Description
Explicitly managing an Azure VM’s NIC makes its subnet, public IP, and security groups easier to review. A NIC can also be created automatically, so omitting it does not mean the VM has no network connection or security group.
Potential impact
Unreviewed automatic network configuration can introduce an unintended public IP or permissive access rules.
Remediation
Specify the required NIC and check the NSGs applied to its NIC or subnet, its public IP, and routing. Naming a NIC alone does not restrict access.
Examples
The revised testvm001 value names a previously prepared NIC. Configure that NIC’s access policies separately.
Before
yaml
- name: VM 생성
azure_rm_virtualmachine:
resource_group: myResourceGroup
name: testvm001
vm_size: Standard_DS1_v2
admin_username: adminUser
admin_password: "{{ vm_admin_password }}"
image: customimage001
no_log: true
After
yaml
- name: VM 생성
azure_rm_virtualmachine:
resource_group: myResourceGroup
name: testvm001
vm_size: Standard_DS1_v2
admin_username: adminUser
admin_password: "{{ vm_admin_password }}"
image: customimage001
network_interfaces: testvm001
no_log: true