azure.disk

Disk Resource

example:

This policy will find all data disks that are not being managed by a VM.

policies:
  - name: orphaned-disk
    resource: azure.disk
    filters:
      - type: value
        key: managedBy
        value: null

Filters

advisor-recommendation

Filter resources by Azure Advisor Recommendations

Select all categories with ‘all’

example:

policies:
  - name: disks-with-cost-recommendations
    resource: azure.disk
    filters:
      - type: advisor-recommendation
        category: Cost
        key: '[].properties.recommendationTypeId'
        op: contains
        value: '48eda464-1485-4dcf-a674-d0905df5054a'
properties:
  category:
    type: string
  default:
    type: object
  key:
    type: string
  op:
    enum:
    - eq
    - equal
    - ne
    - not-equal
    - gt
    - greater-than
    - ge
    - gte
    - le
    - lte
    - lt
    - less-than
    - glob
    - regex
    - regex-case
    - in
    - ni
    - not-in
    - contains
    - difference
    - intersect
    - mod
  tag_key_transforms:
    items:
      type: string
    type: array
  type:
    enum:
    - advisor-recommendation
  value:
    oneOf:
    - type: array
    - type: string
    - type: boolean
    - type: number
    - type: 'null'
  value_from:
    additionalProperties: 'False'
    properties:
      expr:
        oneOf:
        - type: integer
        - type: string
      format:
        enum:
        - csv
        - json
        - txt
        - csv2dict
      headers:
        patternProperties:
          ? ''
          : type: string
        type: object
      query:
        type: string
      url:
        type: string
    required:
    - url
    type: object
  value_path:
    type: string
  value_regex:
    type: string
  value_type:
    enum:
    - age
    - integer
    - expiration
    - normalize
    - size
    - cidr
    - cidr_size
    - swap
    - resource_count
    - expr
    - unique_size
    - date
    - version
    - float
required:
- category
- type

Actions

snapshot

Create a snapshot of each disk.

Snapshots go in the disk’s resource group and are named <disk name>-<YYYYMMDDhhmmss> (UTC). Names over Azure’s 80-character limit are shortened, with a hash of the disk ID added to keep them unique.

incremental (default true) stores only the changes since the disk’s previous snapshot. Set it to false for a full copy. Azure supports only incremental snapshots of Ultra Disks and Premium SSD v2 disks, and finishes copying them after the action returns.

Azure gives the snapshot the disk’s encryption settings, including a customer-managed key. The snapshot gets the disk’s tags, except the custodian_status tag from mark-for-op, plus a custodian_snapshot tag set to the policy name. A snapshot isn’t taken if that comes to more than Azure’s limit of 50 tags.

If a snapshot fails, snapshots of the remaining disks are still taken, then the action raises so later actions in the policy don’t run.

Needs at least Microsoft.Compute/disks/read, Microsoft.Compute/snapshots/write and Microsoft.Compute/snapshots/read.

example:

Take a snapshot of every disk tagged backup: daily:

policies:
  - name: azure-disk-snapshot-daily
    resource: azure.disk
    filters:
      - "tag:backup": daily
    actions:
      - type: snapshot
properties:
  incremental:
    type: boolean
  type:
    enum:
    - snapshot
required:
- type