senthuran Sivananthan c2afa0d997
Support azkms.core.windows.net and IPs in firewall allow list (#329) 2022-08-08 15:42:22 -04:00
Senthuran Sivananthan a7f521dcf9
Add missing log categories in diagnostic settings for Azure Firewall (#324) 2022-07-19 23:31:56 -04:00
Senthuran Sivananthan 60198bc19e
Resolve linter warning: prefer-unquoted-property-names (#322) 2022-07-19 23:11:10 -04:00
Sabyasachi Dasgupta a4e53fffe4
Update machinelearning.md (#327) 2022-07-18 16:44:01 -04:00
Ifyagolu 8fc587a6bf
Fix typo in onboarding guidance (#320) 2022-06-24 17:05:28 -04:00
Islam Gomaa e9a0962b7d
Reference the Guardrails Solution Accelerator for 30-day guardrail assessment (#313) 2022-05-27 16:13:52 -04:00
Senthuran Sivananthan 2b11801386
Add service health notification info (#310) 2022-05-19 10:38:55 -04:00
Senthuran Sivananthan bce747c9fd
Update resource group names for Logging & Networking (#309)
Remove `-rg` suffix
2022-05-18 09:29:03 -04:00
Senthuran Sivananthan 6765c48680
Serial defender plan deployments & revised resource/resource group names (#307) 2022-05-17 15:14:33 -04:00
Senthuran Sivananthan 62adb00d6a
Log Analytics solutions for SQL servers on machines (#303) 2022-05-16 13:53:37 -04:00
Senthuran Sivananthan c1a3b99c96
Flexible policy deployment using PowerShell & GitHub Actions (#300) 2022-05-16 09:26:47 -04:00
Senthuran Sivananthan 0ce5c1ac9e
Disable fail fast for matrix deployments (#297) 2022-05-15 12:19:01 -04:00
Senthuran Sivananthan c078a797d9
Concurrent role deployment with PowerShell & GitHub Actions (#299) 2022-05-15 11:19:43 -04:00
Senthuran Sivananthan 31a214abbf
Disable metrics in diagnostic settings for AKS through Policy (#295) 2022-05-15 10:39:08 -04:00
Senthuran Sivananthan 6a90a2fe9d
Separate Azure Firewall Policy deployment switch & unique telemetry tracking for policy assignments (#289) 2022-05-11 10:56:26 -04:00
Senthuran Sivananthan c4133077e1
Ensure multiple subscriptions can be moved to a management in parallel (#288)
Ensure deployment name for moving subscription is unique
2022-05-10 16:46:06 -04:00
Senthuran Sivananthan 93d2f13847
Support jobs in GitHub Actions (#286) 2022-05-10 14:53:18 -04:00
Steve Keeler 31e8d0ab60
Correct wiring of the subscriptions-ci pipeline and prompt for NVA firewall username & password (#285) 2022-05-10 12:30:36 -04:00
Steve Keeler 229b144663
Fix DeploySubscriptionIds parameter type casting (#282) 2022-05-09 20:41:06 -04:00
Senthuran Sivananthan 799ad52d77
Pass-thru secure strings as-is until ready for use (#281) 2022-05-09 20:10:33 -04:00
Steve Keeler a9c941948d
Add environment configuration override and protect sensitive parameters (#280) 2022-05-09 17:11:12 -04:00
Senthuran Sivananthan ce6c27f4e0
Support schema validation (#277) 2022-05-09 11:23:57 -04:00
Steve Keeler 1d8dbd7baf
GitHub workflow implementation (#276)
Implement GitHub workflows to deploy the Azure Landing Zones for Canadian Public Sector
2022-05-09 08:07:26 -04:00
Senthuran Sivananthan 08d8f9256a
Deployment flow diagram (#274) 2022-05-02 16:03:02 -04:00
Senthuran Sivananthan db098e17a1
Powershell deployment script for archetypes (#273)
Support for deploying subscriptions
2022-04-29 22:37:58 -04:00