Azure Policy Deployments
This examples folder demonstrates an effective deployment of Azure Policy Definitions and Assignments. The order of execution is generally from definitions.tf
-> initiatives.tf
-> assignments_<scope>.tf
Resources
- azurerm_policy_definition.def
- azurerm_policy_set_definition.set
- azurerm_policy_set_definition.cis_benchmark
- azurerm_policy_assignment.def
- azurerm_policy_assignment.set
- azurerm_policy_remediation.rem
- random_uuid.org_mg_remediate_platform_diagnostics_initiative
- random_uuid.org_mg_add_replace_resource_group_tag_key_modify
- data.azurerm_role_definition.security_admin
- azurerm_role_assignment.org_mg_configure_asc_initiative
- azurerm_role_definition.org_mg_remediate_platform_diagnostics_initiative
- azurerm_role_assignment.org_mg_add_replace_resource_group_tag_key_modify
Requirements
Name | Version |
---|---|
terraform | >= 0.13 |
azurerm | ~>2.34 |
Name | Version |
---|---|
terraform | >= 0.13 |
azurerm | ~>2.34 |
Providers
Name | Version |
---|---|
azurerm | ~>2.34 |
random | n/a |
Name | Version |
---|---|
azurerm | ~>2.34 |
random | n/a |
Modules
Resources
Inputs
Name | Description | Type | Default | Required |
---|---|---|---|---|
skip_remediation | Skip creation of all remediation tasks for policies that DeployIfNotExists and Modify | bool | false | no |
Name | Description | Type | Default | Required |
---|---|---|---|---|
skip_remediation | Skip creation of all remediation tasks for policies that DeployIfNotExists and Modify | bool | false | no |
Outputs
No outputoutputs.