fixes deny subnet without nsg & udr policy #249
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Overview/Summary
This PR fixes the issue that is described here: Azure/Enterprise-Scale#407
Despite of the deny policies Deny-Subnet-Without-Udr & Deny-Subnet-Without-Nsg a vNet with a subnet without udr or nsg can be created in a single ARM deployment. After the deployment the subnets get be marked as non-compliant.
Cross-Reference: Azure/Enterprise-Scale#885
This PR fixes/adds/changes/removes
Breaking Changes
Testing Evidence
After the fix I now getting a deny, when I try to create a vnet with a subnet without udr & nsg.
As part of this Pull Request I have
main
branch/docs/wiki/whats-new.md
)