설명
Azure Storage 데이터는 기본적으로 Microsoft 관리형 키로 암호화됩니다. 고객 관리형 키는 조직이 키 접근 권한과 교체를 직접 관리해야 할 때 사용하는 선택 사항입니다.
잠재적 영향
별도 키 통제가 필요한 진단 로그 저장소에서 Microsoft 관리형 키만 사용하면 조직의 키 관리 요구를 충족하지 못할 수 있습니다.
해결 방법
필요한 경우 customer_managed_key 블록이나 별도 azurerm_storage_account_customer_managed_key 리소스 중 하나로 구성하세요. 관리 ID의 키 권한과 키 복구·교체 절차도 준비하세요.
예시
별도 키 리소스를 연결하는 발췌 예시입니다. 필요한 진단 범주와 ID·키 권한은 별도로 구성하고, 계정의 customer_managed_key에는 ignore_changes를 적용해 관리 충돌을 피하세요.
변경 전
hcl
resource "azurerm_storage_account" "logs" {
name = "examplediagnosticlogs"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
}
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "subscription-diagnostics"
target_resource_id = data.azurerm_subscription.current.id
storage_account_id = azurerm_storage_account.logs.id
}
변경 후
hcl
resource "azurerm_storage_account" "logs" {
name = "examplediagnosticlogs"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
account_tier = "Standard"
account_replication_type = "GRS"
identity {
type = "UserAssigned"
identity_ids = [azurerm_user_assigned_identity.storage.id]
}
}
resource "azurerm_storage_account_customer_managed_key" "logs" {
storage_account_id = azurerm_storage_account.logs.id
key_vault_key_id = azurerm_key_vault_key.storage.id
user_assigned_identity_id = azurerm_user_assigned_identity.storage.id
}
resource "azurerm_monitor_diagnostic_setting" "example" {
name = "subscription-diagnostics"
target_resource_id = data.azurerm_subscription.current.id
storage_account_id = azurerm_storage_account.logs.id
}