Skip to content

Commit 132ba12

Browse files
vivaladaVictor Saad Bueno Valadares
and
Victor Saad Bueno Valadares
authored
Review security risks (Azure#305)
* Work in progress. Removed Usernames and Passwords. * Removed hardcoded IP addresses. --------- Co-authored-by: Victor Saad Bueno Valadares <[email protected]>
1 parent b1a46de commit 132ba12

File tree

6 files changed

+43
-43
lines changed

6 files changed

+43
-43
lines changed

AVS-Landing-Zone/GreenField Lite/PortalUI/Bicep/GreenFieldLiteDeploy.parameters.json

+2-2
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"value": "SJLITE-SDDC"
77
},
88
"PrivateCloudAddressSpace": {
9-
"value": "10.55.0.0/22"
9+
"value": ""
1010
},
1111
"PrivateCloudSKU": {
1212
"value": "AV36P"
@@ -16,7 +16,7 @@
1616
},
1717
"AlertEmails": {
1818
"value": [
19-
"example@microsoft.com"
19+
"example@contoso.com"
2020
]
2121
}
2222
}

AVS-Landing-Zone/GreenField/ARM/ESLZDeploy.parameters.json

+8-8
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"value": "ESLZ"
77
},
88
"PrivateCloudAddressSpace": {
9-
"value": "10.0.0.0/22"
9+
"value": ""
1010
},
1111
"PrivateCloudSKU": {
1212
"value": "AV36P"
@@ -15,30 +15,30 @@
1515
"value": 3
1616
},
1717
"VNetAddressSpace": {
18-
"value": "10.1.0.0/16"
18+
"value": ""
1919
},
2020
"VNetGatewaySubnet": {
21-
"value": "10.1.0.0/24"
21+
"value": ""
2222
},
2323
"AlertEmails": {
2424
"value": [
25-
"example@microsoft.com"
25+
"example@contoso.com"
2626
]
2727
},
2828
"DeployJumpbox": {
2929
"value": true
3030
},
3131
"JumpboxUsername": {
32-
"value": "avsjump"
32+
"value": ""
3333
},
3434
"JumpboxPassword": {
35-
"value": "ChangeM3!"
35+
"value": ""
3636
},
3737
"JumpboxSubnet": {
38-
"value": "10.1.1.0/25"
38+
"value": ""
3939
},
4040
"BastionSubnet": {
41-
"value": "10.1.1.128/25"
41+
"value": ""
4242
},
4343
"VNetExists": {
4444
"value": false

AVS-Landing-Zone/GreenField/Bicep/ESLZDeploy.parameters.json

+8-8
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@
66
"value": "LZA"
77
},
88
"PrivateCloudAddressSpace": {
9-
"value": "10.0.0.0/22"
9+
"value": ""
1010
},
1111
"PrivateCloudSKU": {
1212
"value": "AV36P"
@@ -15,27 +15,27 @@
1515
"value": 3
1616
},
1717
"VNetAddressSpace": {
18-
"value": "10.1.0.0/16"
18+
"value": ""
1919
},
2020
"VNetGatewaySubnet": {
21-
"value": "10.1.0.0/24"
21+
"value": ""
2222
},
2323
"AlertEmails": {
2424
"value": [
25-
"example@microsoft.com"
25+
"example@contoso.com"
2626
]
2727
},
2828
"DeployJumpbox": {
2929
"value": true
3030
},
3131
"JumpboxUsername": {
32-
"value": "avsjump"
32+
"value": ""
3333
},
3434
"JumpboxPassword": {
35-
"value": "ChangeM3!"
35+
"value": ""
3636
},
3737
"JumpboxSubnet": {
38-
"value": "10.1.1.0/25"
38+
"value": ""
3939
},
4040
"OSVersion": {
4141
"value": "2022-datacenter-azure-edition-smalldisk"
@@ -50,7 +50,7 @@
5050
"value": "https://raw.githubusercontent.com/Azure/Enterprise-Scale-for-AVS/main/AVS-Landing-Zone/GreenField/Scripts/bootstrap.ps1"
5151
},
5252
"BastionSubnet": {
53-
"value": "10.1.1.128/25"
53+
"value": ""
5454
},
5555
"VNetExists": {
5656
"value": false

AVS-Landing-Zone/GreenField/PortalUI/Bicep/ESLZDeploy.parameters.json

+17-17
Original file line numberDiff line numberDiff line change
@@ -3,25 +3,25 @@
33
"contentVersion": "1.0.0.0",
44
"parameters": {
55
"Prefix": {
6-
"value": "SJTEST2"
6+
"value": ""
77
},
88
"DeployPrivateCloud": {
99
"value": false
1010
},
1111
"PrivateCloudName": {
12-
"value": "SA-SDDC-1"
12+
"value": ""
1313
},
1414
"ExistingPrivateCloudName": {
15-
"value": "SA-SDDC-1"
15+
"value": ""
1616
},
1717
"ExistingPrivateCloudResourceId": {
18-
"value": "/subscriptions/1caa5ab4-523f-4851-952b-1b689c48fae9/resourceGroups/SA-SDDC-1/providers/Microsoft.AVS/privateClouds/SA-SDDC-1"
18+
"value": ""
1919
},
2020
"PrivateCloudResourceGroupName": {
21-
"value": "SA-SDDC-1"
21+
"value": ""
2222
},
2323
"PrivateCloudAddressSpace": {
24-
"value": "10.20.0.0/22"
24+
"value": ""
2525
},
2626
"PrivateCloudSKU": {
2727
"value": "AV36P"
@@ -36,40 +36,40 @@
3636
"value": false
3737
},
3838
"NewNetworkName": {
39-
"value": "SJTESTNET2-vnet"
39+
"value": ""
4040
},
4141
"NewNetworkResourceGroupName": {
42-
"value": "SJTESTNET2"
42+
"value": ""
4343
},
4444
"NewVNetAddressSpace": {
45-
"value": "10.111.0.0/16"
45+
"value": ""
4646
},
4747
"NewVnetNewGatewaySubnetAddressPrefix": {
48-
"value": "10.111.0.0/24"
48+
"value": ""
4949
},
5050
"ExistingNetworkResourceId": {
51-
"value": "/subscriptions/1caa5ab4-523f-4851-952b-1b689c48fae9/resourceGroups/SJTESTNET1/providers/Microsoft.Network/virtualNetworks/SJTESTNET1-vnet"
51+
"value": ""
5252
},
5353
"ExistingGatewayName": {
54-
"value": "SJTEST2-gw"
54+
"value": ""
5555
},
5656
"AlertEmails": {
57-
"value": "example@microsoft.com"
57+
"value": "example@contoso.com"
5858
},
5959
"DeployJumpbox": {
6060
"value": true
6161
},
6262
"JumpboxUsername": {
63-
"value": "avsjump"
63+
"value": ""
6464
},
6565
"JumpboxPassword": {
66-
"value": "ChangeM3!"
66+
"value": ""
6767
},
6868
"JumpboxSubnet": {
69-
"value": "10.111.2.0/24"
69+
"value": ""
7070
},
7171
"BastionSubnet": {
72-
"value": "10.111.1.0/24"
72+
"value": ""
7373
}
7474
}
7575
}

AVS-Landing-Zone/GreenField/Terraform/terraform.tfvars

+7-7
Original file line numberDiff line numberDiff line change
@@ -6,21 +6,21 @@ prefix = "AVS"
66
region = "northeurope"
77

88
#AVS requires a /22 CIDR range, this must not overlap with other networks to be used with AVS
9-
avs-networkblock = "10.1.0.0/22"
9+
avs-networkblock = ""
1010
avs-sku = "AV36P"
1111
avs-hostcount = 3
1212
hcx_key_names = ["hcxsite1", "hcxsite2"]
1313

1414
#Input the Jumpbox local username, password and SKU of your choice
15-
adminusername = "replace me"
16-
adminpassword = "replace me"
15+
adminusername = ""
16+
adminpassword = ""
1717
jumpboxsku = "Standard_D2as_v4"
1818

1919
#Virtual network address space and required subnets, can be any CIDR range
20-
vnetaddressspace = "192.168.1.0/24"
21-
gatewaysubnet = "192.168.1.0/27"
22-
azurebastionsubnet = "192.168.1.64/26"
23-
jumpboxsubnet = "192.168.1.128/25"
20+
vnetaddressspace = ""
21+
gatewaysubnet = ""
22+
azurebastionsubnet = ""
23+
jumpboxsubnet = ""
2424

2525
#Enable or Disable telemetry
2626
telemetry_enabled = true

BrownField/Monitoring/AVS-Service-Health/Bicep/AVSServiceHealth.parameters.json

+1-1
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@
33
"contentVersion": "1.0.0.0",
44
"parameters": {
55
"ActionGroupEmails": {
6-
"value": "example@microsoft.com"
6+
"value": "example@contoso.com"
77
},
88
"PrivateCloudResourceId": {
99
"value": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/ExampleRG/providers/Microsoft.AVS/privateClouds/ExamplePrivateCloud"

0 commit comments

Comments
 (0)