Control: Kubernetes cluster addon Azure policy should be enabled
Description
Ensure that Kubernetes cluster uses Azure Policies Add-on.
Usage
Run the control in your terminal:
powerpipe control run azure_compliance.control.kubernetes_cluster_addon_azure_policy_enabled
Snapshot and share results via Turbot Pipes:
powerpipe loginpowerpipe control run azure_compliance.control.kubernetes_cluster_addon_azure_policy_enabled --share
SQL
This control uses a named query:
select c.id as resource, case when addon_profiles -> 'azurepolicy' ->> 'enabled' = 'true' then 'ok' else 'alarm' end as status, case when addon_profiles -> 'azurepolicy' ->> 'enabled' = 'true' then c.name || ' addon azure policy enabled .' else c.name || ' addon azure policy disabled .' end as reason , c.resource_group as resource_group , sub.display_name as subscriptionfrom azure_kubernetes_cluster c, azure_subscription subwhere sub.subscription_id = c.subscription_id;