Description
Disabling https_only on an Azure Storage account permits HTTP REST requests. Omitting this setting alone does not establish that an existing account permits HTTP.
Potential impact
Storage data and request credentials sent over HTTP can be exposed or modified on the network.
Remediation
Set https_only to true and update application and script URLs to HTTPS. Check existing client compatibility before the change.
Examples
The examples compare only the HTTPS requirement. This setting does not grant access to storage data.
Before
yaml
- name: Storage Account 생성
azure.azcollection.azure_rm_storageaccount:
resource_group: myResourceGroup
name: clh0002
type: Standard_RAGRS
https_only: false
After
yaml
- name: Storage Account 생성
azure.azcollection.azure_rm_storageaccount:
resource_group: myResourceGroup
name: clh0002
type: Standard_RAGRS
https_only: true