Description
An Azure VM connects to a subnet and network paths through a network interface. Without a required NIC it cannot be deployed or communicate normally. Attaching a NIC does not automatically configure an NSG or secure access rules.
Potential impact
- VM deployment, communication or management can fail.
- Attaching a NIC without reviewing security rules can allow unintended access.
Remediation
- Attach a valid NIC through
network_interface_idsand configure the correct subnet and IP settings. Use resource references to express Terraform dependencies. - Review NSGs on the NIC or subnet and the routes, allowing only required traffic. Protect administrator authentication separately.
Examples
These excerpts compare network attachment on the legacy azurerm_virtual_machine resource. OS disks, images and credentials are omitted. The retained password-authentication setting needs separate review.
Before
hcl
resource "azurerm_virtual_machine" "example" {
name = "${var.prefix}-vm"
location = azurerm_resource_group.main.location
resource_group_name = azurerm_resource_group.main.name
network_interface_ids = []
vm_size = "Standard_DS1_v2"
os_profile_linux_config {
disable_password_authentication = false
}
}
After
hcl
resource "azurerm_network_interface" "example" {
name = "${var.prefix}-nic"
location = azurerm_resource_group.main.location
resource_group_name = azurerm_resource_group.main.name
ip_configuration {
name = "testconfiguration1"
subnet_id = azurerm_subnet.internal.id
private_ip_address_allocation = "Dynamic"
}
}
resource "azurerm_virtual_machine" "example" {
name = "${var.prefix}-vm"
location = azurerm_resource_group.main.location
resource_group_name = azurerm_resource_group.main.name
network_interface_ids = [azurerm_network_interface.example.id]
vm_size = "Standard_DS1_v2"
os_profile_linux_config {
disable_password_authentication = false
}
}
Explanation:
- Before: The NIC list is empty, leaving required VM networking absent.
- After: A NIC is created and attached. Configure NSGs and access rules separately.