説明
Azure Storageは、既定でMicrosoftマネージドキーを使ってデータを暗号化します。カスタマーマネージドキーは、組織がキーの権限やローテーションを直接管理する必要がある場合の選択肢です。
想定される影響
診断ログ用アカウントで組織による独立したキー管理が必要な場合、Microsoftマネージドキーだけでは要件を満たせない可能性があります。
対処方法
必要に応じて、customer_managed_keyブロックか独立したazurerm_storage_account_customer_managed_keyリソースのどちらかで構成してください。マネージドIDのキー権限と、キーの復旧・ローテーション手順も用意してください。
例
以下は独立したキーリソースを関連付ける抜粋例です。診断カテゴリとID・キーの権限を別途構成し、管理が競合しないようアカウントのcustomer_managed_keyにignore_changesを適用してください。
変更前
hcl
resource "azurerm_storage_account" "logs" {
name = "examplediagnosticlogs"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
}
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "subscription-diagnostics"
target_resource_id = data.azurerm_subscription.current.id
storage_account_id = azurerm_storage_account.logs.id
}
変更後
hcl
resource "azurerm_storage_account" "logs" {
name = "examplediagnosticlogs"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
identity {
type = "UserAssigned"
identity_ids = [azurerm_user_assigned_identity.storage.id]
}
}
resource "azurerm_storage_account_customer_managed_key" "logs" {
storage_account_id = azurerm_storage_account.logs.id
key_vault_key_id = azurerm_key_vault_key.storage.id
user_assigned_identity_id = azurerm_user_assigned_identity.storage.id
}
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "subscription-diagnostics"
target_resource_id = data.azurerm_subscription.current.id
storage_account_id = azurerm_storage_account.logs.id
}