Azure Storage 고객 관리형 키 설정 점검

조직의 키 관리 요구에 맞는 암호화 키를 사용하세요.

설명

Azure Storage 데이터는 기본적으로 Microsoft 관리형 키로 암호화됩니다. 고객 관리형 키는 조직이 키 접근 권한과 교체를 직접 관리해야 할 때 사용하는 선택 사항입니다.

잠재적 영향

별도 키 통제가 필요한 진단 로그 저장소에서 Microsoft 관리형 키만 사용하면 조직의 키 관리 요구를 충족하지 못할 수 있습니다.

해결 방법

필요한 경우 customer_managed_key 블록이나 별도 azurerm_storage_account_customer_managed_key 리소스 중 하나로 구성하세요. 관리 ID의 키 권한과 키 복구·교체 절차도 준비하세요.

예시

별도 키 리소스를 연결하는 발췌 예시입니다. 필요한 진단 범주와 ID·키 권한은 별도로 구성하고, 계정의 customer_managed_key에는 ignore_changes를 적용해 관리 충돌을 피하세요.

변경 전

hcl
resource "azurerm_storage_account" "logs" {
  name                     = "examplediagnosticlogs"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name               = "subscription-diagnostics"
  target_resource_id = data.azurerm_subscription.current.id
  storage_account_id = azurerm_storage_account.logs.id
}

변경 후

hcl
resource "azurerm_storage_account" "logs" {
  name                     = "examplediagnosticlogs"
  resource_group_name      = azurerm_resource_group.example.name
  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "GRS"

  identity {
    type         = "UserAssigned"
    identity_ids = [azurerm_user_assigned_identity.storage.id]
  }
}

resource "azurerm_storage_account_customer_managed_key" "logs" {
  storage_account_id         = azurerm_storage_account.logs.id
  key_vault_key_id           = azurerm_key_vault_key.storage.id
  user_assigned_identity_id  = azurerm_user_assigned_identity.storage.id
}

resource "azurerm_monitor_diagnostic_setting" "example" {
  name               = "subscription-diagnostics"
  target_resource_id = data.azurerm_subscription.current.id
  storage_account_id = azurerm_storage_account.logs.id
}

참조