azure.disk
Disk Resource
- example:
This policy will find all data disks that are not being managed by a VM.
policies:
- name: orphaned-disk
resource: azure.disk
filters:
- type: value
key: managedBy
value: null
Filters
advisor-recommendation
Filter resources by Azure Advisor Recommendations
Select all categories with ‘all’
- example:
policies:
- name: disks-with-cost-recommendations
resource: azure.disk
filters:
- type: advisor-recommendation
category: Cost
key: '[].properties.recommendationTypeId'
op: contains
value: '48eda464-1485-4dcf-a674-d0905df5054a'
properties:
category:
type: string
default:
type: object
key:
type: string
op:
enum:
- eq
- equal
- ne
- not-equal
- gt
- greater-than
- ge
- gte
- le
- lte
- lt
- less-than
- glob
- regex
- regex-case
- in
- ni
- not-in
- contains
- difference
- intersect
- mod
tag_key_transforms:
items:
type: string
type: array
type:
enum:
- advisor-recommendation
value:
oneOf:
- type: array
- type: string
- type: boolean
- type: number
- type: 'null'
value_from:
additionalProperties: 'False'
properties:
expr:
oneOf:
- type: integer
- type: string
format:
enum:
- csv
- json
- txt
- csv2dict
headers:
patternProperties:
? ''
: type: string
type: object
query:
type: string
url:
type: string
required:
- url
type: object
value_path:
type: string
value_regex:
type: string
value_type:
enum:
- age
- integer
- expiration
- normalize
- size
- cidr
- cidr_size
- swap
- resource_count
- expr
- unique_size
- date
- version
- float
required:
- category
- type
Actions
snapshot
Create a snapshot of each disk.
Snapshots go in the disk’s resource group and are named
<disk name>-<YYYYMMDDhhmmss> (UTC). Names over Azure’s 80-character limit are
shortened, with a hash of the disk ID added to keep them unique.
incremental (default true) stores only the changes since the disk’s previous
snapshot. Set it to false for a full copy. Azure supports only incremental
snapshots of Ultra Disks and Premium SSD v2 disks, and finishes copying them after
the action returns.
Azure gives the snapshot the disk’s encryption settings, including a customer-managed
key. The snapshot gets the disk’s tags, except the custodian_status tag from
mark-for-op, plus a custodian_snapshot tag set to the policy name. A snapshot
isn’t taken if that comes to more than Azure’s limit of 50 tags.
If a snapshot fails, snapshots of the remaining disks are still taken, then the action raises so later actions in the policy don’t run.
Needs at least Microsoft.Compute/disks/read, Microsoft.Compute/snapshots/write
and Microsoft.Compute/snapshots/read.
- example:
Take a snapshot of every disk tagged backup: daily:
policies:
- name: azure-disk-snapshot-daily
resource: azure.disk
filters:
- "tag:backup": daily
actions:
- type: snapshot
properties:
incremental:
type: boolean
type:
enum:
- snapshot
required:
- type