Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Support for Action of Allow or Deny in ip_restriction of azurerm_app_service #6900

Closed
jjperry69 opened this issue May 13, 2020 · 2 comments · Fixed by #6967
Closed

Support for Action of Allow or Deny in ip_restriction of azurerm_app_service #6900

jjperry69 opened this issue May 13, 2020 · 2 comments · Fixed by #6967

Comments

@jjperry69
Copy link

jjperry69 commented May 13, 2020

Community Note

  • Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
  • Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment

Description

Add optional action setting for "Allow" or "Deny" to the service_config -> ip_restriction block.

The changes made by Pull Request #6705 doesn't permit the ability to set if this is an Allow or Deny rule. When this is applied the rules are always made to be allow, and default deny rule is added. Any exiting rules are deleted.

In the event that some IPs may need to be blocked in the provided IP range / VNET, an ARM template must still be used to setup those deny rules.

New or Affected Resource(s)

  • azurerm_app_service

Potential Terraform Configuration

ip_restriction = [
  {
     ip_address = "1.2.3.0/24" # This exists today
     name = "foo" # This exists today
     priority = 101 # This exists today
  },
  {
     ip_address = "1.2.3.4/32" # This exists today
     name = "bar" # This exists today
     priority = 100 # This exists today
     action = "Deny"
  }
]   

References

@jjperry69 jjperry69 changed the title Support for Allow or Deny in ip_restriction of azurerm_app_service Support for Action of Allow or Deny in ip_restriction of azurerm_app_service May 13, 2020
@katbyte katbyte added this to the v2.11.0 milestone May 20, 2020
katbyte pushed a commit that referenced this issue May 20, 2020
@ghost
Copy link

ghost commented May 22, 2020

This has been released in version 2.11.0 of the provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading. As an example:

provider "azurerm" {
    version = "~> 2.11.0"
}
# ... other configuration ...

@ghost
Copy link

ghost commented Jun 19, 2020

I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues.

If you feel this issue should be reopened, we encourage creating a new issue linking back to this one for added context. If you feel I made an error 🤖 🙉 , please reach out to my human friends 👉 hashibot-feedback@hashicorp.com. Thanks!

@hashicorp hashicorp locked and limited conversation to collaborators Jun 19, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants