Private/Get-AACDependencyQuery.ps1
|
function Get-AACDependencyQuery { <# .SYNOPSIS The Azure Resource Graph queries behind Get-AACDependencyGraph: the resources that depend on each other and what links them - compute and its network, load balancers, gateways and Front Door to their backends, apps to their plans, private endpoints to their targets, managed identities to what their roles reach - and what makes each redundant (zones, instances, SKUs). .DESCRIPTION -ResourceGroupName narrows the compute and data queries; role assignments are read tenant-wide (filtered to resource scopes later). #> [CmdletBinding()] [OutputType([System.Collections.Specialized.OrderedDictionary])] param( [string[]] $ResourceGroupName = @() ) $quote = { param([string] $Text) "'" + ($Text -replace "'", "\'") + "'" } $groups = if ($ResourceGroupName.Count) { " | where resourceGroup in~ ($((@($ResourceGroupName | ForEach-Object { & $quote $_ })) -join ', '))" } else { '' } [ordered]@{ vms = "resources | where type =~ 'microsoft.compute/virtualmachines'$groups | project id = tolower(id), name, type = tolower(type), resourceGroup, subscriptionId, zones, avset = tolower(tostring(properties.availabilitySet.id)), osDisk = tolower(tostring(properties.storageProfile.osDisk.managedDisk.id)), dataDisks = properties.storageProfile.dataDisks, identity" nics = "resources | where type =~ 'microsoft.network/networkinterfaces' | project id = tolower(id), vm = tolower(tostring(properties.virtualMachine.id)), ipConfigs = properties.ipConfigurations" vnets = "resources | where type =~ 'microsoft.network/virtualnetworks' | project id = tolower(id), name, type = tolower(type), resourceGroup, subscriptionId, peerings = properties.virtualNetworkPeerings" balancers = "resources | where type in~ ('microsoft.network/loadbalancers', 'microsoft.network/applicationgateways')$groups | project id = tolower(id), name, type = tolower(type), resourceGroup, subscriptionId, zones, capacity = toint(properties.sku.capacity), autoscale = properties.autoscaleConfiguration, pools = properties.backendAddressPools" origins = "resources | where type =~ 'microsoft.cdn/profiles/origingroups/origins' | project id = tolower(id), profile = tolower(tostring(split(id, '/originGroups/')[0])), host = tolower(tostring(properties.hostName))" profiles = "resources | where type =~ 'microsoft.cdn/profiles'$groups | project id = tolower(id), name, type = tolower(type), resourceGroup, subscriptionId" web = "resources | where type =~ 'microsoft.web/sites'$groups | project id = tolower(id), name, type = tolower(type), kind, resourceGroup, subscriptionId, plan = tolower(tostring(properties.serverFarmId)), subnet = tolower(tostring(properties.virtualNetworkSubnetId)), hosts = properties.enabledHostNames, identity" plans = "resources | where type =~ 'microsoft.web/serverfarms'$groups | project id = tolower(id), name, type = tolower(type), resourceGroup, subscriptionId, capacity = toint(sku.capacity), tier = tostring(sku.tier), zoneRedundant = tobool(properties.zoneRedundant)" endpoints = "resources | where type =~ 'microsoft.network/privateendpoints'$groups | project id = tolower(id), name, type = tolower(type), resourceGroup, subscriptionId, subnet = tolower(tostring(properties.subnet.id)), links = array_concat(properties.privateLinkServiceConnections, properties.manualPrivateLinkServiceConnections)" clusters = "resources | where type =~ 'microsoft.containerservice/managedclusters'$groups | project id = tolower(id), name, type = tolower(type), resourceGroup, subscriptionId, pools = properties.agentPoolProfiles, identity, kubelet = tostring(properties.identityProfile.kubeletidentity.objectId)" data = "resources | where type in~ ('microsoft.storage/storageaccounts', 'microsoft.sql/servers', 'microsoft.sql/servers/databases', 'microsoft.documentdb/databaseaccounts', 'microsoft.cache/redis', 'microsoft.keyvault/vaults', 'microsoft.servicebus/namespaces', 'microsoft.eventhub/namespaces', 'microsoft.dbforpostgresql/flexibleservers', 'microsoft.dbformysql/flexibleservers', 'microsoft.containerregistry/registries')$groups | project id = tolower(id), name, type = tolower(type), resourceGroup, subscriptionId, zones, sku = tostring(sku.name), tier = tostring(sku.tier), zoneRedundant = tobool(properties.zoneRedundant), host = tolower(coalesce(tostring(properties.fullyQualifiedDomainName), tostring(properties.hostName), tostring(parse_url(tostring(properties.vaultUri)).Host), tostring(parse_url(tostring(properties.serviceBusEndpoint)).Host), tostring(parse_url(tostring(properties.primaryEndpoints.blob)).Host), tostring(properties.loginServer))), locations = properties.locations, ha = tostring(properties.highAvailability.mode)" identities = "resources | where type =~ 'microsoft.managedidentity/userassignedidentities' | project id = tolower(id), principalId = tostring(properties.principalId)" roles = @{ Tenant = $true; Query = "authorizationresources | where type =~ 'microsoft.authorization/roleassignments' | extend scope = tolower(tostring(properties.scope)) | where scope has '/providers/' and scope !startswith '/providers/microsoft.management' | project id, principalId = tostring(properties.principalId), scope, roleId = tolower(tostring(properties.roleDefinitionId))" } insights = "resources | where type =~ 'microsoft.insights/components'$groups | project id = tolower(id), name, workspace = tolower(tostring(properties.WorkspaceResourceId))" workspaces = "resources | where type =~ 'microsoft.operationalinsights/workspaces' | project id = tolower(id), customerId = tostring(properties.customerId)" } } |