Azure Storage 보안 전송 설정 점검

Storage 요청에 암호화된 연결을 사용하도록 설정하세요.

설명

Azure Storage에서 보안 전송을 요구하지 않으면 HTTP 요청을 허용할 수 있습니다. 클라이언트가 HTTP를 사용하면 전송 중 데이터와 인증 정보가 노출될 수 있습니다.

잠재적 영향

암호화되지 않은 요청을 가로챌 수 있는 주체가 데이터나 SAS 토큰을 읽을 수 있습니다.

해결 방법

https_traffic_only_enabled = true로 설정하고 클라이언트가 HTTPS를 사용하도록 변경하세요. 파일 공유를 사용한다면 암호화된 SMB 연결도 확인하세요.

예시

현재 AzureRM의 보안 전송 옵션을 설정하는 발췌 예시입니다.

변경 전

hcl
resource "azurerm_storage_account" "example" {
  name                      = "example1"
  resource_group_name       = data.azurerm_resource_group.example.name
  location                  = data.azurerm_resource_group.example.location
  account_tier              = "Standard"
  account_replication_type  = "GRS"
  https_traffic_only_enabled = false
}

변경 후

hcl
resource "azurerm_storage_account" "example" {
  name                      = "example"
  resource_group_name       = data.azurerm_resource_group.example.name
  location                  = data.azurerm_resource_group.example.location
  account_tier              = "Standard"
  account_replication_type  = "GRS"
  https_traffic_only_enabled = true
}

참조