You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure Pipeline中PSRule忽略.ps-rule/目录本地规则问题

PSRule忽略自定义抑制组规则的排查与解决

问题场景

基于ALZ-Bicep构建的项目中,Azure Pipeline执行PSRule扫描时,.ps-rule/LogForAutomation.Rule.yaml中定义的抑制组规则未生效,PSRule依然触发了Azure.Automation.AuditLogs和Azure.Automation.PlatformLogs规则的告警。相关配置如下:

Pipeline配置

trigger:
- none

pool:
  vmImage: ubuntu-latest

stages:
- stage: PSrule
  jobs:
  - job: PSrule
    displayName: PSrule best practice validation
    steps:
      # Install PSRule.Rules.Azure from the PowerShell Gallery
      - task: ps-rule-install@2
        inputs:
          module: PSRule.Rules.Azure   # Install PSRule.Rules.Azure from the PowerShell Gallery.

      # Run analysis from JSON files using the `PSRule.Rules.Azure` module and custom rules from `.ps-rule/`.
      - task: ps-rule-assert@2
        continueOnError: true
        inputs:
          inputType: repository
          modules: 'PSRule.Rules.Azure'            # Analyze objects using the rules within the PSRule.Rules.Azure PowerShell module.
          baseline: 'Azure.GA_2023_09'
          option: 'ps-rule.yaml'                   # Use the rules defined in 'ps-rule.yaml'.
          source: '.ps-rule/'                      # Additionally, analyze object using custom rules from '.ps-rule/'.
          outputFormat: NUnit3                     # Save results to an NUnit report.
          outputPath: reports/ps-results.xml  # Write NUnit report to 'reports/ps-rule-results.xml'.

ps-rule.yaml配置

#
# PSRule for Azure configuration
#

# Use rules from the following modules/
include:
  module:
  - 'PSRule.Rules.Azure'

# Require a minimum version of modules that include referenced baseline.
requires:
  PSRule: '@pre >=2.3.2'
  PSRule.Rules.Azure: '@pre >=1.18.1'

# Reference the repository in output.
repository:
  url: xxxxxxxxx

execution:
  # Ignore warnings for resources and objects that don't have any rules.
  notProcessedWarning: false

configuration:
  # Enable expansion for Bicep source files.
  AZURE_BICEP_FILE_EXPANSION: false

  # Expand Bicep module from Azure parameter files.
  AZURE_PARAMETER_FILE_EXPANSION: true

  # Set timeout for expanding Bicep source files.
  AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 15

input:
  pathIgnore:
  # Ignore common files that don't need analysis.
  - '**/bicepconfig.json'
  - '.github/'

  # Exclude samples/ test files from modules
  - 'infra-as-code/bicep/**/samples/*.bicep'

binding:
  preferTargetInfo: true
  targetType:
  - resourceType
  - type

rule:
  includeLocal: true
  exclude:
  # Ignore these recommendations for this repo.
  - Azure.Resource.UseTags
  - Azure.ACR.MinSku
  - Azure.ACR.ContentTrust
  - Azure.Policy.AssignmentAssignedBy

  # Currently a bug as of v1.15.2. Review in the next release.
  - Azure.PublicIP.Name

自定义抑制组规则(.ps-rule/LogForAutomation.Rule.yaml)

# Synopsis: Ignore automation account audit diagnostic logs are enabled as these are covered by DINE policies in ALZ
apiVersion: github.com/microsoft/PSRule/v1
kind: SuppressionGroup
metadata:
  name: ALZ.DiagLogForAutomation
spec:
  rule:
  - Azure.Automation.AuditLogs
  - Azure.Automation.PlatformLogs
  if:
    allOf:
    - name: '.'
      contains: alz-automation-account
    - type: '.'
      in:
      - Microsoft.Automation/automationAccounts

排查与解决方案

1. 修正抑制组条件表达式语法

当前抑制组的条件写法不符合PSRule语法规范,正确写法需要用field字段指定匹配的属性:

if:
  allOf:
  - field: name
    contains: alz-automation-account
  - field: type
    in:
    - Microsoft.Automation/automationAccounts

2. 确认规则文件加载有效性

  • 确保.ps-rule/目录下的规则文件命名符合PSRule要求:必须以.Rule.yaml或.Rule.json结尾(当前文件命名符合要求)
  • PSRule会递归扫描source指定目录下的规则文件,无需额外配置路径

3. 验证基线与自定义规则的兼容性

使用Azure.GA_2023_09基线时,可能存在基线覆盖自定义规则的情况。可以临时移除baseline配置,测试抑制组是否生效:若生效,需调整基线与自定义规则的优先级,或在基线中引入自定义抑制组。

4. 启用调试日志确认规则加载状态

在ps-rule-assert@2任务中添加logLevel: Debug参数,查看日志是否包含加载自定义抑制组的条目:

- task: ps-rule-assert@2
  continueOnError: true
  inputs:
    inputType: repository
    modules: 'PSRule.Rules.Azure'
    baseline: 'Azure.GA_2023_09'
    option: 'ps-rule.yaml'
    source: '.ps-rule/'
    outputFormat: NUnit3
    outputPath: reports/ps-results.xml
    logLevel: Debug  # 添加调试日志

若日志中出现Loading suppression group from '.ps-rule/LogForAutomation.Rule.yaml',说明规则已被加载,需进一步检查条件匹配逻辑。

5. 验证资源属性匹配逻辑

确认触发告警的自动化账户名称确实包含alz-automation-account,可在扫描结果中查看资源的name和type属性,验证条件是否完全匹配。

总结

最可能的问题是抑制组条件表达式语法错误,修正后即可生效。若问题持续,通过调试日志确认规则加载状态,再逐步排查基线兼容性、资源属性匹配等问题。

内容的提问来源于stack exchange,提问作者Bob

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 15:53:19