manifests/collectors/Security/Vault.psd1
|
# # GENERATED by scripts/ConvertTo-ScoutCollectorDefinition.ps1 from Modules/Public/InventoryModules/Security/Vault.ps1 (AB#5660). # Field expressions are copied verbatim from the original collector and evaluate in an # equivalent scope -- see docs/design/decisions/declarative-collectors.md. # Review before trusting; regenerate rather than hand-patch if the source collector changes. # @{ ResourceTypes = @( 'microsoft.keyvault/vaults' ) ResourceTypeMatching = 'Grouped' AdditionalFilter = $null FilterPreamble = '' RowLoopVariable = '1' Preamble = @' $ResUCount = 1 # An EMPTY $sub1 is not $null -- the match is empty for any resource whose subscription # is outside the requested scope -- and reading .Name off an empty collection throws # under StrictMode (AB#5671). Resolved once here, as VirtualMachine.ps1 already does. $sub1 = $SUB | Where-Object { $_.id -eq $1.subscriptionId } # The else arm is $null, NOT '': with StrictMode off $sub1.Name on an unmatched ($null) # $sub1 evaluated to $null, and the ~110 collectors that still read $sub1.Name directly # emit $null here. '' was a silent behaviour change -- the declarative equivalence proof # caught it on 11 collectors, and it would have been invisible on the rest (AB#5659). $SubscriptionName = if ($sub1) { @($sub1)[0].Name } else { $null } $data = $1.PROPERTIES $Retired = $Retirements | Where-Object { $_.id -eq $1.id } if ($Retired) { $RetiredFeature = foreach ($Retire in $Retired) { $RetiredServiceID = $Unsupported | Where-Object {$_.Id -eq $Retired.ServiceID} $tmp0 = [pscustomobject]@{ 'RetiredFeature' = $RetiredServiceID.RetiringFeature 'RetiredDate' = $RetiredServiceID.RetirementDate } $tmp0 } $RetiringFeature = if (@($RetiredFeature.RetiredFeature).count -gt 1) { $RetiredFeature.RetiredFeature | ForEach-Object { $_ + ' ,' } }else { $RetiredFeature.RetiredFeature} $RetiringFeature = [string]$RetiringFeature $RetiringFeature = if ($RetiringFeature -like '* ,*') { $RetiringFeature -replace ".$" }else { $RetiringFeature } $RetiringDate = if (@($RetiredFeature.RetiredDate).count -gt 1) { $RetiredFeature.RetiredDate | ForEach-Object { $_ + ' ,' } }else { $RetiredFeature.RetiredDate} $RetiringDate = [string]$RetiringDate $RetiringDate = if ($RetiringDate -like '* ,*') { $RetiringDate -replace ".$" }else { $RetiringDate } } else { $RetiringFeature = $null $RetiringDate = $null } # `enableSoftDelete` and `enableRbacAuthorization` are both absent (not null) on an # older vault that has never had either set. Both arms are read through the accessor, # not just the guard: the else arm only runs when the property exists, so it happens # not to throw today, but leaving one raw read behind means the next person has to # work out which of the two spellings was deliberate (AB#5671). $EnableSoftDelete = Get-AZSCSafeProperty -InputObject $data -Path 'enableSoftDelete' $EnableRbac = Get-AZSCSafeProperty -InputObject $data -Path 'enableRbacAuthorization' if([string]::IsNullOrEmpty($EnableSoftDelete)){$Soft = $false}else{$Soft = $EnableSoftDelete} if([string]::IsNullOrEmpty($EnableRbac)){$RBAC = $false}else{$RBAC = $EnableRbac} # AB#5671: an untagged resource's Resource Graph row OMITS the tags property rather # than carrying an empty object, so the raw read throws under StrictMode -- and so # does psobject.properties on a $null. The historic '0' sentinel existed only to make # the tag loop below run ONCE for an untagged resource, but '0'.Name throws too; an # empty tag object runs it once AND emits the identical [string]-cast empty Name/Value. $RowTags = Get-AZSCSafeProperty -InputObject $1 -Path 'tags' $TagProps = if ($null -ne $RowTags) { $RowTags.psobject.properties } else { $null } $Tags = if (![string]::IsNullOrEmpty($TagProps)) { $TagProps } else { [pscustomobject]@{ Name = $null; Value = $null } } $AccessPol = if(![string]::IsNullOrEmpty((Get-AZSCSafeProperty -InputObject $data -Path 'accessPolicies' -Enumerate))){(Get-AZSCSafeProperty -InputObject $data -Path 'accessPolicies' -Enumerate)}else{'0'} '@ AdditionalRowLoops = @( @{ Variable = '2' Source = '$AccessPol' Preamble = @' $Secrets = if (@((Get-AZSCSafeProperty -InputObject $2 -Path 'permissions.secrets' -Enumerate)).count -gt 1) { (Get-AZSCSafeProperty -InputObject $2 -Path 'permissions.secrets' -Enumerate) | ForEach-Object { $_ + ' ,' } }else { (Get-AZSCSafeProperty -InputObject $2 -Path 'permissions.secrets' -Enumerate) } $Secrets = [string]$Secrets $Secrets = if ($Secrets -like '* ,*') { $Secrets -replace ".$" }else { $Secrets } $Keys = if (@((Get-AZSCSafeProperty -InputObject $2 -Path 'permissions.keys' -Enumerate)).count -gt 1) { (Get-AZSCSafeProperty -InputObject $2 -Path 'permissions.keys' -Enumerate) | ForEach-Object { $_ + ' ,' } }else { (Get-AZSCSafeProperty -InputObject $2 -Path 'permissions.keys' -Enumerate) } $Keys = [string]$Keys $Keys = if ($Keys -like '* ,*') { $Keys -replace ".$" }else { $Keys } $Certs = if (@((Get-AZSCSafeProperty -InputObject $2 -Path 'permissions.certificates' -Enumerate)).count -gt 1) { (Get-AZSCSafeProperty -InputObject $2 -Path 'permissions.certificates' -Enumerate) | ForEach-Object { $_ + ' ,' } }else { (Get-AZSCSafeProperty -InputObject $2 -Path 'permissions.certificates' -Enumerate) } $Certs = [string]$Certs $Certs = if ($Certs -like '* ,*') { $Certs -replace ".$" }else { $Certs } '@ } ) TagLoop = @{ Variable = 'Tag' Source = '$Tags' Preamble = '' } Fields = @( @{ Name = 'ID' Expression = '$1.id' } @{ Name = 'Subscription' Expression = '$SubscriptionName' } @{ Name = 'Resource Group' Expression = '$1.RESOURCEGROUP' } @{ Name = 'Name' Expression = '$1.NAME' } @{ Name = 'Location' Expression = '$1.LOCATION' } @{ Name = 'Retiring Feature' Expression = '$RetiringFeature' } @{ Name = 'Retiring Date' Expression = '$RetiringDate' } @{ Name = 'SKU Family' Expression = '(Get-AZSCSafeProperty -InputObject $data -Path ''sku.family'' -Enumerate)' } @{ Name = 'SKU' Expression = '(Get-AZSCSafeProperty -InputObject $data -Path ''sku.name'' -Enumerate)' } @{ Name = 'Vault Uri' Expression = '(Get-AZSCSafeProperty -InputObject $data -Path ''vaultUri'' -Enumerate)' } @{ Name = 'Public Network Access' Expression = '(Get-AZSCSafeProperty -InputObject $data -Path ''publicnetworkaccess'' -Enumerate)' } @{ Name = 'Enable RBAC' Expression = '$RBAC' } @{ Name = 'Enable Soft Delete' Expression = '$Soft' } @{ Name = 'Enable for Disk Encryption' Expression = '(Get-AZSCSafeProperty -InputObject $data -Path ''enabledForDiskEncryption'' -Enumerate)' } @{ Name = 'Soft Delete Retention Days' Expression = '(Get-AZSCSafeProperty -InputObject $data -Path ''softDeleteRetentionInDays'' -Enumerate)' } @{ Name = 'Access Policy ObjectID' Expression = '(Get-AZSCSafeProperty -InputObject $2 -Path ''objectid'' -Enumerate)' } @{ Name = 'Certificate Permissions' Expression = '$Certs' } @{ Name = 'Key Permissions' Expression = '$Keys' } @{ Name = 'Secret Permissions' Expression = '$Secrets' } @{ Name = 'Resource U' Expression = '$ResUCount' } @{ Name = 'Tag Name' Expression = '[string]$Tag.Name' } @{ Name = 'Tag Value' Expression = '[string]$Tag.Value' } ) Export = @{ WorksheetName = 'Key Vaults' TableNamePrefix = 'VaultTable_' Columns = @( 'Subscription' 'Resource Group' 'Name' 'Location' 'Retiring Feature' 'Retiring Date' 'SKU Family' 'SKU' 'Vault Uri' 'Public Network Access' 'Enable RBAC' 'Enable Soft Delete' 'Enable for Disk Encryption' 'Soft Delete Retention Days' 'Access Policy ObjectID' 'Certificate Permissions' 'Key Permissions' 'Secret Permissions' 'Resource U' ) TagColumns = @( 'Tag Name' 'Tag Value' ) TagColumnsBefore = 'Resource U' NumberFormat = '0' ConditionalText = @( 'New-ConditionalText false -Range L:L' 'New-ConditionalText enabled -Range J:J' 'New-ConditionalText -Range E2:E100 -ConditionalType ContainsText' ) } SourceCollector = 'Modules/Public/InventoryModules/Security/Vault.ps1' } |