如何设置最低Tls版本

时间:2020-08-10 18:57:35

标签: terraform terraform-provider-azure

在通过Terraform创建存储帐户时,如何将tls的最低版本设置为1.2,并将网络连接到Public Endpoint(选定的网络)?

1 个答案:

答案 0 :(得分:1)

HereNSFetchedResultsController的网络规则用法示例。要将最小tls版本设置为1.2,可以使用块azurerm_storage_account。默认情况下,块min_tls_version用于存储帐户的公共端点。您可以选择允许或拒绝某些网络。

enter image description here

network_rules

结果

enter image description here

版本

您可以检查terraform的版本,也可以通过https://www.terraform.io/downloads.html升级到最新的terraform。

enter image description here

提供商

resource "azurerm_resource_group" "example" {
  name     = "example-resources"
  location = "West Europe"
}

resource "azurerm_virtual_network" "example" {
  name                = "virtnetname"
  address_space       = ["10.0.0.0/16"]
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name
}

resource "azurerm_subnet" "example" {
  name                 = "subnetname"
  resource_group_name  = azurerm_resource_group.example.name
  virtual_network_name = azurerm_virtual_network.example.name
  address_prefix       = "10.0.2.0/24"
  service_endpoints    = ["Microsoft.Sql", "Microsoft.Storage"]
}

resource "azurerm_storage_account" "example" {
  name                = "storageaccountname123"
  resource_group_name = azurerm_resource_group.example.name

  location                 = azurerm_resource_group.example.location
  account_tier             = "Standard"
  account_replication_type = "LRS"

  min_tls_version = "TLS1_2"

  network_rules {
    default_action             = "Deny"
    ip_rules                   = ["100.0.0.1"]
    virtual_network_subnet_ids = [azurerm_subnet.example.id]
  }

  tags = {
    environment = "staging"
  }
}