Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[AVM Module Issue]: avm/res/operational-insights/workspace does not support deploy of SQLAuditing solution #3378

Open
1 task done
jikuja opened this issue Sep 29, 2024 · 3 comments
Assignees
Labels
Class: Resource Module 📦 This is a resource module Needs: Triage 🔍 Maintainers need to triage still Status: Response Overdue 🚩 When an issue/PR has not been responded to for X amount of days Type: AVM 🅰️ ✌️ Ⓜ️ This is an AVM related issue Type: Bug 🐛 Something isn't working

Comments

@jikuja
Copy link

jikuja commented Sep 29, 2024

Check for previous/existing GitHub issues

  • I have checked for previous/existing GitHub issues

Issue Type?

Bug

Module Name

avm/res/operations-management/solution

(Optional) Module Version

No response

Description

Following code fails:

module law 'br/public:avm/res/operational-insights/workspace:0.7.0' = {
  name: logAnalyticsWorspaceName
  params: {
    name: logAnalyticsWorspaceName
    enableTelemetry: false
    gallerySolutions: [
      {
        name: 'SQLAuditing'
        product: 'SQLAuditing'
        publisher: 'Microsoft'
      }
    ]
  }
}

Error message:

Solution product name cannot start with 'OMSGallery/' as it is reserved for Microsoft first party solutions. Operation Id: '8aab36af321b604584069fe60e602148' (Code: InvalidParameter, Target: plan.product)

Solution can be added by using solutions resource:

var solutionName = 'SQLAuditing(${logAnalyticsWorspaceName})'
resource solution 'Microsoft.OperationsManagement/solutions@2015-11-01-preview' = {
  name: solutionName
  location: location
  properties: {
    workspaceResourceId: law.outputs.resourceId
  }
  plan: {
    name: solutionName
    promotionCode: ''
    product: 'SQLAuditing'
    publisher: 'Microsoft'
  }
}

For me it looks like SQLAudit solution is not available on OMSGallery namespace,

https://github.com/Azure/bicep-registry-modules/blob/main/avm/res/operations-management/solution/main.bicep#L48:

var solutionProduct = publisher == 'Microsoft' ? 'OMSGallery/${name}' : product

For a reference Portal creates following resource(not the call but resulting stete of the resource) when turning on auditing to LAW on Azure SQL:

{
  "plan": {
    "name": "SQLAuditing[law-law]",
    "publisher": "Microsoft",
    "promotionCode": "",
    "product": "SQLAuditing",
    "version": "1.0"
  },
  "properties": {
    "workspaceResourceId": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RgName/providers/Microsoft.OperationalInsights/workspaces/law-law",
    "provisioningState": "Succeeded",
    "creationTime": "Thu, 26 Sep 2024 14:55:20 GMT",
    "lastModifiedTime": "Thu, 26 Sep 2024 14:55:20 GMT",
    "containedResources": [
      "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RgName/providers/Microsoft.OperationalInsights/workspaces/law-law/views/SQLSecurityInsights",
      "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RgName/providers/Microsoft.OperationalInsights/workspaces/law-law/views/SQLAccessToSensitiveData"
    ],
    "referencedResources": []
  },
  "location": "westeurope",
  "tags": {},
  "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/RgName/providers/Microsoft.OperationsManagement/solutions/SQLAuditing[law-law]",
  "name": "SQLAuditing[law-law]",
  "type": "Microsoft.OperationsManagement/solutions"
}

(Optional) Correlation Id

No response

@jikuja jikuja added Needs: Triage 🔍 Maintainers need to triage still Type: AVM 🅰️ ✌️ Ⓜ️ This is an AVM related issue labels Sep 29, 2024
Copy link

@jikuja, thanks for submitting this issue for the avm/res/operations-management/solution module!

Important

A member of the @Azure/avm-res-operationsmanagement-solution-module-owners-bicep or @Azure/avm-res-operationsmanagement-solution-module-contributors-bicep team will review it soon!

@avm-team-linter avm-team-linter bot added the Class: Resource Module 📦 This is a resource module label Sep 29, 2024

Important

The "Needs: Triage 🔍" label must be removed once the triage process is complete!

Tip

For additional guidance on how to triage this issue/PR, see the BRM Issue Triage documentation.

@microsoft-github-policy-service microsoft-github-policy-service bot added the Type: Bug 🐛 Something isn't working label Sep 29, 2024

Warning

Tagging the AVM Core Team (@Azure/avm-core-team-technical-bicep) due to a module owner or contributor having not responded to this issue within 3 business days. The AVM Core Team will attempt to contact the module owners/contributors directly.

Tip

  • To prevent further actions to take effect, the "Status: Response Overdue 🚩" label must be removed, once this issue has been responded to.
  • To avoid this rule being (re)triggered, the ""Needs: Triage 🔍" label must be removed as part of the triage process (when the issue is first responded to)!

@microsoft-github-policy-service microsoft-github-policy-service bot added the Status: Response Overdue 🚩 When an issue/PR has not been responded to for X amount of days label Oct 3, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Class: Resource Module 📦 This is a resource module Needs: Triage 🔍 Maintainers need to triage still Status: Response Overdue 🚩 When an issue/PR has not been responded to for X amount of days Type: AVM 🅰️ ✌️ Ⓜ️ This is an AVM related issue Type: Bug 🐛 Something isn't working
Projects
Status: Needs: Triage
Development

No branches or pull requests

2 participants