You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Azure策略识别已部署集中式Metric的PIP合规性?

问题场景

已通过Azure Policy实现将租户内多订阅的Public IP(PIP)对应的Metric Alert部署到中央监控订阅/资源组,但策略无法识别已关联Metric Alert的PIP,始终标记为不合规。尝试过existenceCondition但默认仅能检查PIP所在订阅的资源;考虑过给PIP打标签,但不够简洁。当前代码可成功部署Metric Alert,但合规性判断失效。

解决方案

核心是利用Azure Policy的远程资源引用能力,在existenceCondition中直接查询中央监控订阅/资源组内的Metric Alert,验证其是否已关联当前PIP。具体修改如下:

关键修改点

  • 在existenceCondition中添加名称匹配与PIP关联验证逻辑
  • 通过existenceScope指定合规性检查的目标订阅和资源组,实现跨订阅查询
  • 补充策略权限,确保能读取中央订阅内的Metric Alert资源

修改后的完整Policy代码

{
  "mode": "All",
  "policyRule": {
    "if": {
      "allOf": [
        {
          "field": "type",
          "equals": "Microsoft.Network/publicIPAddresses"
        }
      ]
    },
    "then": {
      "effect": "deployIfNotExists",
      "details": {
        "roleDefinitionIds": [
          "/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c",
          "/providers/Microsoft.Authorization/roleDefinitions/43d0d8ad-25c7-4714-9337-8ba259a9fe05" // 新增监控读取权限,用于查询中央订阅的Metric Alert
        ],
        "type": "Microsoft.Insights/metricAlerts",
        "existenceCondition": {
          "allOf": [
            {
              "field": "name",
              "equals": "[concat(field('name'), '-VipAvailability')]"
            },
            {
              "field": "properties.scopes[0]",
              "equals": "[field('id')]"
            }
          ]
        },
        "existenceScope": {
          "subscriptionId": "{你的中央监控订阅ID}",
          "resourceGroupName": "{你的中央监控资源组名}"
        },
        "deployment": {
          "properties": {
            "mode": "incremental",
            "template": {
              "$schema": "https://schema.management.azure.com/schemas/2018-05-01/subscriptionDeploymentTemplate.json#",
              "contentVersion": "1.0.0.0",
              "parameters": {
                "resourceName": {
                  "type": "String",
                  "metadata": {
                    "displayName": "resourceName",
                    "description": "Name of the resource"
                  }
                },
                "resourceId": {
                  "type": "String",
                  "metadata": {
                    "displayName": "resourceId",
                    "description": "Resource ID of the resource emitting the metric that will be used for the comparison"
                  }
                },
                "severity": {
                  "type": "String"
                },
                "windowSize": {
                  "type": "String"
                },
                "evaluationFrequency": {
                  "type": "String"
                },
                "autoMitigate": {
                  "type": "String"
                },
                "enabled": {
                  "type": "String"
                },
                "threshold": {
                  "type": "String"
                }
              },
              "variables": {},
              "resources": [
                {
                  "type": "Microsoft.Resources/deployments",
                  "apiVersion": "2022-09-01",
                  "name": "[concat(parameters('resourceName'), '-MetricDeployment')]",
                  "subscriptionId": "{你的中央监控订阅ID}",
                  "resourceGroup": "{你的中央监控资源组名}",
                  "properties": {
                    "mode": "Incremental",
                    "template": {
                      "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
                      "contentVersion": "1.0.0.0",
                      "resources": [
                        {
                          "type": "Microsoft.Insights/metricAlerts",
                          "apiVersion": "2018-03-01",
                          "name": "[concat(parameters('resourceName'), '-VipAvailability')]",
                          "location": "global",
                          "tags": {
                            "_deployed_by_amba": true
                          },
                          "properties": {
                            "description": "Metric Alert for Network publicIPAddresses VipAvailability",
                            "severity": "[parameters('severity')]",
                            "enabled": "[parameters('enabled')]",
                            "scopes": [
                              "[parameters('resourceId')]"
                            ],
                            "evaluationFrequency": "[parameters('evaluationFrequency')]",
                            "windowSize": "[parameters('windowSize')]",
                            "criteria": {
                              "allOf": [
                                {
                                  "name": "VipAvailability",
                                  "metricNamespace": "Microsoft.Network/publicIPAddresses",
                                  "metricName": "VipAvailability",
                                  "operator": "LessThan",
                                  "threshold": "[parameters('threshold')]",
                                  "timeAggregation": "Average",
                                  "criterionType": "StaticThresholdCriterion"
                                }
                              ],
                              "odata.type": "Microsoft.Azure.Monitor.SingleResourceMultipleMetricCriteria"
                            },
                            "autoMitigate": "[parameters('autoMitigate')]",
                            "parameters": {
                              "severity": {
                                "value": "[parameters('severity')]"
                              },
                              "windowSize": {
                                "value": "[parameters('windowSize')]"
                              },
                              "evaluationFrequency": {
                                "value": "[parameters('evaluationFrequency')]"
                              },
                              "autoMitigate": {
                                "value": "[parameters('autoMitigate')]"
                              },
                              "enabled": {
                                "value": "[parameters('enabled')]"
                              },
                              "threshold": {
                                "value": "[parameters('threshold')]"
                              }
                            }
                          }
                        }
                      ]
                    }
                  }
                }
              ]
            },
            "parameters": {
              "resourceName": {
                "value": "[field('name')]"
              },
              "resourceId": {
                "value": "[field('id')]"
              },
              "severity": {
                "value": "[parameters('severity')]"
              },
              "windowSize": {
                "value": "[parameters('windowSize')]"
              },
              "evaluationFrequency": {
                "value": "[parameters('evaluationFrequency')]"
              },
              "autoMitigate": {
                "value": "[parameters('autoMitigate')]"
              },
              "enabled": {
                "value": "[parameters('enabled')]"
              },
              "threshold": {
                "value": "[if(contains(field('tags'), '_amba-VipAvailability-threshold-Override_'), field('tags._amba-VipAvailability-threshold-Override_'), parameters('threshold'))]"
              }
            }
          }
        }
      }
    }
  },
  "parameters": {
    "severity": {
      "type": "String",
      "metadata": {
        "displayName": "Severity",
        "description": "Severity of the Alert"
      },
      "allowedValues": [
        "0",
        "1",
        "2",
        "3",
        "4"
      ],
      "defaultValue": "1"
    },
    "windowSize": {
      "type": "String",
      "metadata": {
        "displayName": "Window Size",
        "description": "Window size for the alert"
      },
      "allowedValues": [
        "PT1M",
        "PT5M",
        "PT15M",
        "PT30M",
        "PT1H",
        "PT6H",
        "PT12H",
        "P1D"
      ],
      "defaultValue": "PT5M"
    },
    "evaluationFrequency": {
      "type": "String",
      "metadata": {
        "displayName": "Evaluation Frequency",
        "description": "Evaluation frequency for the alert"
      },
      "allowedValues": [
        "PT1M",
        "PT5M",
        "PT15M",
        "PT30M",
        "PT1H"
      ],
      "defaultValue": "PT1M"
    },
    "autoMitigate": {
      "type": "String",
      "metadata": {
        "displayName": "Auto Mitigate",
        "description": "Auto Mitigate for the alert"
      },
      "allowedValues": [
        "true",
        "false"
      ],
      "defaultValue": "true"
    },
    "enabled": {
      "type": "String",
      "metadata": {
        "displayName": "Alert State",
        "description": "Alert state for the alert"
      },
      "allowedValues": [
        "true",
        "false"
      ],
      "defaultValue": "true"
    },
    "threshold": {
      "type": "String",
      "metadata": {
        "displayName": "Threshold",
        "description": "Threshold for the alert"
      },
      "defaultValue": "90"
    }
  }
}

注意事项

  1. 替换代码中的{你的中央监控订阅ID}和{你的中央监控资源组名}为实际值
  2. existenceScope指定了合规性检查的目标范围,让策略能跨订阅查询Metric Alert
  3. existenceCondition通过名称匹配+关联PIP的方式,精准验证合规性
  4. 新增的Monitoring Reader角色确保策略有足够权限读取中央订阅的监控资源

内容的提问来源于stack exchange,提问作者JimmyACon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 23:57:01