Skip to content

bug(scanner): replace broken AZ-NET-012 NSG flow-log logic with VNet flow-log evidence #300

Description

@m-khan-97

What is wrong

AZ-NET-012 calls AzureClient.get_nsg_flow_logs, which does not exist. Its broad exception handler then turns that programming error into a finding for every NSG. The test suite currently mocks the invented method and explicitly documents the production false positive.

The remediation script creates NSG flow logs. Microsoft stopped new NSG flow-log creation after June 30, 2025 and retires the feature on September 30, 2027; VNet flow logs are the supported replacement.

Evidence: scanner/rules/az_net_012.py:47-56, tests/test_rules_network.py:546-551, and playbooks/cli/fix_az_net_012.sh:18-25.

Primary source: https://learn.microsoft.com/azure/network-watcher/network-watcher-nsg-flow-logging-overview

Acceptance criteria

  • The rule evaluates VNet flow logs at the correct Azure scope.
  • Existing legacy NSG logs are represented accurately during migration without recommending new creation.
  • Permission/API failure becomes UNKNOWN under feat: persist PASS/FAIL/ERROR/NOT_APPLICABLE per rule per resource, fix compliance score #263, never FAIL or PASS.
  • Tests use real Azure SDK response shapes and cover no resources, compliant, noncompliant, 403, 429, pagination and partial collection.
  • Remediation is preview-first, idempotent, target-verified and has rollback/validation guidance.
  • Rule documentation and framework mappings are re-reviewed against the new evidence semantics.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workingpriority: criticalMust be fixed immediately, breaks core functionality

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions