Skip to content

feat: add VM Scale Set inventory, collectors, and first rule #271

Description

@parthrohit22

What problem does this solve?

OpenShield currently has zero coverage of Virtual Machine Scale Sets — no inventory collector, no
rules. VMSS is a common production compute pattern and is entirely invisible to the scanner today.

Describe the solution

  • Add a VMSS inventory collector to AzureClient (get_virtual_machine_scale_sets(), following the
    existing collector pattern in docs/adding-a-rule.md).
  • Ship one high-value first rule reusing existing compute-domain logic where possible (e.g. a VMSS
    equivalent of AZ-CMP-002's disk-encryption check, or AZ-CMP-001's NSG check applied to the VMSS
    network profile) rather than inventing new detection logic from scratch.
  • Add matching playbook, tests, and framework mappings per the standard rule contract.

Alternatives considered

Wait until AKS/container work (already well underway via issue #255 and 6 existing az_aks rules)
progresses further before touching VMSS — rejected; VMSS is a distinct, currently uncovered gap
that doesn't depend on the container work landing first.

Additional context

Sequenced before container platform work, per the compute roadmap's own implementation strategy.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requesthelp wantedCommunity contributions neededpriority: mediumShould be fixed soon but not blockingstale

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions