-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New Feature: Workload Specific Compliance #1622
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 1 commit
Commits
Show all changes
155 commits
Select commit
Hold shift + click to select a range
196bdd0
Add FSI specific policies
Springstone a1fdff3
Add Deny-CognitiveServices-RestrictOutboundNetworkAccess policy defin…
Springstone 97db4cb
Add FSI specific policies
Springstone 15610d5
Add FSI specific initiative policy set definition
Springstone ecdae38
Add FSI specific initiative policies for App Services
Springstone be7bc0d
Add aaModifyPublicNetworkAccess parameter to Deny-PublicPaaSEndpoints…
Springstone 4032cb7
Add policy definitions for Cognitive Search and Automation
Springstone a449bff
Update policy definitions for Deny-PublicPaaSEndpoints and Enforce-En…
Springstone 97d4c06
Update policy set definitions for Compute and Container Apps
Springstone 7f35801
Add new policy set definitions for Enforce-Guardrails-CosmosDb, Enfor…
Springstone f2de5cd
Update policy definitions for Event Hub encryption
Springstone 7147bb3
Update Enforce-Encryption-CMK policy set definition version and name
Springstone 64eddf4
Add new policySetDefinitions for KeyVault guardrails
Springstone 50b18c5
Remove metadata and update groupNames in policySetDefinitions
Springstone 6703c5e
Add ESLZ custom initiatives
Springstone ec12be6
Update policy and initiative files
Springstone 6ab4bfb
Add FSI specific policy set definitions for Kubernetes, Machine Learn…
Springstone f321e00
Add policy set definition for Service Bus and update policy set defin…
Springstone 22e017d
Add policy set definitions for SQL and Storage
Springstone aa7da20
Add policy set definition for Enforce-Guardrails-Synapse.json
Springstone dd098a5
Update policy and initiative files
Springstone c7f60e5
Update policy set definitions for ESLZ Arm template and Enforce-Encry…
Springstone 97999e3
Update policy set definitions for Enforce-Encryption-CMK.json, Enforc…
Springstone 90b5f3a
Update policy set definitions for Enforce-Guardrails-CosmosDb.json, E…
Springstone d6bd94f
Update policy set definitions for Enforce-Guardrails-KeyVault-Sup.jso…
Springstone 969a8be
Update ALZ Policies documentation and ESLZ Arm template
Springstone 2791ffa
Update mdfcConfiguration.json description for resource group name
Springstone 0d575d4
Update policy set definitions for ESLZ Arm template and Enforce-Encry…
Springstone 684a4e1
Update policy set definitions for Enforce-Guardrails-ServiceBus.json
Springstone 501f4f9
.
Springstone 27b3a1c
.
Springstone 65d2ec6
.
Springstone 7939b30
.
Springstone 8a53c49
.
Springstone 3b4429b
.
Springstone ce6327c
.
Springstone 1336c28
Update labels and descriptions for regulated industry policy initiatives
Springstone da224a5
Update labels and descriptions for regulated industry policy initiatives
Springstone 1c4aba5
Update regulated industry and regulatory compliance initiatives assig…
Springstone b1edff6
Refactor policy assignments for regulated industry and regulatory com…
Springstone afdcbb1
Add policy assignment for API Management
Springstone 3c0038a
Add support for enabling API Management Policy Initiatives in regulat…
Springstone cd95554
Update multiselect and selectAll properties in eslz-portal.json
Springstone 51aa41f
Update labels and descriptions for regulated industry policy initiatives
Springstone e88ea04
Refactor policy assignments for regulated industry and regulatory com…
Springstone f30e319
.
Springstone e7ff876
Update labels and descriptions for regulated industry policy initiatives
Springstone 6905103
.
Springstone bb97da3
.
Springstone 9385efa
.
Springstone 96deba4
Update labels and descriptions for regulated industry policy initiatives
Springstone bc338da
.
Springstone e96c18e
.
Springstone 7cb943c
Update labels and descriptions for regulated industry policy initiatives
Springstone bf2a03c
Update labels and descriptions for regulated industry policy initiatives
Springstone 8fa209f
Merge branch 'Azure:main' into FSI
Springstone 88b69ab
Update defaultValue for delayCount to 45 in eslzArm.json
Springstone 18ebd31
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone c8b4427
Update labels and descriptions for regulated industry policy initiatives
Springstone 13f4c77
Update labels and descriptions for regulated industry policy initiatives
Springstone 58d3ba0
Update labels and descriptions for workload specific compliance polic…
Springstone 835db96
Update labels and descriptions for regulated industry policy initiatives
Springstone 71e8db4
Update names and scopes for wsAPIM deployments in eslzArm.json
Springstone ac845ab
.
Springstone 99d4e1a
.
Springstone c57d209
Update policy assignment names and variables in ENFORCE-GuardrailsAPI…
Springstone c60db38
Update descriptions for regulated industry policy initiatives
Springstone ff59bea
Update descriptions for regulated industry policy initiatives
Springstone ac234c9
Update policy definition group names in Enforce-Guardrails-ContainerI…
Springstone 5396bc2
Update policy definition group names, descriptions, and labels for re…
Springstone 586ff0a
Update eslz-portal.json to hide "resourceScope" field in Microsoft.Co…
Springstone 2d2e147
Update eslz-portal.json to remove "visible" property for "resourceSco…
Springstone 5ac9198
Fix typo in eventGridPublicNetworkAccess parameter name
Springstone 8548093
Update deployment name in eslzArm.json for wsContainerInstance
Springstone 29a9b00
Add option to enable all workload specific compliance initiatives in …
Springstone 8c02fcc
.
Springstone e0e4982
.
Springstone cb64d20
.
Springstone 034fdf5
.
Springstone 0fc8768
.
Springstone a407eff
.
Springstone e734a95
Add option to enable all workload specific compliance initiatives in …
Springstone df4b232
Update policy assignment names for guardrails in eslzArm/managementGr…
Springstone 7fc9b3f
Add new workload specific compliance initiatives and update existing …
Springstone e876277
Update ALZ Portal accelerator with new "Workload Specific Compliance"…
Springstone 66c6615
Update ALZ Portal accelerator with new "Workload Specific Compliance"…
Springstone 2d12ae2
Update ALZ Portal accelerator with new "Workload Specific Compliance"…
Springstone 02fcb46
Fix ALZ Policies and Initiatives escape character issue and update De…
Springstone 835f1dc
Auto-update Portal experience [Springstone/651f57a7]
github-actions[bot] 71b20af
Adding dependsOn for workload policies to stagger identity creation
Springstone 4d78387
Update ALZ Portal accelerator with new "Workload Specific Compliance"…
Springstone 2c0a47a
Update eslzArm.json to remove wsAPIMDeploymentName from dependencies
Springstone a79cc46
Update policy assignment names for guardrails in eslzArm/managementGr…
Springstone da02a54
Update policy assignment names for guardrails in eslzArm/managementGr…
Springstone 66a8d21
Update Enforce-Encryption-CMK.json with default values set to "Deny"
Springstone 63c8f96
Update ALZ Portal accelerator with tooltip text change in eslz-portal…
Springstone 23eb19d
Update policy definitions for storage account TLS and secure transfer
Springstone 907598d
Update Whats New for custom policy for storage account TLS and secure…
Springstone bff97fa
Fixing policy description length
Springstone 59691d4
Add ddosPlanResourceId to eslzArm.json
Springstone 4e688df
Add ddosPlanResourceId parameter to ENFORCE-GuardrailsNetworkPolicyAs…
Springstone 28efe0f
Update Audit-PublicIpAddresses-UnusedResourcesCostOptimization policy…
Springstone f9c2aca
Auto-update Portal experience [Springstone/651f57a7]
github-actions[bot] cdda534
Update visibility condition for Network and Networking services in es…
Springstone b8a201d
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 5d5f73f
Merge branch 'policy-refresh-q3fy24' of https://github.com/Azure/Ente…
Springstone 5986775
Auto-update Portal experience [Springstone/79c74f4d]
github-actions[bot] a4e6c3f
Merge branch 'policy-refresh-q3fy24' of https://github.com/Azure/Ente…
Springstone 14d8d20
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 788ac66
Merge branch 'policy-refresh-q3fy24' of https://github.com/Azure/Ente…
Springstone 1c0bbee
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 091f87c
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 2f22f1d
Fixing a merge issue
Springstone 7e2deac
Meh, another merge issue.
Springstone bee9fb7
Update .github/workflows/update-portal.yml
Springstone a643a1a
Update src/resources/Microsoft.Authorization/policyDefinitions/Audit-…
Springstone 66f751a
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] da2c6a8
Update docs/wiki/ALZ-Policies-Extra.md
Springstone b9d6fea
Update src/resources/Microsoft.Authorization/policySetDefinitions/Enf…
Springstone e47bd94
Update src/resources/Microsoft.Authorization/policyDefinitions/Deploy…
Springstone 7a88d92
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] a8da58f
Update src/resources/Microsoft.Authorization/policyDefinitions/Deny-S…
Springstone d195087
feat: Add new generic policy for PaaS resources private endpoint to o…
Springstone 3049425
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 198d740
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] f708cff
Update docs/wiki/ALZ-Policies-Extra.md
Springstone a4f3f93
Update src/resources/Microsoft.Authorization/policySetDefinitions/Enf…
Springstone 6bf11fd
Update src/resources/Microsoft.Authorization/policyDefinitions/Deny-E…
Springstone 03c1034
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 5008c64
Update policy set definitions for enforcing guardrails
Springstone 9d4d316
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 1d907e1
Update docs/wiki/ALZ-Policies-Extra.md
Springstone 4600af3
Update src/resources/Microsoft.Authorization/policyDefinitions/Deny-L…
Springstone 4317ef0
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 3b92d0f
Update src/resources/Microsoft.Authorization/policyDefinitions/Deny-L…
Springstone f778788
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] e970c1c
Update policy set definitions for enforcing guardrails
Springstone b17189b
Update docs/wiki/ALZ-Policies-Extra.md
Springstone 939ca85
chore: Update ALZ-Policies-FAQ.md with deployment instructions
Springstone b0539aa
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 650d4cc
chore: Update ALZ-Policies-FAQ.md with deployment instructions
Springstone c9446eb
Update ALZ-Policies-Extra.md to fix typo in policy name
Springstone 8b027fb
Fix typo in ALZ-Policies-Extra.md
Springstone 76925b9
Update ALZ-Policies-Extra.md to fix typo in policy name
Springstone 1eed266
Update policy set definitions for enforcing guardrails
Springstone fd4e3d0
Update policy set definitions for enforcing guardrails
Springstone e602796
Update policy set definitions for enforcing guardrails
Springstone cb43fff
Auto-update Portal experience [Springstone/e2264bf6]
github-actions[bot] 34f58b7
Update policy set definitions for enforcing guardrails
Springstone c182e01
Merge branch 'FSI' of https://github.com/Springstone/Enterprise-Scale…
Springstone 57e77ee
Update policy set definitions to include Enforce-EncryptTransit_20240…
Springstone c10909e
Update policy set definitions to include Enforce-EncryptTransit_20240…
Springstone 579a017
Update policy set definitions to include Enforce-EncryptTransit_20240…
Springstone f23ea29
Update policy set definitions to include Enforce-EncryptTransit_20240…
Springstone d476a25
Update docs/wiki/ALZ-Policies-Extra.md
Springstone File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Update ALZ Portal accelerator with new "Workload Specific Compliance"…
… section and additional custom initiatives
- Loading branch information
commit e8762773b79b2bf55d72523f294b51def23b2fc1
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
10 changes: 5 additions & 5 deletions
10
eslzArm/managementGroupTemplates/policyDefinitions/README.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,16 +1,16 @@ | ||
| # Information relating to `policies.json` | ||
| # Information relating to `policies.json` and `initiatives.json` | ||
|
|
||
| The `policies.json` deployment template provides a unified deployment experience for creating all Policy Definitions and Policy Set Definitions (Initiatives) as recommended for the Azure landing zone reference implementation. | ||
| The `policies.json` and `initiatives.json` deployment templates provides a unified deployment experience for creating all Policy Definitions and Policy Set Definitions (Initiatives) as recommended for the Azure landing zone reference implementation. | ||
|
|
||
| This template is designed to work across the following clouds, ensuring the supported combination of policies are created in the customer environment: | ||
| This templates are designed to work across the following clouds, ensuring the supported combination of policies are created in the customer environment: | ||
|
|
||
| - AzureCloud (Public) | ||
| - AzureChinaCloud (Azure China / 21Vianet) | ||
| - AzureUSGovernment (US Government) | ||
|
|
||
| > **IMPORTANT:** | ||
| > Please note that the `policies.json` file located in this directory is programmatically generated and **must not** be manually edited. | ||
| > When making changes to policies, please refer to the [policies.bicep](../../../src/templates/policies.bicep) file. | ||
| > Please note that the `policies.json` and `initiatives.json` files located in this directory is programmatically generated and **must not** be manually edited. | ||
| > When making changes to policies, please refer to the [policies.bicep](../../../src/templates/policies.bicep) and [initiatives.bicep](../../../src/templates/initiatives.bicep) files. | ||
| <!-- markdownlint-disable-next-line MD036 --> | ||
| *further guidance to follow* | ||
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.