Azure / Enterprise-Scale

The Azure Landing Zones (Enterprise-Scale) architecture provides prescriptive guidance coupled with Azure best practices, and it follows design principles across the critical design areas for organizations to define their Azure architecture
https://aka.ms/alz
MIT License
1.72k stars 980 forks source link

AKS Clusters Not Included in "Enable allLogs Category Group Resource Logging for Supported Resources to Log Analytics" Policy #1838

Open qaiserali opened 1 month ago

qaiserali commented 1 month ago

Community Note

Versions

terraform: 1.7

azure provider: 3.107

module: 6.1.0

Description

We have enabled diagnostic settings for all of our AKS clusters through the policy "Deploy Diagnostic Settings to Azure Services." This policy is now superseded by the built-in initiative Enable allLogs Category Group Resource Logging for Supported Resources to Log Analytics.

While this new policy initiative supports various Azure services, but it does not seem to include AKS clusters, leaving us unable to manage diagnostic settings for AKS through the policy.

Questions:

Any clarification or recommendations would be greatly appreciated.

matt-FFFFFF commented 1 week ago

Hi routing upstream as pertains to policies

gbr759 commented 23 hours ago

It appears as though Microsoft.storage/storageaccounts is also missing from the list of supported resources.