You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过Azure Policy阻止从Azure Marketplace创建VM/VMSS的策略优化咨询

Azure Policy 验证:仅允许通过共享映像库创建VM/VMSS

现有策略的正确性分析

你的策略核心逻辑方向正确,但存在VMSS镜像路径未覆盖的关键漏洞:

  • 策略仅检查了VM的镜像引用路径 Microsoft.Compute/virtualMachines/storageProfile.imageReference.id,但VMSS的镜像引用路径为 Microsoft.Compute/virtualMachineScaleSets/virtualMachineProfile.storageProfile.imageReference.id,这会导致使用Marketplace镜像创建VMSS时绕过规则。
  • 排除发布者的匹配是大小写敏感的,若实际使用的发布者名称大小写与参数不一致,会导致排除规则失效。

需要补充/优化的参数与逻辑

  1. 覆盖VMSS的镜像引用路径:在anyOf中添加VMSS的字段检查,确保两种资源类型都被规则覆盖。
  2. 统一大小写匹配:将排除发布者的参数和实际字段值统一转换为小写(可通过toLowerCase()函数),避免大小写差异导致的规则失效。
  3. 明确自定义VHD的处理:若需求是仅允许共享映像库,自定义VHD(非Marketplace、非共享库)也应被阻止,当前策略已通过not contains galleries实现,但可在策略描述中明确这一点。
  4. 优化条件逻辑可读性:调整条件结构,明确允许的场景(排除的发布者 或 共享库镜像),其余场景一律拒绝。

优化后的策略示例

{
    "properties": {
        "displayName": "Block VM or VMSS creation except from Shared Image Gallery or excluded publishers",
        "description": "Restrict VM & VMSS creation to only Shared Image Gallery images or specified excluded publishers (e.g. NVAs)",
        "mode": "Indexed",
        "metadata": {
            "version": "1.1.0",
            "category": "Compute"
        },
        "parameters": {
            "publishersToExclude": {
                 "type": "Array",
                 "metadata": {
                      "displayName": "Excluded Publishers",
                      "description": "An array of publishers to exclude from evaluation, such as NVAs"
                 },
                 "defaultValue": [
                      "cisco",
                      "microsoft-aks",                     
                      "microsoft-ads",
                      "azuredatabricks"
               ]
            }
         },
        "policyRule": {
            "if": {
                "allOf": [
                    {
                       "field": "type",
                       "in": [
                            "Microsoft.Compute/virtualMachines",
                            "Microsoft.Compute/virtualMachineScaleSets"
                        ]
                    },
                    {
                        "not": {
                            "anyOf": [
                                {
                                    "field": "Microsoft.Compute/imagePublisher",
                                    "in": "[parameters('publishersToExclude')]"
                                },
                                {
                                    "field": "Microsoft.Compute/virtualMachines/storageProfile.imageReference.id",
                                    "contains": "Microsoft.Compute/galleries"
                                },
                                {
                                    "field": "Microsoft.Compute/virtualMachineScaleSets/virtualMachineProfile.storageProfile.imageReference.id",
                                    "contains": "Microsoft.Compute/galleries"
                                }
                            ]
                        }
                    }
                ]
            },        
            "then": {
                "effect": "deny"
            }
        }
    }
}

额外注意事项

  • 测试需覆盖全场景:用共享库镜像创建VM/VMSS(应允许)、用非排除发布者的Marketplace镜像创建(应拒绝)、用排除发布者的Marketplace镜像创建(应允许)、用自定义VHD创建(应拒绝)。
  • 后续添加排除发布者时,直接更新publishersToExclude参数即可,无需修改策略规则。

内容的提问来源于stack exchange,提问作者kalyani

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 22:06:06