Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Overview/Summary
This pull request introduces metadata descriptions and design recommendations for various parameters in the
eslzArm.json
file, improving documentation and clarity on governance and security policies.Governance Enhancements:
enableDecommissioned
,enableSandbox
,enableSqlAudit
,enableStorageHttps
, andenforceKvGuardrails
parameters to specify the impact of enabling these policies. [1] [2] [3] [4]Security Improvements:
enforceBackup
,enforceKvGuardrailsPlat
,enforceBackupPlat
,enforceAcsb
, andenforceWsCMKInitiatives
parameters to detail the security measures and recommendations. [1] [2] [3] [4] [5]Networking Policies:
denyHybridNetworking
,auditPeDnsZones
, andauditAppGwWaf
parameters to outline the networking policies and their enforcement. [1] [2] [3]Workload Specific Compliance:
wsAPIMSelectorMG
,wsAppServicesSelectorMG
,wsAutomationSelectorMG
,wsBotServiceSelectorMG
,wsCognitiveServicesSelectorMG
,wsComputeSelectorMG
,wsContainerAppsSelectorMG
, andwsContainerInstanceSelectorMG
parameters to enforce best practices for specific workloads. [1] [2] [3] [4] [5] [6] [7] [8]Configuration Clarifications:
delayCount
andcurrentDateTimeUtcNow
parameters to indicate they are managed by the ALZ team and not user-configurable. [1] [2]