如何通过Terraform为存储账户启用Microsoft Defender for Storage恶意软件扫描?
关于用Terraform启用存储账户Defender for Storage上传恶意软件扫描的问题
Terraform支持情况
目前Terraform的AzureRM Provider(版本3.0及以上)已经支持配置存储账户的上传时恶意软件扫描功能,你可以通过azurerm_storage_account资源中的defender块来实现。示例配置代码如下:
resource "azurerm_storage_account" "example" { name = "examplestorageacc" resource_group_name = azurerm_resource_group.example.name location = azurerm_resource_group.example.location account_tier = "Standard" account_replication_type = "GRS" defender { malware_scanning { on_upload_enabled = true # 可选:设置扫描失败时的处理动作,可选值为 Quarantine 或 Audit failure_action = "Quarantine" } } }
注意:请确保你的AzureRM Provider版本满足要求,可以在versions.tf中指定版本约束:
terraform { required_providers { azurerm = { source = "hashicorp/azurerm" version = ">= 3.0.0" } } }
替代程序化实现方式
如果你的Provider版本较低暂时无法升级,或者需要其他程序化手段,可选择以下方式:
1. Azure CLI
使用az storage account update命令完成配置:
az storage account update \ --name <你的存储账户名> \ --resource-group <你的资源组名> \ --enable-defender-malware-scanning-on-upload true \ --defender-malware-scanning-failure-action Quarantine
2. Azure PowerShell
通过Set-AzStorageAccount cmdlet配置:
Set-AzStorageAccount -ResourceGroupName <你的资源组名> -Name <你的存储账户名> ` -EnableDefenderMalwareScanningOnUpload $true ` -DefenderMalwareScanningFailureAction Quarantine
3. Azure REST API
调用存储账户更新接口,在请求体中添加恶意软件扫描配置:
PUT https://management.azure.com/subscriptions/{订阅ID}/resourceGroups/{资源组名}/providers/Microsoft.Storage/storageAccounts/{存储账户名}?api-version=2023-01-01
请求体示例:
{ "properties": { "defender": { "malwareScanning": { "onUploadEnabled": true, "failureAction": "Quarantine" } } } }
内容的提问来源于stack exchange,提问作者O'Neil Tomlinson
相关产品推荐
相关产品推荐

