Logic App 관리 ID 미설정

Logic App Standard의 지원되는 연결에 관리 ID를 사용하여 워크플로가 관리하는 비밀정보를 줄이세요.

설명

Logic App Standard 워크플로가 다른 Azure 서비스에 접근하기 위해 액세스 키나 클라이언트 비밀정보를 저장하면 유출과 교체 실패 위험이 생깁니다. 관리 ID는 이를 지원하는 커넥터와 작업에서 비밀정보를 직접 보관하지 않고 인증하도록 돕습니다. ID를 추가해도 모든 연결이 자동으로 전환되지는 않습니다.

잠재적 영향

  • 워크플로 또는 애플리케이션 설정에 장기 자격 증명이 노출될 수 있습니다.
  • 비밀정보 교체 실패로 서비스 중단이나 무단 접근이 발생할 수 있습니다.
  • 워크플로별 최소 권한과 접근 이력을 일관되게 관리하기 어려워질 수 있습니다.

해결 방법

Logic App Standard에 운영 목적에 맞는 identity를 구성하고, 관리 ID 인증을 지원하는 연결과 작업에서 실제로 사용하도록 설정하세요. 사용자 할당 ID에는 identity_ids를 지정하고 대상 리소스에 필요한 권한만 부여하세요. 각 연결을 테스트한 뒤 대체된 비밀정보를 제거하고 폐기하세요.

예시

아래는 Logic App Standard에 시스템 할당 관리 ID를 추가하는 예제입니다. 참조하는 계획과 스토리지, 커넥터 구성 및 대상 리소스 권한은 별도로 준비하세요.

변경 전

hcl
resource "azurerm_logic_app_standard" "example" {
  name                       = "example-logic-app"
  location                   = azurerm_resource_group.example.location
  resource_group_name        = azurerm_resource_group.example.name
  app_service_plan_id        = azurerm_service_plan.example.id
  storage_account_name       = azurerm_storage_account.example.name
  storage_account_access_key = azurerm_storage_account.example.primary_access_key
}

변경 후

hcl
resource "azurerm_logic_app_standard" "example" {
  name                       = "example-logic-app"
  location                   = azurerm_resource_group.example.location
  resource_group_name        = azurerm_resource_group.example.name
  app_service_plan_id        = azurerm_service_plan.example.id
  storage_account_name       = azurerm_storage_account.example.name
  storage_account_access_key = azurerm_storage_account.example.primary_access_key

  identity {
    type = "SystemAssigned"
  }
}

변경 후에는 SystemAssigned ID를 추가하지만 예제의 storage_account_access_key는 그대로 사용합니다. 관리 ID 추가만으로 스토리지 키나 모든 커넥터의 비밀정보가 제거되는 것은 아닙니다.

참조