Skip to content

Automatic OS image patching is disabled for Virtual Machine scale sets

Description

This policy enforces enabling automatic OS image patching on Virtual Machine Scale Sets to always keep Virtual Machines secure by safely applying latest security patches every month.

Code Example

go
resource "azurerm_virtual_machine_scale_set" "example" {
          ...
 +        automatic_os_upgrade = true
          ...
        }

Remediation

Terraform

  • Resource: azurerm_virtual_machine_scale_set
  • Arguments: automatic_os_upgrade

Rule Details

FieldValue
IDIAC-0602
SeverityLOW
IaC Typearm
FrameworksTerraform, TerraformPlan
Checkov IDCKV_AZURE_95

References