Skip to content

ContainerService - ManagedClusters #493

ContainerService - ManagedClusters

ContainerService - ManagedClusters #493

Manually triggered November 17, 2023 19:48
Status Failure
Total duration 2m 31s
Artifacts
This run and associated checks have been archived and are scheduled for deletion. Learn more about checks retention
Initialize pipeline
13s
Initialize pipeline
Module  /  Static validation
1m 54s
Module / Static validation
Matrix: Module / PSRule validation
Matrix: Module / Deployment validation
Module  /  Publishing
0s
Module / Publishing
Fit to window
Zoom out
Zoom in

Annotations

49 errors and 11 warnings
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000408: 864e505983a1f-test-csmpriv failed Azure.Deployment.SecureParameter. Use secure parameters for any parameter that contains sensitive information.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000015: ***csmpriv001 failed Azure.AKS.Version. AKS control plane and nodes pools should use a current stable release.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000016: ***csmpriv001 failed Azure.AKS.PoolVersion. AKS node pools should match Kubernetes control plane version.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000018: ***csmpriv001 failed Azure.AKS.NodeMinPods. Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000022: ***csmpriv001 failed Azure.AKS.AuditLogs. AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000023: ***csmpriv001 failed Azure.AKS.PlatformLogs. AKS clusters should collect platform diagnostic logs to monitor the state of workloads.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000024: ***csmpriv001 failed Azure.AKS.MinNodeCount. AKS clusters should have minimum number of nodes for failover and updates.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000027: ***csmpriv001 failed Azure.AKS.NetworkPolicy. Deploy AKS clusters with Network Policies enabled.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000030: ***csmpriv001 failed Azure.AKS.AuthorizedIPs. Restrict access to API server endpoints to authorized IP addresses.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000031: ***csmpriv001 failed Azure.AKS.LocalAccounts. Enforce named user accounts with RBAC assigned permissions.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000408: 864e505983a1f-test-csmmin failed Azure.Deployment.SecureParameter. Use secure parameters for any parameter that contains sensitive information.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000015: ***csmmin001 failed Azure.AKS.Version. AKS control plane and nodes pools should use a current stable release.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000017: ***csmmin001 failed Azure.AKS.PoolScaleSet. Deploy AKS clusters with nodes pools based on VM scale sets.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000018: ***csmmin001 failed Azure.AKS.NodeMinPods. Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000022: ***csmmin001 failed Azure.AKS.AuditLogs. AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000023: ***csmmin001 failed Azure.AKS.PlatformLogs. AKS clusters should collect platform diagnostic logs to monitor the state of workloads.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000285: ***csmmin001 failed Azure.AKS.UptimeSLA. AKS clusters should have Uptime SLA enabled for a financially backed SLA.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000024: ***csmmin001 failed Azure.AKS.MinNodeCount. AKS clusters should have minimum number of nodes for failover and updates.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000027: ***csmmin001 failed Azure.AKS.NetworkPolicy. Deploy AKS clusters with Network Policies enabled.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
AZR-000030: ***csmmin001 failed Azure.AKS.AuthorizedIPs. Restrict access to API server endpoints to authorized IP addresses.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000408: 864e505983a1f-test-csmkube failed Azure.Deployment.SecureParameter. Use secure parameters for any parameter that contains sensitive information.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000015: ***csmkube001 failed Azure.AKS.Version. AKS control plane and nodes pools should use a current stable release.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000016: ***csmkube001 failed Azure.AKS.PoolVersion. AKS node pools should match Kubernetes control plane version.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000018: ***csmkube001 failed Azure.AKS.NodeMinPods. Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000022: ***csmkube001 failed Azure.AKS.AuditLogs. AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000023: ***csmkube001 failed Azure.AKS.PlatformLogs. AKS clusters should collect platform diagnostic logs to monitor the state of workloads.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000285: ***csmkube001 failed Azure.AKS.UptimeSLA. AKS clusters should have Uptime SLA enabled for a financially backed SLA.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000024: ***csmkube001 failed Azure.AKS.MinNodeCount. AKS clusters should have minimum number of nodes for failover and updates.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000027: ***csmkube001 failed Azure.AKS.NetworkPolicy. Deploy AKS clusters with Network Policies enabled.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000030: ***csmkube001 failed Azure.AKS.AuthorizedIPs. Restrict access to API server endpoints to authorized IP addresses.
Module / Static validation
[-] In [container-service/managed-cluster] used resource type [locks] should use one of the recent API version(s). Currently using [2020-05-01]. 6ms (5ms|2ms)
Module / Static validation
[-] In [container-service/managed-cluster] used resource type [roleAssignments] should use one of the recent API version(s). Currently using [2022-04-01]. 3ms (2ms|1ms)
Module / Static validation
[-] In [container-service/managed-cluster] used resource type [managedClusters] should use one of the recent API version(s). Currently using [2023-07-02-preview]. 3ms (3ms|1ms)
Module / Static validation
[-] In [container-service/managed-cluster] used resource type [managedClusters/agentPools] should use one of the recent API version(s). Currently using [2023-07-02-preview]. 3ms (3ms|1ms)
Module / Static validation
[-] In [container-service/managed-cluster] used resource type [diagnosticSettings] should use one of the recent API version(s). Currently using [2021-05-01-preview]. 33ms (32ms|1ms)
Module / Static validation
[-] In [container-service/managed-cluster] used resource type [extensions] should use one of the recent API version(s). Currently using [2022-03-01]. 3ms (2ms|1ms)
Module / Static validation
[-] In [container-service/managed-cluster] used resource type [fluxConfigurations] should use one of the recent API version(s). Currently using [2022-03-01]. 2ms (2ms|1ms)
Module / Static validation
[-] In [container-service/managed-cluster/agent-pool] used resource type [managedClusters/agentPools] should use one of the recent API version(s). Currently using [2023-07-02-preview]. 2ms (2ms|0ms)
Module / Static validation
Process completed with exit code 1.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000408: 864e505983a1f-test-csmaz failed Azure.Deployment.SecureParameter. Use secure parameters for any parameter that contains sensitive information.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000016: ***csmaz001 failed Azure.AKS.PoolVersion. AKS node pools should match Kubernetes control plane version.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000018: ***csmaz001 failed Azure.AKS.NodeMinPods. Azure Kubernetes Cluster (AKS) nodes should use a minimum number of pods.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000022: ***csmaz001 failed Azure.AKS.AuditLogs. AKS clusters should collect security-based audit logs to assess and monitor the compliance status of workloads.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000023: ***csmaz001 failed Azure.AKS.PlatformLogs. AKS clusters should collect platform diagnostic logs to monitor the state of workloads.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000285: ***csmaz001 failed Azure.AKS.UptimeSLA. AKS clusters should have Uptime SLA enabled for a financially backed SLA.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000024: ***csmaz001 failed Azure.AKS.MinNodeCount. AKS clusters should have minimum number of nodes for failover and updates.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000027: ***csmaz001 failed Azure.AKS.NetworkPolicy. Deploy AKS clusters with Network Policies enabled.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000030: ***csmaz001 failed Azure.AKS.AuthorizedIPs. Restrict access to API server endpoints to authorized IP addresses.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000031: ***csmaz001 failed Azure.AKS.LocalAccounts. Enforce named user accounts with RBAC assigned permissions.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
The option 'Execution.SuppressedRuleWarning' is deprecated and will be removed with PSRule v3. See http://aka.ms/ps-rule/deprecations for more detail.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
The option 'Execution.NotProcessedWarning' is deprecated and will be removed with PSRule v3. See http://aka.ms/ps-rule/deprecations for more detail.
Module / PSRule validation (tests/e2e/priv/main.test.bicep)
AZR-000287: ***csmpriv001 failed Azure.AKS.EphemeralOSDisk. AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
The option 'Execution.SuppressedRuleWarning' is deprecated and will be removed with PSRule v3. See http://aka.ms/ps-rule/deprecations for more detail.
Module / PSRule validation (tests/e2e/defaults/main.test.bicep)
The option 'Execution.NotProcessedWarning' is deprecated and will be removed with PSRule v3. See http://aka.ms/ps-rule/deprecations for more detail.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
The option 'Execution.SuppressedRuleWarning' is deprecated and will be removed with PSRule v3. See http://aka.ms/ps-rule/deprecations for more detail.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
The option 'Execution.NotProcessedWarning' is deprecated and will be removed with PSRule v3. See http://aka.ms/ps-rule/deprecations for more detail.
Module / PSRule validation (tests/e2e/kubenet/main.test.bicep)
AZR-000287: ***csmkube001 failed Azure.AKS.EphemeralOSDisk. AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
The option 'Execution.SuppressedRuleWarning' is deprecated and will be removed with PSRule v3. See http://aka.ms/ps-rule/deprecations for more detail.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
The option 'Execution.NotProcessedWarning' is deprecated and will be removed with PSRule v3. See http://aka.ms/ps-rule/deprecations for more detail.
Module / PSRule validation (tests/e2e/azure/main.test.bicep)
AZR-000287: ***csmaz001 failed Azure.AKS.EphemeralOSDisk. AKS clusters should use ephemeral OS disks which can provide lower read/write latency, along with faster node scaling and cluster upgrades.