feat(azure): add Deploy-to-Azure Bicep template and certificate auth

This commit is contained in:
Lydia Vilchez committed 2026-08-12 09:48:34 +02:00
1 parent a47d94954a
commit 2eff97c2cc
4 files changed
+8 -12

No files matched your search

@@ -220,7 +220,7 @@ The following security checks require the `ProwlerRole` permissions for executio
## Deploy to Azure (Quick-Start)
Prowler ships a public [Bicep template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/azure/bicep/prowler-scan.bicep) that provisions the App Registration, Service Principal, built-in `Reader` role assignment, and the custom `ProwlerRole` — all bound to an X.509 certificate credential — in a single deployment. This is the Azure analogue of the AWS CloudFormation quick-create flow.
Prowler ships a public [Bicep template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/azure/bicep/prowler-scan.bicep) that provisions the App Registration / Service Principal, the built-in `Reader` role assignment, and the custom `ProwlerRole` — all bound to an X.509 certificate credential — in a single deployment. This is the Azure analogue of the AWS CloudFormation quick-create flow.
Use it from the Prowler Cloud **add-provider wizard**:
@@ -57,7 +57,7 @@ Azure supports two authentication methods in the add-provider wizard. Prowler Cl
#### Certificate Authentication (Recommended)
The one-click flow: click **Deploy to Azure** in the wizard and let the Bicep template create the App Registration, Service Principal, `Reader` role assignment, and custom `ProwlerRole` with a certificate credential in a single deployment.
The one-click flow: click **Deploy to Azure** in the wizard and let the Bicep template create the App Registration / Service Principal, the `Reader` role assignment, and the custom `ProwlerRole` with a certificate credential in a single deployment.
1. In the Azure wizard, select **Certificate Authentication (Recommended)**.
2. Click the **Deploy to Azure** button. This opens the Azure Portal deployment blade pre-loaded with the [Prowler Bicep template](https://github.com/prowler-cloud/prowler/blob/master/permissions/templates/azure/bicep/prowler-scan.bicep).
+2 -6
View File
@@ -1194,9 +1194,7 @@ class AzureProvider(Provider):
# `client_id`). Reaching into `credentials._client_id`
# would be the same class of azure-identity private state
# we deliberately avoided for the thumbprint.
identity.identity_id = getenv(
"AZURE_CLIENT_ID", default=client_id
)
identity.identity_id = getenv("AZURE_CLIENT_ID", default=client_id)
identity.identity_type = "Service Principal with Certificate"
# The SHA-1 thumbprint is computed from the certificate
# bytes by `_compute_certificate_thumbprint` at
@@ -1624,9 +1622,7 @@ class AzureProvider(Provider):
# calling worker (this runs on request threads and Celery tasks
# in the API path). 30s covers the p99 of the token endpoint
# comfortably.
response = requests.post(
url, headers=headers, data=data, timeout=30
).json()
response = requests.post(url, headers=headers, data=data, timeout=30).json()
if (
"access_token" not in response.keys()
and "error_codes" in response.keys()
@@ -75,8 +75,8 @@ export const AzureCertificateCredentialsForm = ({
Certificate Authentication (Recommended)
</div>
<div className="text-text-neutral-tertiary text-sm">
Deploy the Prowler Bicep template to provision the App Registration,
Service Principal, and read-only roles in one click, then paste the
Deploy the Prowler Bicep template to provision the App Registration
/ Service Principal and read-only roles in one click, then paste the
resulting credentials below.
</div>
</div>
@@ -88,8 +88,8 @@ export const AzureCertificateCredentialsForm = ({
</Button>
<p className="text-text-neutral-tertiary text-xs">
After deployment, copy <strong>Tenant ID</strong> and{" "}
<strong>Application (Client) ID</strong> from the deployment outputs —
the certificate private key you generated locally goes in the
<strong>Application ID</strong> from the deployment outputs. The
certificate private key you generated locally goes in the
&ldquo;Certificate Private Key&rdquo; field below.
</p>
</div>