Azure Pipeline中PSRule忽略.ps-rule/目录本地规则问题
PSRule忽略自定义抑制组规则的排查与解决
问题场景
基于ALZ-Bicep构建的项目中,Azure Pipeline执行PSRule扫描时,.ps-rule/LogForAutomation.Rule.yaml中定义的抑制组规则未生效,PSRule依然触发了Azure.Automation.AuditLogs和Azure.Automation.PlatformLogs规则的告警。相关配置如下:
Pipeline配置
trigger: - none pool: vmImage: ubuntu-latest stages: - stage: PSrule jobs: - job: PSrule displayName: PSrule best practice validation steps: # Install PSRule.Rules.Azure from the PowerShell Gallery - task: ps-rule-install@2 inputs: module: PSRule.Rules.Azure # Install PSRule.Rules.Azure from the PowerShell Gallery. # Run analysis from JSON files using the `PSRule.Rules.Azure` module and custom rules from `.ps-rule/`. - task: ps-rule-assert@2 continueOnError: true inputs: inputType: repository modules: 'PSRule.Rules.Azure' # Analyze objects using the rules within the PSRule.Rules.Azure PowerShell module. baseline: 'Azure.GA_2023_09' option: 'ps-rule.yaml' # Use the rules defined in 'ps-rule.yaml'. source: '.ps-rule/' # Additionally, analyze object using custom rules from '.ps-rule/'. outputFormat: NUnit3 # Save results to an NUnit report. outputPath: reports/ps-results.xml # Write NUnit report to 'reports/ps-rule-results.xml'.
ps-rule.yaml配置
# # PSRule for Azure configuration # # Use rules from the following modules/ include: module: - 'PSRule.Rules.Azure' # Require a minimum version of modules that include referenced baseline. requires: PSRule: '@pre >=2.3.2' PSRule.Rules.Azure: '@pre >=1.18.1' # Reference the repository in output. repository: url: xxxxxxxxx execution: # Ignore warnings for resources and objects that don't have any rules. notProcessedWarning: false configuration: # Enable expansion for Bicep source files. AZURE_BICEP_FILE_EXPANSION: false # Expand Bicep module from Azure parameter files. AZURE_PARAMETER_FILE_EXPANSION: true # Set timeout for expanding Bicep source files. AZURE_BICEP_FILE_EXPANSION_TIMEOUT: 15 input: pathIgnore: # Ignore common files that don't need analysis. - '**/bicepconfig.json' - '.github/' # Exclude samples/ test files from modules - 'infra-as-code/bicep/**/samples/*.bicep' binding: preferTargetInfo: true targetType: - resourceType - type rule: includeLocal: true exclude: # Ignore these recommendations for this repo. - Azure.Resource.UseTags - Azure.ACR.MinSku - Azure.ACR.ContentTrust - Azure.Policy.AssignmentAssignedBy # Currently a bug as of v1.15.2. Review in the next release. - Azure.PublicIP.Name
自定义抑制组规则(.ps-rule/LogForAutomation.Rule.yaml)
# Synopsis: Ignore automation account audit diagnostic logs are enabled as these are covered by DINE policies in ALZ apiVersion: github.com/microsoft/PSRule/v1 kind: SuppressionGroup metadata: name: ALZ.DiagLogForAutomation spec: rule: - Azure.Automation.AuditLogs - Azure.Automation.PlatformLogs if: allOf: - name: '.' contains: alz-automation-account - type: '.' in: - Microsoft.Automation/automationAccounts
排查与解决方案
1. 修正抑制组条件表达式语法
当前抑制组的条件写法不符合PSRule语法规范,正确写法需要用field字段指定匹配的属性:
if: allOf: - field: name contains: alz-automation-account - field: type in: - Microsoft.Automation/automationAccounts
2. 确认规则文件加载有效性
- 确保
.ps-rule/目录下的规则文件命名符合PSRule要求:必须以.Rule.yaml或.Rule.json结尾(当前文件命名符合要求) - PSRule会递归扫描
source指定目录下的规则文件,无需额外配置路径
3. 验证基线与自定义规则的兼容性
使用Azure.GA_2023_09基线时,可能存在基线覆盖自定义规则的情况。可以临时移除baseline配置,测试抑制组是否生效:若生效,需调整基线与自定义规则的优先级,或在基线中引入自定义抑制组。
4. 启用调试日志确认规则加载状态
在ps-rule-assert@2任务中添加logLevel: Debug参数,查看日志是否包含加载自定义抑制组的条目:
- task: ps-rule-assert@2 continueOnError: true inputs: inputType: repository modules: 'PSRule.Rules.Azure' baseline: 'Azure.GA_2023_09' option: 'ps-rule.yaml' source: '.ps-rule/' outputFormat: NUnit3 outputPath: reports/ps-results.xml logLevel: Debug # 添加调试日志
若日志中出现Loading suppression group from '.ps-rule/LogForAutomation.Rule.yaml',说明规则已被加载,需进一步检查条件匹配逻辑。
5. 验证资源属性匹配逻辑
确认触发告警的自动化账户名称确实包含alz-automation-account,可在扫描结果中查看资源的name和type属性,验证条件是否完全匹配。
总结
最可能的问题是抑制组条件表达式语法错误,修正后即可生效。若问题持续,通过调试日志确认规则加载状态,再逐步排查基线兼容性、资源属性匹配等问题。
内容的提问来源于stack exchange,提问作者Bob
相关产品推荐
相关产品推荐

