Skip to content

Conversation

@aruneko
Copy link
Contributor

@aruneko aruneko commented Apr 13, 2023

Summary

I noticed that policies of CIS Azure v1.3.0 Section 8.1 and 8.2 always return fail. I add 3 changes the sql conditions mainly.

  1. use sub-resoruce (keyvault_key and keyvault_secret) id as the resource_id column in azure_policy_results table.
    • That makes it easier to identify what does resource lack expiration date directly.
  2. fix fail condition.
    • adjusting the original documentation of CIS Benchmark. It says that the failing condition is "enabled is true and expiration date is null".
  3. use JOIN instead of LEFT JOIN.
    • If we use LEFT JOIN on an Azure environment which don't have key or secret in a key vault, we get null columns and it satisfies a failing condition.

Copy link
Member

@erezrokah erezrokah left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks @aruneko, this looks good to me 🚀 Much cleaner than before

@erezrokah erezrokah added the automerge Automatically merge once required checks pass label Apr 13, 2023
@kodiakhq kodiakhq bot merged commit 612da16 into cloudquery:main Apr 13, 2023
kodiakhq bot pushed a commit that referenced this pull request Apr 23, 2023
🤖 I have created a release *beep* *boop*
---


## [7.2.0](plugins-source-azure-v7.1.1...plugins-source-azure-v7.2.0) (2023-04-23)


### This Release has the Following Changes to Tables
- Table `azure_consumption_billing_account_balances` was added
- Table `azure_consumption_billing_account_budgets` was added
- Table `azure_consumption_billing_account_charges` was added
- Table `azure_consumption_billing_account_events` was added
- Table `azure_consumption_billing_account_legacy_usage_details` was added
- Table `azure_consumption_billing_account_lots` was added
- Table `azure_consumption_billing_account_marketplaces` was added
- Table `azure_consumption_billing_account_modern_usage_details` was added
- Table `azure_consumption_billing_account_reservation_recommendations` was added
- Table `azure_consumption_billing_account_tags` was added
- Table `azure_consumption_billing_profile_reservation_details` was added
- Table `azure_consumption_billing_profile_reservation_recommendations` was added
- Table `azure_consumption_billing_profile_reservation_summaries` was added
- Table `azure_consumption_billing_profile_reservation_transactions` was added
- Table `azure_consumption_subscription_budgets` was added
- Table `azure_consumption_subscription_legacy_usage_details` was added
- Table `azure_consumption_subscription_marketplaces` was added
- Table `azure_consumption_subscription_price_sheets` was added
- Table `azure_consumption_subscription_reservation_recommendations` was added
- Table `azure_consumption_subscription_tags` was added

### Features

* **azure-resources:** Add Consumption Resources ([#9117](#9117)) ([007421a](007421a))
* **azure:** Add policy docs ([#10253](#10253)) ([e5b9ec7](e5b9ec7))
* **azure:** Upgrade to `github.com/cloudquery/plugin-sdk/v2` ([#9943](#9943)) ([11d98b3](11d98b3)), closes [#9942](#9942)


### Bug Fixes

* **azure:** Added missing character ([#10183](#10183)) ([cbd948d](cbd948d))
* **azure:** Fix detecting conditions in CIS Section 8 ([#9923](#9923)) ([612da16](612da16))
* **Azure:** Reduce duplicate results of Azure CIS v1.3.0 Section 9.1 ([#10013](#10013)) ([6539ee3](6539ee3))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v2 to v2.2.0 ([#10135](#10135)) ([cf33b89](cf33b89))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v2 to v2.2.2 ([#10143](#10143)) ([8f887e0](8f887e0))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v2 to v2.3.0 ([#10163](#10163)) ([9a7f214](9a7f214))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v2 to v2.3.1 ([#10175](#10175)) ([5b53423](5b53423))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v2 to v2.3.3 ([#10187](#10187)) ([b185248](b185248))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v2 to v2.3.4 ([#10196](#10196)) ([c6d2f59](c6d2f59))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v2 to v2.3.5 ([#10200](#10200)) ([5a33693](5a33693))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v2 to v2.3.6 ([#10208](#10208)) ([91c80a7](91c80a7))
* **deps:** Update module github.com/cloudquery/plugin-sdk/v2 to v2.3.8 ([#10213](#10213)) ([f358666](f358666))

---
This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

automerge Automatically merge once required checks pass

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants