azure_policy_definitions resource
Use the azure_policy_definitions
InSpec audit resource to test the properties and configuration of multiple Azure Policy definitions.
Azure REST API version, endpoint, and HTTP client parameters
This resource interacts with API versions supported by the resource provider.
You can specify the api_version
as a resource parameter to use a specific version of the Azure REST API.
If you don’t specify an API version, this resource uses the latest version available.
For more information about API versioning, see the azure_generic_resource
.
By default, this resource uses the azure_cloud
global endpoint and default HTTP client settings.
You can override these settings if you need to connect to a different Azure environment (such as Azure Government or Azure China).
For more information about configuration options, see the resource pack README.
Syntax
An azure_policy_definitions
resource block returns all policy definitions built-in (if built_in_only: true
) or within a subscription.
describe azure_policy_definitions do
it { should exist }
end
Or
describe azure_policy_definitions(built_in_only: true) do
it { should exist }
end
Parameters
built_in_only
(optional)Indicates whether the interrogated policy definitions are built-in only. Defaults to
false
if not supplied.
Properties
ids
- A list of the unique resource IDs.
Field:
id
names
- A list of names of all the resources being interrogated.
Field:
name
policy_types
- A list of policy types of all the resources.
Field:
policy_type
modes
- A list of modes of all the resources.
Field:
mode
metadata_versions
- A list of metadata versions of the resources.
Field:
metadata_version
metadata_categories
- A list of metadata categories of the resources.
Field:
metadata_category
parameters
- A list of parameters of the resources.
Field:
parameters
policy_rules
- A list of policy rules of the resources.
Field:
policy_rule
properties
- A list of properties for all the resources being interrogated.
Field:
properties
Note
Examples
Check a specific Policy definition is present:
describe azure_policy_definitions do
its('names') { should include 'my-policy' }
end
Filters the results to include only those Policy definitions which include the specified name:
describe azure_policy_definitions.where{ name.include?('my-policy') } do
it { should exist }
end
Filters the results to include only the custom Policy definitions:
describe azure_policy_definitions.where(policy_type: "Custom") do
it { should exist }
its('count') { should be 15 }
end
Matchers
For a full list of available matchers, see our Universal Matchers page.This resource has the following special matchers.
exists
The control passes if the filter returns at least one result. Use should_not
if you expect zero matches.
describe azure_policy_definitions do
it { should exist }
end
Azure permissions
Your Service Principal must be set up with at least a contributor
role on the subscription you wish to test.