如何让Azure策略识别已部署集中式Metric的PIP合规性?
问题场景
已通过Azure Policy实现将租户内多订阅的Public IP(PIP)对应的Metric Alert部署到中央监控订阅/资源组,但策略无法识别已关联Metric Alert的PIP,始终标记为不合规。尝试过existenceCondition但默认仅能检查PIP所在订阅的资源;考虑过给PIP打标签,但不够简洁。当前代码可成功部署Metric Alert,但合规性判断失效。
解决方案
核心是利用Azure Policy的远程资源引用能力,在existenceCondition中直接查询中央监控订阅/资源组内的Metric Alert,验证其是否已关联当前PIP。具体修改如下:
关键修改点
- 在
existenceCondition中添加名称匹配与PIP关联验证逻辑 - 通过
existenceScope指定合规性检查的目标订阅和资源组,实现跨订阅查询 - 补充策略权限,确保能读取中央订阅内的Metric Alert资源
修改后的完整Policy代码
{ "mode": "All", "policyRule": { "if": { "allOf": [ { "field": "type", "equals": "Microsoft.Network/publicIPAddresses" } ] }, "then": { "effect": "deployIfNotExists", "details": { "roleDefinitionIds": [ "/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c", "/providers/Microsoft.Authorization/roleDefinitions/43d0d8ad-25c7-4714-9337-8ba259a9fe05" // 新增监控读取权限,用于查询中央订阅的Metric Alert ], "type": "Microsoft.Insights/metricAlerts", "existenceCondition": { "allOf": [ { "field": "name", "equals": "[concat(field('name'), '-VipAvailability')]" }, { "field": "properties.scopes[0]", "equals": "[field('id')]" } ] }, "existenceScope": { "subscriptionId": "{你的中央监控订阅ID}", "resourceGroupName": "{你的中央监控资源组名}" }, "deployment": { "properties": { "mode": "incremental", "template": { "$schema": "https://schema.management.azure.com/schemas/2018-05-01/subscriptionDeploymentTemplate.json#", "contentVersion": "1.0.0.0", "parameters": { "resourceName": { "type": "String", "metadata": { "displayName": "resourceName", "description": "Name of the resource" } }, "resourceId": { "type": "String", "metadata": { "displayName": "resourceId", "description": "Resource ID of the resource emitting the metric that will be used for the comparison" } }, "severity": { "type": "String" }, "windowSize": { "type": "String" }, "evaluationFrequency": { "type": "String" }, "autoMitigate": { "type": "String" }, "enabled": { "type": "String" }, "threshold": { "type": "String" } }, "variables": {}, "resources": [ { "type": "Microsoft.Resources/deployments", "apiVersion": "2022-09-01", "name": "[concat(parameters('resourceName'), '-MetricDeployment')]", "subscriptionId": "{你的中央监控订阅ID}", "resourceGroup": "{你的中央监控资源组名}", "properties": { "mode": "Incremental", "template": { "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#", "contentVersion": "1.0.0.0", "resources": [ { "type": "Microsoft.Insights/metricAlerts", "apiVersion": "2018-03-01", "name": "[concat(parameters('resourceName'), '-VipAvailability')]", "location": "global", "tags": { "_deployed_by_amba": true }, "properties": { "description": "Metric Alert for Network publicIPAddresses VipAvailability", "severity": "[parameters('severity')]", "enabled": "[parameters('enabled')]", "scopes": [ "[parameters('resourceId')]" ], "evaluationFrequency": "[parameters('evaluationFrequency')]", "windowSize": "[parameters('windowSize')]", "criteria": { "allOf": [ { "name": "VipAvailability", "metricNamespace": "Microsoft.Network/publicIPAddresses", "metricName": "VipAvailability", "operator": "LessThan", "threshold": "[parameters('threshold')]", "timeAggregation": "Average", "criterionType": "StaticThresholdCriterion" } ], "odata.type": "Microsoft.Azure.Monitor.SingleResourceMultipleMetricCriteria" }, "autoMitigate": "[parameters('autoMitigate')]", "parameters": { "severity": { "value": "[parameters('severity')]" }, "windowSize": { "value": "[parameters('windowSize')]" }, "evaluationFrequency": { "value": "[parameters('evaluationFrequency')]" }, "autoMitigate": { "value": "[parameters('autoMitigate')]" }, "enabled": { "value": "[parameters('enabled')]" }, "threshold": { "value": "[parameters('threshold')]" } } } } ] } } } ] }, "parameters": { "resourceName": { "value": "[field('name')]" }, "resourceId": { "value": "[field('id')]" }, "severity": { "value": "[parameters('severity')]" }, "windowSize": { "value": "[parameters('windowSize')]" }, "evaluationFrequency": { "value": "[parameters('evaluationFrequency')]" }, "autoMitigate": { "value": "[parameters('autoMitigate')]" }, "enabled": { "value": "[parameters('enabled')]" }, "threshold": { "value": "[if(contains(field('tags'), '_amba-VipAvailability-threshold-Override_'), field('tags._amba-VipAvailability-threshold-Override_'), parameters('threshold'))]" } } } } } } }, "parameters": { "severity": { "type": "String", "metadata": { "displayName": "Severity", "description": "Severity of the Alert" }, "allowedValues": [ "0", "1", "2", "3", "4" ], "defaultValue": "1" }, "windowSize": { "type": "String", "metadata": { "displayName": "Window Size", "description": "Window size for the alert" }, "allowedValues": [ "PT1M", "PT5M", "PT15M", "PT30M", "PT1H", "PT6H", "PT12H", "P1D" ], "defaultValue": "PT5M" }, "evaluationFrequency": { "type": "String", "metadata": { "displayName": "Evaluation Frequency", "description": "Evaluation frequency for the alert" }, "allowedValues": [ "PT1M", "PT5M", "PT15M", "PT30M", "PT1H" ], "defaultValue": "PT1M" }, "autoMitigate": { "type": "String", "metadata": { "displayName": "Auto Mitigate", "description": "Auto Mitigate for the alert" }, "allowedValues": [ "true", "false" ], "defaultValue": "true" }, "enabled": { "type": "String", "metadata": { "displayName": "Alert State", "description": "Alert state for the alert" }, "allowedValues": [ "true", "false" ], "defaultValue": "true" }, "threshold": { "type": "String", "metadata": { "displayName": "Threshold", "description": "Threshold for the alert" }, "defaultValue": "90" } } }
注意事项
- 替换代码中的
{你的中央监控订阅ID}和{你的中央监控资源组名}为实际值 existenceScope指定了合规性检查的目标范围,让策略能跨订阅查询Metric AlertexistenceCondition通过名称匹配+关联PIP的方式,精准验证合规性- 新增的Monitoring Reader角色确保策略有足够权限读取中央订阅的监控资源
内容的提问来源于stack exchange,提问作者JimmyACon
相关产品推荐
相关产品推荐

