Terraform으로 정의한 Azure 리소스의 보안과 구성 설정을 다루는 148개의 문서입니다.
문서 목록
| 문서 | 경로 |
|---|---|
| AKS Azure Policy 적용 설정 점검 | terraform/azure/aks_uses_azure_policies_addon_disabled |
| AKS 디스크의 고객 관리형 키 설정 점검 | terraform/azure/aks_disk_encryption_set_id_undefined |
| AKS RBAC 비활성화 | terraform/azure/aks_rbac_disabled |
| AKS 네트워크 정책 설정 점검 | terraform/azure/aks_network_policy_misconfigured |
| AKS API 서버의 비공개 접근 설정 점검 | terraform/azure/aks_private_cluster_disabled |
| Activity Log 보존 기간 점검 | terraform/azure/small_activity_log_retention_period |
| App Service FTP 전송 보호 점검 | terraform/azure/app_service_ftps_enforce_disabled |
| App Service HTTP/2 설정 점검 | terraform/azure/app_service_http2_disabled |
| App Service 관리 ID 사용 점검 | terraform/azure/app_service_managed_identity_disabled |
| App Service 내장 인증 설정 점검 | terraform/azure/app_service_authentication_disabled |
| App Service PHP 런타임 지원 상태 점검 | terraform/azure/app_service_without_latest_php_version |
| App Service Python 런타임 지원 상태 점검 | terraform/azure/app_service_without_latest_python_version |
| App Service 클라이언트 인증서 요구 설정 점검 | terraform/azure/azure_app_service_client_certificate_disabled |
| Azure Application Gateway WAF 설정 점검 | terraform/azure/waf_is_disabled_for_azure_application_gateway |
| Azure AI Search 공용 네트워크 접근 점검 | terraform/azure/azure_cognitive_search_public_network_access_enabled |
| Defender for Cloud 보호 계획 점검 | terraform/azure/security_center_pricing_tier_is_not_standard |
| Azure Front Door WAF 정책 연결 점검 | terraform/azure/azure_front_door_waf_disabled |
| Azure 게스트 사용자 역할 권한 점검 | terraform/azure/role_assignment_not_limit_guest_users_permissions |
| Key Vault 비밀정보 만료일 설정 점검 | terraform/azure/secret_expiration_not_set |
| Azure Key Vault 감사 로그 수집 점검 | terraform/azure/vault_auditing_disabled |
| Azure MySQL TLS 연결 강제 설정 점검 | terraform/azure/mysql_ssl_connection_disabled |
| Azure Network Watcher 흐름 로그 비활성화 | terraform/azure/network_watcher_flow_disabled |
| Azure PostgreSQL 연결 암호화 설정 점검 | terraform/azure/ssl_enforce_is_disabled |
| Azure PostgreSQL 인증 실패 연결 제한 설정 점검 | terraform/azure/postgresql_server_without_connection_throttling |
| Azure PostgreSQL 연결 종료 로그 비활성화 | terraform/azure/postgresql_log_disconnections_not_set |
| Azure PostgreSQL 위협 탐지 설정 점검 | terraform/azure/postgresql_server_threat_detection_policy_disabled |
| Azure PostgreSQL 접속 로그 설정 점검 | terraform/azure/postgresql_log_connections_not_set |
| Azure PostgreSQL 체크포인트 로그 비활성화 | terraform/azure/postgresql_log_checkpoints_disabled |
| Azure PostgreSQL 쿼리 수행 시간 로그 설정 점검 | terraform/azure/postgresql_log_duration_not_set |
| Azure Redis 비암호화 연결 허용 | terraform/azure/redis_cache_allows_non_ssl_connections |
| Azure Redis 유지보수 일정 점검 | terraform/azure/redis_not_updated_regularly |
| Azure SQL Database 위협 탐지 설정 점검 | terraform/azure/sql_database_audit_disabled |
| Azure SQL 서버 감사 로그 설정 점검 | terraform/azure/sql_server_auditing_disabled |
| Azure SQL 보안 경고의 관리자 이메일 설정 점검 | terraform/azure/sql_server_alert_email_disabled |
| Azure SQL 서버 보안 경고 설정 점검 | terraform/azure/mssql_server_database_with_alerts_disabled |
| Azure NSG의 인터넷 SSH 접근 허용 | terraform/azure/ssh_is_exposed_to_the_internet |
| Azure Storage 보안 전송 설정 점검 | terraform/azure/storage_account_not_forcing_https |
| Azure 파일 공유 접근 정책의 과도한 권한 | terraform/azure/storage_share_allows_all_acl_permissions |
| Azure Storage Shared Key 접근 허용 | terraform/azure/storage_account_with_shared_access_key |
| Azure Table 접근 정책의 과도한 권한 | terraform/azure/storage_table_allows_all_acl_permissions |
| Azure Storage의 신뢰된 서비스 예외 점검 | terraform/azure/trusted_microsoft_services_not_enabled |
| Azure Storage 최소 TLS 버전 점검 | terraform/azure/storage_account_not_using_latest_tls_encryption_version |
| Azure Storage 테넌트 간 개체 복제 허용 | terraform/azure/storage_account_with_cross_tenant_replication_enabled |
| Azure User Access Administrator 할당 범위 점검 | terraform/azure/use_of_user_access_administrator_role_is_not_restricted |
| Azure VM 관리 디스크 전환 점검 | terraform/azure/vm_without_managed_disk |
| Azure VM 네트워크 인터페이스 연결 점검 | terraform/azure/vm_not_attached_to_network |
| Azure Web App HTTPS 강제 설정 점검 | terraform/azure/web_app_accepting_traffic_other_than_https |
| Azure 네트워크 인터페이스 IP 전달 설정 점검 | terraform/azure/network_interfaces_ip_forwarding_enabled |
| Azure 네트워크 인터페이스 공인 IP 연결 점검 | terraform/azure/network_interfaces_with_public_ip |
| Azure 리소스 진단 설정 점검 | terraform/azure/resource_without_diagnostic_settings |
| Azure NSG의 민감 포트 접근 허용 점검 | terraform/azure/sensitive_port_is_exposed_to_small_public_network |
| Azure 보안 연락처 이메일 미설정 | terraform/azure/security_contact_email |
| Azure 사용자 지정 역할 정의 변경 권한 | terraform/azure/role_definition_allows_custom_role_creation |
| Azure 서비스 리소스 로그 수집 점검 | terraform/azure/service_without_resource_logging |
| Azure 흐름 로그 보존 기간 점검 | terraform/azure/small_flow_logs_retention_period |
| Azure Databricks 고객 관리형 키 적용 범위 점검 | terraform/azure/databricks_workspace_without_cmk |
| Container Registry 관리자 사용자 활성화 | terraform/azure/admin_user_enabled_for_container_registry |
| Key Vault 비밀정보의 콘텐츠 유형 미설정 | terraform/azure/key_vault_secrets_content_type_undefined |
| Cosmos DB 계정 태그 미설정 | terraform/azure/cosmos_db_account_without_tags |
| Databricks 진단 로그 수집 점검 | terraform/azure/databricks_diagnostic_logging_unconfigured |
| Function App FTP 전송 보호 점검 | terraform/azure/function_app_ftps_enforce_disabled |
| Function App HTTP/2 사용 설정 점검 | terraform/azure/function_app_http2_disabled |
| Function App 관리 ID 미설정 | terraform/azure/function_app_managed_identity_disabled |
| Function App 인증 설정 점검 | terraform/azure/function_app_authentication_disabled |
| Function App 클라이언트 인증서 요구 설정 점검 | terraform/azure/function_app_client_certificates_unrequired |
| Cosmos DB IP 방화벽 구성 점검 필요 | terraform/azure/cosmosdb_account_ip_range_filter_not_set |
| Azure Backup Vault의 백업 변경·삭제 보호 점검 | terraform/azure/backup_vault_without_immutability |
| Recovery Services Vault 백업 불변성 점검 | terraform/azure/recovery_services_vaut_without_immutability |
| AKS Kubernetes Dashboard 사용 점검 | terraform/azure/dashboard_is_enabled |
| Azure SQL 서버 감사 정책 설정 점검 | terraform/azure/mssql_server_auditing_disabled |
| Azure SQL 감사 정책의 보존 기간 점검 | terraform/azure/small_mssql_audit_retention_period |
| Managed Disk 암호화 방식 점검 | terraform/azure/encryption_on_managed_disk_disabled |
| MariaDB 워크로드의 지역 재해 복구 준비 | terraform/azure/mariadb_server_georedundant_backup_disabled |
| Network Security Group 삭제 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_delete_network_security_group_not_configured |
| Network Security Group 생성·변경 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_create_or_update_network_security_group_not_configured |
| Azure 서브넷의 NSG 연결 점검 | terraform/azure/security_group_is_not_configured |
| Policy Assignment 삭제 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_delete_policy_assignment_not_configured |
| Policy Assignment 생성·변경 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_create_policy_assignment_not_configured |
| Azure PostgreSQL 로그 보존 설정 점검 | terraform/azure/log_retention_is_not_set |
| Azure PostgreSQL 서버 로그 보존 기간 점검 | terraform/azure/small_postgresql_db_server_log_retention_period |
| Azure PostgreSQL 저장 데이터 암호화 설정 점검 | terraform/azure/postgresql_server_infrastructure_encryption_disabled |
| Azure PostgreSQL 지역 중복 백업 설정 점검 | terraform/azure/geo_redundancy_is_disabled |
| Public IP 삭제 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_delete_public_ip_address_rule_not_configured |
| Public IP 생성·변경 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_create_or_update_public_ip_address_rule_not_configured |
| Azure Key Vault 영구 삭제 방지 점검 | terraform/azure/key_vault_purge_protection_is_enabled |
| Azure RDP 규칙의 공개 접근 범위 점검 | terraform/azure/rdp_is_exposed_to_the_internet |
| SQL Server 방화벽 규칙 삭제 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_delete_sql_server_firewall_rule_not_configured |
| SQL Server 방화벽 규칙 생성·변경 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_create_or_update_sql_server_firewall_rule_not_configured |
| Azure SQL의 Microsoft Entra 관리자 이름 점검 | terraform/azure/sql_server_predictable_active_directory_admin_account_name |
| Azure SQL 관리자 로그인 이름 점검 | terraform/azure/sql_server_predictable_admin_account_name |
| Azure SQL의 Microsoft Entra 관리자 설정 점검 | terraform/azure/ad_admin_not_configured_for_sql_server |
| Azure SQL 감사 로그 보존 기간 점검 | terraform/azure/small_msql_server_audit_retention |
| Security Solution 삭제 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_delete_security_solution_not_configured |
| Security Solution 생성·변경 Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_create_or_update_security_solution_not_configured |
| Service Fabric 관리 인증 설정 점검 | terraform/azure/azure_active_directory_authentication |
| Service Health Activity Log Alert 점검 | terraform/azure/activity_log_alert_for_service_health_not_configured |
| Azure Backup Vault의 일시 삭제 보호 점검 | terraform/azure/backup_vault_without_soft_delete |
| Recovery Services Vault 삭제 후 복구 보호 점검 | terraform/azure/recovery_services_vaut_without_soft_delete |
| Azure Blob 컨테이너 삭제 복구 보존 기간 점검 | terraform/azure/containers_without_soft_delete |
| Azure Blob 삭제 복구 보존 기간 점검 | terraform/azure/blob_storage_without_soft_delete |
| Azure 파일 공유의 일시 삭제 보호 점검 | terraform/azure/file_share_without_soft_delete |
| Beta - 삭제 보호 확인이 필요한 Azure 저장소 계정 | terraform/azure/storage_account_without_delete_lock |
| Virtual Network DDoS 보호 계획 점검 | terraform/azure/virtual_network_with_ddos_protection_plan_disabled |
| Redis 방화벽 접근 범위 점검 필요 | terraform/azure/redis_publicly_accessible |
| Azure Storage Account 공개 접근 설정 점검 | terraform/azure/public_storage_account |
| 익명 읽기가 허용된 Azure Storage Container | terraform/azure/storage_container_is_publicly_accessible |
| Azure MSSQL Server 공용 네트워크 접근 점검 | terraform/azure/mssql_server_public_network_access_enabled |
| 공용 네트워크 접근이 활성화된 Azure MariaDB Server | terraform/azure/mariadb_public_network_access_enabled |
| 이전 Azure MySQL Server 공용 네트워크 접근 점검 | terraform/azure/mysql_server_public_access_enabled |
| Azure Recovery Services Vault 공용 네트워크 접근 점검 | terraform/azure/recovery_services_vaut_with_public_network_access |
| Azure Container Registry 삭제 보호 잠금 점검 | terraform/azure/azure_container_registry_with_no_locks |
| Azure Databricks 가상 네트워크 배치 점검 | terraform/azure/databricks_workspace_using_default_virtual_network |
| Azure Storage Account 기본 네트워크 접근 제한 점검 | terraform/azure/default_azure_storage_account_network_access_is_too_permissive |
| Azure Linux VM 비밀번호 인증 허용 | terraform/azure/azure_instance_using_basic_authentication |
| Azure Redis 방화벽 허용 범위 점검 | terraform/azure/firewall_rule_allows_too_many_hosts_to_access_redis_cache |
| Key Vault 키 만료일 설정 점검 | terraform/azure/key_expiration_not_set |
| Azure NSG의 사설망 민감 포트 접근 점검 | terraform/azure/sensitive_port_is_exposed_to_wide_private_network |
| Azure 관리·내부 서비스 포트의 공개 접근 범위 점검 | terraform/azure/sensitive_port_is_exposed_to_entire_network |
| Azure Files SMB 채널 암호 정책 점검 | terraform/azure/storage_account_using_unsafe_smb_channel_encryption |
| 이메일 경고 비활성화 | terraform/azure/email_alerts_disabled |
| Azure SQL Database 저장 시 암호화 점검 | terraform/azure/sql_database_without_data_encryption |
| Diagnostic Setting 로그 카테고리 점검 | terraform/azure/diagnostic_settings_without_appropriate_logging |
| 모든 IPv4 주소를 허용하는 Redis 방화벽 | terraform/azure/redis_entirely_accessible |
| 전체 IPv4 범위를 지정한 Azure 데이터베이스 방화벽 규칙 | terraform/azure/sql_server_ingress_from_any_ip |
| Azure Files SMB 버전 정책 점검 | terraform/azure/storage_account_not_using_latest_smb_protocol_version |
| App Service 최소 TLS 버전 설정 점검 | terraform/azure/app_service_not_using_latest_tls_encryption_version |
| Function App 최소 TLS 버전 점검 | terraform/azure/function_app_not_using_latest_tls_encryption_version |
| Azure 데이터베이스 방화벽의 광범위한 접근 허용 | terraform/azure/unrestricted_sql_server_access |
| AKS 감사 로그 수집 점검 | terraform/azure/aks_without_audit_logs |
| App Service 슬롯 관리 ID 사용 점검 | terraform/azure/app_service_slot_managed_identity_disabled |
| Azure Container Registry 권한 범위 점검 | terraform/azure/azure_container_registry_with_broad_permissions |
| Container App 관리 ID 미설정 | terraform/azure/container_app_managed_identity_disabled |
| Container Group 관리 ID 미설정 | terraform/azure/container_group_managed_identity_disabled |
| Azure Container Instances 네트워크 공개 범위 점검 | terraform/azure/container_instances_not_using_private_virtual_networks |
| Managed Disk 고객 관리형 키 설정 점검 | terraform/azure/disk_encryption_on_managed_disk_disabled |
| Function App 배포 슬롯 최소 TLS 버전 점검 | terraform/azure/function_app_deployment_slot_not_using_latest_tls_encryption_version |
| Key Vault 키의 HSM 보호 설정 점검 | terraform/azure/key_vault_without_hsm_protection |
| AKS 관리 ID 사용 점검 | terraform/azure/kubernetes_cluster_managed_identity_disabled |
| Logic App 관리 ID 미설정 | terraform/azure/logic_app_managed_identity_disabled |
| Azure SQL의 최소 TLS 버전 점검 | terraform/azure/mssql_not_using_latest_tls_encryption_version |
| Azure PostgreSQL 최소 TLS 버전 설정 점검 | terraform/azure/postgresql_not_using_latest_tls_encryption_version |
| Azure Redis 관리 ID 사용 범위 점검 | terraform/azure/redis_cache_managed_identity_is_not_set_to_system_assigned |
| Azure Redis 최소 TLS 버전 점검 | terraform/azure/redis_cache_not_using_latest_tls_encryption_version |
| Azure Storage 고객 관리형 키 설정 점검 | terraform/azure/storage_account_without_cmk |
| Windows VM 자동 업데이트 설정 점검 | terraform/azure/vm_with_automatic_updates_disabled |
| Azure VM 확장 작업 허용 점검 | terraform/azure/vm_with_extension_operations_enabled |
| Azure VM 관리자 SSH 공개 키 설정 점검 | terraform/azure/vm_without_admin_ssh_public_key_set |
| Azure VM 호스트 암호화 설정 점검 | terraform/azure/vm_without_encryption_at_host |