Ensure Virtual Machine extensions are not installed

Error: Virtual Machine extensions are installed

Bridgecrew Policy ID: BC_AZR_GENERAL_14
Checkov Check ID: CKV_AZURE_50
Severity: MEDIUM

Virtual Machine extensions are installed

Description

Azure virtual machine extensions run with administrative privileges and as such can access anything on a virtual machine.

Fix - Buildtime

Terraform

  • Resource: azurerm_virtual_machine, azurerm_linux_virtual_machine
  • Argument: allow_extension_operations
resource "azurerm_linux_virtual_machine" "example" {
    ...
 ~  allow_extension_operations=false
  }

Did this page help you?