-
Notifications
You must be signed in to change notification settings - Fork 159
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Block TRE access to Terraform/Hashicorp domains #2590
Conversation
/test-extended |
🤖 pr-bot 🤖 🏃 Running extended tests: https://github.com/microsoft/AzureTRE/actions/runs/3042442645 (with refid (in response to this comment from @tamirkamara) |
/test-extended |
🤖 pr-bot 🤖 🏃 Running extended tests: https://github.com/microsoft/AzureTRE/actions/runs/3043310345 (with refid (in response to this comment from @tamirkamara) |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nice. lgtm
/test-extended |
🤖 pr-bot 🤖 🏃 Running extended tests: https://github.com/microsoft/AzureTRE/actions/runs/3047555810 (with refid (in response to this comment from @tamirkamara) |
…)" to be added back in a future release This reverts commit e6b62f4.
Revert "Block TRE access to Terraform/Hashicorp domains (#2590)" to be added back in a future release
Revert "Block TRE access to Terraform/Hashicorp domains (#2590)" to be added back in a future release
Resolves #2445
What is being addressed
With all bundles implementing Terraform provider mirroring it's time to start blocking TRE communication to Terraform/Hasihcorp domains.
Migration
It's advised to upgrade your firewall to the new
0.5.0
version if all your deployed tre resources are at (or above) the versions below.If you have created and deployed custom templates that use Terraform, you need to make sure you mirror providers. Look at the dockerfile.tmpl of one our templates for an example.
The method to do this upgrade is manual - upgrade the templateVersion of
tre-shared-service-firewall
resource in Cosmos to0.5.0