mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-10 05:24:20 +00:00
feat(azure): add Deploy-to-Azure Bicep template and certificate auth
This commit is contained in:
1 parent
a47d94954a
commit
2eff97c2cc
4 files changed
+8
-12
No files matched your search
@@ -220,7 +220,7 @@ The following security checks require the `ProwlerRole` permissions for executio
|
||||
|
||||
## Deploy to Azure (Quick-Start)
|
||||
|
||||
Prowler ships a public [Bicep template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/azure/bicep/prowler-scan.bicep) that provisions the App Registration, Service Principal, built-in `Reader` role assignment, and the custom `ProwlerRole` — all bound to an X.509 certificate credential — in a single deployment. This is the Azure analogue of the AWS CloudFormation quick-create flow.
|
||||
Prowler ships a public [Bicep template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/azure/bicep/prowler-scan.bicep) that provisions the App Registration / Service Principal, the built-in `Reader` role assignment, and the custom `ProwlerRole` — all bound to an X.509 certificate credential — in a single deployment. This is the Azure analogue of the AWS CloudFormation quick-create flow.
|
||||
|
||||
Use it from the Prowler Cloud **add-provider wizard**:
|
||||
|
||||
|
||||
@@ -57,7 +57,7 @@ Azure supports two authentication methods in the add-provider wizard. Prowler Cl
|
||||
|
||||
#### Certificate Authentication (Recommended)
|
||||
|
||||
The one-click flow: click **Deploy to Azure** in the wizard and let the Bicep template create the App Registration, Service Principal, `Reader` role assignment, and custom `ProwlerRole` with a certificate credential in a single deployment.
|
||||
The one-click flow: click **Deploy to Azure** in the wizard and let the Bicep template create the App Registration / Service Principal, the `Reader` role assignment, and the custom `ProwlerRole` with a certificate credential in a single deployment.
|
||||
|
||||
1. In the Azure wizard, select **Certificate Authentication (Recommended)**.
|
||||
2. Click the **Deploy to Azure** button. This opens the Azure Portal deployment blade pre-loaded with the [Prowler Bicep template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/azure/bicep/prowler-scan.bicep).
|
||||
|
||||
@@ -1194,9 +1194,7 @@ class AzureProvider(Provider):
|
||||
# `client_id`). Reaching into `credentials._client_id`
|
||||
# would be the same class of azure-identity private state
|
||||
# we deliberately avoided for the thumbprint.
|
||||
identity.identity_id = getenv(
|
||||
"AZURE_CLIENT_ID", default=client_id
|
||||
)
|
||||
identity.identity_id = getenv("AZURE_CLIENT_ID", default=client_id)
|
||||
identity.identity_type = "Service Principal with Certificate"
|
||||
# The SHA-1 thumbprint is computed from the certificate
|
||||
# bytes by `_compute_certificate_thumbprint` at
|
||||
@@ -1624,9 +1622,7 @@ class AzureProvider(Provider):
|
||||
# calling worker (this runs on request threads and Celery tasks
|
||||
# in the API path). 30s covers the p99 of the token endpoint
|
||||
# comfortably.
|
||||
response = requests.post(
|
||||
url, headers=headers, data=data, timeout=30
|
||||
).json()
|
||||
response = requests.post(url, headers=headers, data=data, timeout=30).json()
|
||||
if (
|
||||
"access_token" not in response.keys()
|
||||
and "error_codes" in response.keys()
|
||||
|
||||
+4
-4
@@ -75,8 +75,8 @@ export const AzureCertificateCredentialsForm = ({
|
||||
Certificate Authentication (Recommended)
|
||||
</div>
|
||||
<div className="text-text-neutral-tertiary text-sm">
|
||||
Deploy the Prowler Bicep template to provision the App Registration,
|
||||
Service Principal, and read-only roles in one click, then paste the
|
||||
Deploy the Prowler Bicep template to provision the App Registration
|
||||
/ Service Principal and read-only roles in one click, then paste the
|
||||
resulting credentials below.
|
||||
</div>
|
||||
</div>
|
||||
@@ -88,8 +88,8 @@ export const AzureCertificateCredentialsForm = ({
|
||||
</Button>
|
||||
<p className="text-text-neutral-tertiary text-xs">
|
||||
After deployment, copy <strong>Tenant ID</strong> and{" "}
|
||||
<strong>Application (Client) ID</strong> from the deployment outputs —
|
||||
the certificate private key you generated locally goes in the
|
||||
<strong>Application ID</strong> from the deployment outputs. The
|
||||
certificate private key you generated locally goes in the
|
||||
“Certificate Private Key” field below.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
Reference in new issue
Block a user