-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathSubnetPolicy.bicep
More file actions
77 lines (75 loc) · 2.06 KB
/
Copy pathSubnetPolicy.bicep
File metadata and controls
77 lines (75 loc) · 2.06 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
targetScope = 'managementGroup'
resource policy 'Microsoft.Authorization/policyDefinitions@2021-06-01' = {
name: 'Deny VNET Subnet size'
properties: {
description: 'Deny VNET subnet size specified in parameters. Policy works for VNET creation and added/updated Subnets for existing VNETs'
displayName: 'Deny VNET Subnet size'
mode: 'All'
metadata: {
'category': 'Network'
}
parameters: {
'DeniedSubnetSize': {
'type': 'String'
'defaultValue': '/24'
'metadata': {
'description': 'The denied Subnet size (eg. /24) VNETs'
'displayName': 'Deny Subnet size'
}
}
'effect': {
'type': 'String'
'metadata': {
'displayName': 'Effect'
'description': 'Enable or disable the execution of the policy.'
}
'allowedValues': [
'audit'
'deny'
'disabled'
]
'defaultValue': 'deny'
}
}
policyRule: {
'if': {
'anyof': [
{
'allof': [
{
'field': 'type'
'equals': 'Microsoft.Network/virtualNetworks'
}
{
'count': {
'field': 'Microsoft.Network/virtualNetworks/subnets[*]'
'where': {
'field': 'Microsoft.Network/virtualNetworks/subnets[*].addressPrefix'
'contains': '[parameters(\'DeniedSubnetSize\')]'
}
}
'greater': 0
}
]
}
{
'allof': [
{
'field': 'type'
'equals': 'Microsoft.Network/virtualNetworks/subnets'
}
{
'field': 'Microsoft.Network/virtualNetworks/subnets/addressPrefix'
'contains': '[parameters(\'DeniedSubnetSize\')]'
}
]
}
]
}
'then': {
'effect': '[parameters(\'effect\')]'
}
}
}
}
output policyID string = policy.id