Azure Storageの安全な転送設定の確認

Storageへの要求に暗号化された接続を使用してください。

説明

Azure Storageで安全な転送を必須にしないと、HTTP要求を受け付ける場合があります。クライアントがHTTPを使うと、転送中のデータや資格情報が露出するおそれがあります。

想定される影響

暗号化されていない要求を傍受できる第三者に、データやSASトークンを読み取られるおそれがあります。

対処方法

https_traffic_only_enabled = trueを設定し、クライアントもHTTPSを使うように変更してください。ファイル共有では、SMB接続も暗号化されていることを確認してください。

例

以下は現在のAzureRMの安全な転送オプションを設定する抜粋例です。

変更前

hcl
resource "azurerm_storage_account" "example" {
  name                      = "example1"
  resource_group_name       = data.azurerm_resource_group.example.name
  location                  = data.azurerm_resource_group.example.location
  account_tier              = "Standard"
  account_replication_type  = "GRS"
  https_traffic_only_enabled = false
}

変更後

hcl
resource "azurerm_storage_account" "example" {
  name                      = "example"
  resource_group_name       = data.azurerm_resource_group.example.name
  location                  = data.azurerm_resource_group.example.location
  account_tier              = "Standard"
  account_replication_type  = "GRS"
  https_traffic_only_enabled = true
}

参考資料