Resource Provider Registration on Qualdo-DRX for Azure¶
Please ensure that the Azure Subscription in which Qualdo-DRX will be deployed is registered for the required resource providers.
- The required resource providers to be registered are:
-
Microsoft.Authorization Microsoft.Compute Microsoft.ContainerRegistry Microsoft.ContainerService Microsoft.Databricks Microsoft.DBforPostgreSQL Microsoft.Insights Microsoft.KeyVault Microsoft.ManagedIdentity Microsoft.Network Microsoft.Resources Microsoft.Sql Microsoft.Storage Microsoft.SignalRService
Firewall rules to be added¶
Please ensure that the following rules are added in the Firewall.
- Network rules:
-
S.No Purpose Source Type Source IP Destination Type Destination Service Tags Protocol Port 1 tag IP Address Private and Public Subnet CIDR Range for Compute Engine Service Tags AzureDatabricks TCP 443 2 sql IP Address Private and Public Subnet CIDR Range for Compute Engine Service Tags Sql.<Region> or Sql TCP 3306 3 storage IP Address Private and Public Subnet CIDR Range for Compute Engine Service Tags Storage.<Region> or Storage TCP 443 4 hub IP Address Private and Public Subnet CIDR Range for Compute Engine Service Tags EventHub.<Region> or EventHub TCP 9093 - Application rules:
-
S.No Source Type Source IP Address Destination Type Target FQDNs / Tags Protocol & Port 1 IP Address Subnet CIDR Range & Private and Public Subnet CIDR Range for Compute Engine FQDN files.pythonhosted.org, pypi.org Http:80, Https:443 2 IP Address Subnet CIDR Range FQDN prod-central-ops.azure-qualdo.ai, docs.azure-qualdo.ai, api.sendgrid.com, azure.archive.ubuntu.com, management.azure.com, api.snapcraft.io, canonical-bos01.cdn.snapcraftcontent.com, prodqualdomanagehub.eastus.data.azurecr.io, prodqualdomanagehub.azurecr.io, qualdo.zendesk.com, nonsaasbucket.blob.core.windows.net, download.docker.com, pkgs.k8s.io, archive.ubuntu.com, kubernetes.github.io, github.com, objects.githubusercontent.com, registry.k8s.io, Us-east4-docker.pkg.dev, prod-registry-k8s-io-us-east-1.s3.dualstack.us-east-1.amazonaws.com, eastus.av.mk.io, release-assets.githubusercontent.com, *.webpubsub.azure.com, raw.githubusercontent.com, aka.ms, azcliextensionsync.blob.core.windows.net, azcliprod.blob.core.windows.net, athena-downloads.s3.amazonaws.com, *.docker.io, production.cloudflare.docker.com, production.cloudfront.docker.com,login.microsoftonline.com,aka.ms,*.registry.k8s.io,*.pkg.dev, *.docker.pkg.dev Http:80, Https:443 3 IP Address Subnet CIDR Range FQDN Tag AzureKubernetesService Https:443 4 IP Address Private and Public Subnet CIDR Range for Compute Engine FQDN repo.maven.apache.org, repo1.maven.org Http:80, Https:443 - DNAT rules:
-
Source Type Source IP Address Destination IP Address Destination Port Protocol Translated Type Translated Address Translated Port IP Address * or VPN IP Firewall Public IP 80 TCP IP Address Loadbalancer IP 80