Day 539. When trying to query a built-in #Azure Policy definition using the Azure CLI, the CLI will first tell you to supply a "--policy" argument and then tell you that there is no such argument.
Daily Azure Shit
Daily dosis of shit experienced on Microsoft Azure.
This account is obviously not affiliated with Microsoft.
Day 534. When you read the #Azure Service Principal of the Microsoft Graph application as data source in Terraform, the complete output is around 16000 lines and this data source alone will add approximately 760kB to your Terraform state. That is because this data source contains all of these application's app roles and all OAuth2 permission scopes including their descriptions.
Day 541. While we already know that log category groups can differ from service to service, this is the first time we have seen different category groups within one service. In this example, we found that #Azure Key Vaults in Denmark East do not have the "audit" log category group while it exists in other regions. Both of these Key Vaults have been created at the same time, so this is not about age of the resource.
Day 527. The only documentation you can find about supported log categories for the #Azure Application Gateway uses log table names which are for some reason different than the actual log category names. How do you find the names of these log categories to enable them using Terraform when there is no documentation? Easy, just look into the API requests the Azure Portal is doing when you enable them through the GUI.
Day 542. The shit from day 541 even breaks #Microsoft's own built-in #Azure Policies. When deploying a Key Vault in Denmark East and using the built-in policy to automatically deploy diagnostic settings, the policy evaluation will simply fail because the "audit" log category group does not exist, even when you want to enable a different category group. You cannot use this policy with Key Vaults in Denmark East.
Day 535. Once you have associated a custom route table to your #Azure Kubernetes Cluster, you are not allowed to change that route table. That seems to be a completely arbitrary limitation since you are allowed to change all custom routes, just not the name of the route table. And while they also state it in the docs, it doesn't get explained. Want to use a new route table for your cluster? Easy, deploy a new cluster.
Day 531. Once you have enabled a Web Application Firewall on your #Azure Application Gateway by associating a WAF policy, there is no way to disable the WAF again. The only way to get rid of the WAF is to delete the Application Gateway and recreate it again. That seems like a completely arbitrary limitation and will hit you hard once you decide you no longer want to use the WAF feature.
Day 540. Continuing the shit from day 539, Azure CLI not being able to show built-in Azure Policy definitions has been a known issue for years. Instead of fixing it, #Microsoft support simply closed the issue and called it a day.
Day 530. When creating an #Azure Log Analytics Workspace data export rule through #Terraform and you use a name that does not comply with the naming constraints, the Azure provider will tell you that this name is not allowed, but won't tell you what's wrong.
Tip: The names are not allowed to have an underscore.
Day 543. The reason why the shit from day 541 (a Key Vault resource without the "audit" log category group) breaks the the built-in #Azure Policy provided by #Microsoft is that it by design always tries to deploy a diagnostic setting for all log category groups and then sets them to enabled or disabled based on parameters you supply. If one of these disabled categories doesn't exist, the deployment always fails.
Day 537. The #Azure Portal setting for startup directory applies to your whole Microsoft Account and not just the browser you are currently in. Which is kind of stupid, because if you have multiple browsers set up for multiple Azure tenants, Azure will per default always log you into the same Azure tenant, regardless of your work environment.
Day 536. In case you are wondering, the terms "Azure tenant" and "Azure directory" largely refer to the same thing and are most often used interchangebly. They even always have the same UUID. According to #Microsoft support, there apparently is some distinction on a technical level though. Why does it always have to be this complicated?
Day 528. On day 425 we showed how #Azure finally introduced a workaround for a limitation in their Private Link DNS integration concept by allowing the Azure DNS resolver to fall back to Public DNS in case a Private Link DNS zone does not have a corresponding DNS record. This could be a really useful feature for Private DNS zones in general, but for some reason you are only allowed to use it for Private Link DNS zones.
Day 526. Following up on the shit from day 514 where the #Azure #Terraform provider tries to read registered Azure providers even though you tell it not to. #Microsoft's response: This is expected behavior and how about you disable enhanced provider validation for ALL of your Terraform providers by setting an environment variable?