attestations
Creates, updates, deletes, gets or lists an attestations resource.
Overview
| Name | attestations |
| Type | Resource |
| Id | azure.policy_insights.attestations |
Fields
The following fields are returned by SELECT queries:
- get_at_resource_group
- list_for_resource_group
- get_at_subscription
- get_at_resource
- list_for_subscription
- list_for_resource
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentDate | string (date-time) | The time the evidence was assessed. |
comments | string | Comments describing why this attestation was created. |
complianceState | string | The compliance state that should be set on the resource. Known values are: "Compliant", "NonCompliant", and "Unknown". (Compliant, NonCompliant, Unknown) |
evidence | array | The evidence supporting the compliance state set in this attestation. |
expiresOn | string (date-time) | The time the compliance state should expire. |
lastComplianceStateChangeAt | string (date-time) | The time the compliance state was last changed in this attestation. |
metadata | object | Additional metadata for this attestation. |
owner | string | The person responsible for setting the state of the resource. This value is typically an Azure Active Directory object ID. |
policyAssignmentId | string | The resource ID of the policy assignment that the attestation is setting the state for. Required. |
policyDefinitionReferenceId | string | The policy definition reference ID from a policy set definition that the attestation is setting the state for. If the policy assignment assigns a policy set definition the attestation can choose a definition within the set definition with this property or omit this and set the state for the entire set definition. |
provisioningState | string | The status of the attestation. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentDate | string (date-time) | The time the evidence was assessed. |
comments | string | Comments describing why this attestation was created. |
complianceState | string | The compliance state that should be set on the resource. Known values are: "Compliant", "NonCompliant", and "Unknown". (Compliant, NonCompliant, Unknown) |
evidence | array | The evidence supporting the compliance state set in this attestation. |
expiresOn | string (date-time) | The time the compliance state should expire. |
lastComplianceStateChangeAt | string (date-time) | The time the compliance state was last changed in this attestation. |
metadata | object | Additional metadata for this attestation. |
owner | string | The person responsible for setting the state of the resource. This value is typically an Azure Active Directory object ID. |
policyAssignmentId | string | The resource ID of the policy assignment that the attestation is setting the state for. Required. |
policyDefinitionReferenceId | string | The policy definition reference ID from a policy set definition that the attestation is setting the state for. If the policy assignment assigns a policy set definition the attestation can choose a definition within the set definition with this property or omit this and set the state for the entire set definition. |
provisioningState | string | The status of the attestation. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentDate | string (date-time) | The time the evidence was assessed. |
comments | string | Comments describing why this attestation was created. |
complianceState | string | The compliance state that should be set on the resource. Known values are: "Compliant", "NonCompliant", and "Unknown". (Compliant, NonCompliant, Unknown) |
evidence | array | The evidence supporting the compliance state set in this attestation. |
expiresOn | string (date-time) | The time the compliance state should expire. |
lastComplianceStateChangeAt | string (date-time) | The time the compliance state was last changed in this attestation. |
metadata | object | Additional metadata for this attestation. |
owner | string | The person responsible for setting the state of the resource. This value is typically an Azure Active Directory object ID. |
policyAssignmentId | string | The resource ID of the policy assignment that the attestation is setting the state for. Required. |
policyDefinitionReferenceId | string | The policy definition reference ID from a policy set definition that the attestation is setting the state for. If the policy assignment assigns a policy set definition the attestation can choose a definition within the set definition with this property or omit this and set the state for the entire set definition. |
provisioningState | string | The status of the attestation. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentDate | string (date-time) | The time the evidence was assessed. |
comments | string | Comments describing why this attestation was created. |
complianceState | string | The compliance state that should be set on the resource. Known values are: "Compliant", "NonCompliant", and "Unknown". (Compliant, NonCompliant, Unknown) |
evidence | array | The evidence supporting the compliance state set in this attestation. |
expiresOn | string (date-time) | The time the compliance state should expire. |
lastComplianceStateChangeAt | string (date-time) | The time the compliance state was last changed in this attestation. |
metadata | object | Additional metadata for this attestation. |
owner | string | The person responsible for setting the state of the resource. This value is typically an Azure Active Directory object ID. |
policyAssignmentId | string | The resource ID of the policy assignment that the attestation is setting the state for. Required. |
policyDefinitionReferenceId | string | The policy definition reference ID from a policy set definition that the attestation is setting the state for. If the policy assignment assigns a policy set definition the attestation can choose a definition within the set definition with this property or omit this and set the state for the entire set definition. |
provisioningState | string | The status of the attestation. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentDate | string (date-time) | The time the evidence was assessed. |
comments | string | Comments describing why this attestation was created. |
complianceState | string | The compliance state that should be set on the resource. Known values are: "Compliant", "NonCompliant", and "Unknown". (Compliant, NonCompliant, Unknown) |
evidence | array | The evidence supporting the compliance state set in this attestation. |
expiresOn | string (date-time) | The time the compliance state should expire. |
lastComplianceStateChangeAt | string (date-time) | The time the compliance state was last changed in this attestation. |
metadata | object | Additional metadata for this attestation. |
owner | string | The person responsible for setting the state of the resource. This value is typically an Azure Active Directory object ID. |
policyAssignmentId | string | The resource ID of the policy assignment that the attestation is setting the state for. Required. |
policyDefinitionReferenceId | string | The policy definition reference ID from a policy set definition that the attestation is setting the state for. If the policy assignment assigns a policy set definition the attestation can choose a definition within the set definition with this property or omit this and set the state for the entire set definition. |
provisioningState | string | The status of the attestation. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
assessmentDate | string (date-time) | The time the evidence was assessed. |
comments | string | Comments describing why this attestation was created. |
complianceState | string | The compliance state that should be set on the resource. Known values are: "Compliant", "NonCompliant", and "Unknown". (Compliant, NonCompliant, Unknown) |
evidence | array | The evidence supporting the compliance state set in this attestation. |
expiresOn | string (date-time) | The time the compliance state should expire. |
lastComplianceStateChangeAt | string (date-time) | The time the compliance state was last changed in this attestation. |
metadata | object | Additional metadata for this attestation. |
owner | string | The person responsible for setting the state of the resource. This value is typically an Azure Active Directory object ID. |
policyAssignmentId | string | The resource ID of the policy assignment that the attestation is setting the state for. Required. |
policyDefinitionReferenceId | string | The policy definition reference ID from a policy set definition that the attestation is setting the state for. If the policy assignment assigns a policy set definition the attestation can choose a definition within the set definition with this property or omit this and set the state for the entire set definition. |
provisioningState | string | The status of the attestation. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get_at_resource_group | select | resource_group_name, attestation_name, subscription_id | Gets an existing attestation at resource group scope. | |
list_for_resource_group | select | resource_group_name, subscription_id | $top, $filter | Gets all attestations for the resource group. |
get_at_subscription | select | attestation_name, subscription_id | Gets an existing attestation at subscription scope. | |
get_at_resource | select | resource_id, attestation_name | Gets an existing attestation at resource scope. | |
list_for_subscription | select | subscription_id | $top, $filter | Gets all attestations for the subscription. |
list_for_resource | select | resource_id | $top, $filter | Gets all attestations for a resource. |
create_or_update_at_resource_group | insert | resource_group_name, attestation_name, subscription_id, properties | Creates or updates an attestation at resource group scope. | |
create_or_update_at_subscription | insert | attestation_name, subscription_id, properties | Creates or updates an attestation at subscription scope. | |
create_or_update_at_resource | insert | resource_id, attestation_name, properties | Creates or updates an attestation at resource scope. | |
create_or_update_at_resource_group | replace | resource_group_name, attestation_name, subscription_id, properties | Creates or updates an attestation at resource group scope. | |
create_or_update_at_subscription | replace | attestation_name, subscription_id, properties | Creates or updates an attestation at subscription scope. | |
create_or_update_at_resource | replace | resource_id, attestation_name, properties | Creates or updates an attestation at resource scope. | |
delete_at_resource_group | delete | resource_group_name, attestation_name, subscription_id | Deletes an existing attestation at resource group scope. | |
delete_at_subscription | delete | attestation_name, subscription_id | Deletes an existing attestation at subscription scope. | |
delete_at_resource | delete | resource_id, attestation_name | Deletes an existing attestation at individual resource scope. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
attestation_name | string | The name of the attestation. Required. |
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
resource_id | string | Resource ID. Required. |
subscription_id | string | |
$filter | string | OData filter expression. Default value is None. |
$top | integer | Maximum number of records to return. Default value is None. |
SELECT examples
- get_at_resource_group
- list_for_resource_group
- get_at_subscription
- get_at_resource
- list_for_subscription
- list_for_resource
Gets an existing attestation at resource group scope.
SELECT
id,
name,
assessmentDate,
comments,
complianceState,
evidence,
expiresOn,
lastComplianceStateChangeAt,
metadata,
owner,
policyAssignmentId,
policyDefinitionReferenceId,
provisioningState,
systemData,
type
FROM azure.policy_insights.attestations
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND attestation_name = '{{ attestation_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets all attestations for the resource group.
SELECT
id,
name,
assessmentDate,
comments,
complianceState,
evidence,
expiresOn,
lastComplianceStateChangeAt,
metadata,
owner,
policyAssignmentId,
policyDefinitionReferenceId,
provisioningState,
systemData,
type
FROM azure.policy_insights.attestations
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
AND $top = '{{ $top }}'
AND $filter = '{{ $filter }}'
;
Gets an existing attestation at subscription scope.
SELECT
id,
name,
assessmentDate,
comments,
complianceState,
evidence,
expiresOn,
lastComplianceStateChangeAt,
metadata,
owner,
policyAssignmentId,
policyDefinitionReferenceId,
provisioningState,
systemData,
type
FROM azure.policy_insights.attestations
WHERE attestation_name = '{{ attestation_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets an existing attestation at resource scope.
SELECT
id,
name,
assessmentDate,
comments,
complianceState,
evidence,
expiresOn,
lastComplianceStateChangeAt,
metadata,
owner,
policyAssignmentId,
policyDefinitionReferenceId,
provisioningState,
systemData,
type
FROM azure.policy_insights.attestations
WHERE resource_id = '{{ resource_id }}' -- required
AND attestation_name = '{{ attestation_name }}' -- required
;
Gets all attestations for the subscription.
SELECT
id,
name,
assessmentDate,
comments,
complianceState,
evidence,
expiresOn,
lastComplianceStateChangeAt,
metadata,
owner,
policyAssignmentId,
policyDefinitionReferenceId,
provisioningState,
systemData,
type
FROM azure.policy_insights.attestations
WHERE subscription_id = '{{ subscription_id }}' -- required
AND $top = '{{ $top }}'
AND $filter = '{{ $filter }}'
;
Gets all attestations for a resource.
SELECT
id,
name,
assessmentDate,
comments,
complianceState,
evidence,
expiresOn,
lastComplianceStateChangeAt,
metadata,
owner,
policyAssignmentId,
policyDefinitionReferenceId,
provisioningState,
systemData,
type
FROM azure.policy_insights.attestations
WHERE resource_id = '{{ resource_id }}' -- required
AND $top = '{{ $top }}'
AND $filter = '{{ $filter }}'
;
INSERT examples
- create_or_update_at_resource_group
- create_or_update_at_subscription
- create_or_update_at_resource
- Manifest
Creates or updates an attestation at resource group scope.
INSERT INTO azure.policy_insights.attestations (
properties,
resource_group_name,
attestation_name,
subscription_id
)
SELECT
'{{ properties }}' /* required */,
'{{ resource_group_name }}',
'{{ attestation_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
properties,
systemData,
type
;
Creates or updates an attestation at subscription scope.
INSERT INTO azure.policy_insights.attestations (
properties,
attestation_name,
subscription_id
)
SELECT
'{{ properties }}' /* required */,
'{{ attestation_name }}',
'{{ subscription_id }}'
RETURNING
id,
name,
properties,
systemData,
type
;
Creates or updates an attestation at resource scope.
INSERT INTO azure.policy_insights.attestations (
properties,
resource_id,
attestation_name
)
SELECT
'{{ properties }}' /* required */,
'{{ resource_id }}',
'{{ attestation_name }}'
RETURNING
id,
name,
properties,
systemData,
type
;
# Description fields are for documentation purposes
- name: attestations
props:
- name: resource_group_name
value: "{{ resource_group_name }}"
description: Required parameter for the attestations resource.
- name: attestation_name
value: "{{ attestation_name }}"
description: Required parameter for the attestations resource.
- name: subscription_id
value: "{{ subscription_id }}"
description: Required parameter for the attestations resource.
- name: resource_id
value: "{{ resource_id }}"
description: Required parameter for the attestations resource.
- name: properties
description: |
Properties for the attestation. Required.
value:
policyAssignmentId: "{{ policyAssignmentId }}"
policyDefinitionReferenceId: "{{ policyDefinitionReferenceId }}"
complianceState: "{{ complianceState }}"
expiresOn: "{{ expiresOn }}"
owner: "{{ owner }}"
comments: "{{ comments }}"
evidence:
- description: "{{ description }}"
sourceUri: "{{ sourceUri }}"
provisioningState: "{{ provisioningState }}"
lastComplianceStateChangeAt: "{{ lastComplianceStateChangeAt }}"
assessmentDate: "{{ assessmentDate }}"
metadata: "{{ metadata }}"
REPLACE examples
- create_or_update_at_resource_group
- create_or_update_at_subscription
- create_or_update_at_resource
Creates or updates an attestation at resource group scope.
REPLACE azure.policy_insights.attestations
SET
properties = '{{ properties }}'
WHERE
resource_group_name = '{{ resource_group_name }}' --required
AND attestation_name = '{{ attestation_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
AND properties = '{{ properties }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
Creates or updates an attestation at subscription scope.
REPLACE azure.policy_insights.attestations
SET
properties = '{{ properties }}'
WHERE
attestation_name = '{{ attestation_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
AND properties = '{{ properties }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
Creates or updates an attestation at resource scope.
REPLACE azure.policy_insights.attestations
SET
properties = '{{ properties }}'
WHERE
resource_id = '{{ resource_id }}' --required
AND attestation_name = '{{ attestation_name }}' --required
AND properties = '{{ properties }}' --required
RETURNING
id,
name,
properties,
systemData,
type;
DELETE examples
- delete_at_resource_group
- delete_at_subscription
- delete_at_resource
Deletes an existing attestation at resource group scope.
DELETE FROM azure.policy_insights.attestations
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND attestation_name = '{{ attestation_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;
Deletes an existing attestation at subscription scope.
DELETE FROM azure.policy_insights.attestations
WHERE attestation_name = '{{ attestation_name }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;
Deletes an existing attestation at individual resource scope.
DELETE FROM azure.policy_insights.attestations
WHERE resource_id = '{{ resource_id }}' --required
AND attestation_name = '{{ attestation_name }}' --required
;