Azure Storageのカスタマーマネージドキー設定の確認

組織のキー管理要件に合う暗号化キーを使用してください。

説明

Azure Storageは、既定でMicrosoftマネージドキーを使ってデータを暗号化します。カスタマーマネージドキーは、組織がキーの権限やローテーションを直接管理する必要がある場合の選択肢です。

想定される影響

診断ログ用アカウントで組織による独立したキー管理が必要な場合、Microsoftマネージドキーだけでは要件を満たせない可能性があります。

対処方法

必要に応じて、customer_managed_keyブロックか独立したazurerm_storage_account_customer_managed_keyリソースのどちらかで構成してください。マネージドIDのキー権限と、キーの復旧・ローテーション手順も用意してください。

例

以下は独立したキーリソースを関連付ける抜粋例です。診断カテゴリとID・キーの権限を別途構成し、管理が競合しないようアカウントのcustomer_managed_keyにignore_changesを適用してください。

変更前

hcl
resource "azurerm_storage_account" "logs" {
  name                     = "examplediagnosticlogs"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name               = "subscription-diagnostics"
  target_resource_id = data.azurerm_subscription.current.id
  storage_account_id = azurerm_storage_account.logs.id
}

変更後

hcl
resource "azurerm_storage_account" "logs" {
  name                     = "examplediagnosticlogs"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  identity {
    type         = "UserAssigned"
    identity_ids = [azurerm_user_assigned_identity.storage.id]
  }
}

resource "azurerm_storage_account_customer_managed_key" "logs" {
  storage_account_id         = azurerm_storage_account.logs.id
  key_vault_key_id           = azurerm_key_vault_key.storage.id
  user_assigned_identity_id  = azurerm_user_assigned_identity.storage.id
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name               = "subscription-diagnostics"
  target_resource_id = data.azurerm_subscription.current.id
  storage_account_id = azurerm_storage_account.logs.id
}

参考資料