Skip to content

feat(finops-hub): add Azure Data Explorer encryption options - #2338

Open
Chaithanya Nallamothu (Chaithanyanallamothu) wants to merge 2 commits into
microsoft:devfrom
Chaithanyanallamothu:Chaithanyanallamothu/adx-double-encryption
Open

Chaithanya Nallamothu (Chaithanyanallamothu) wants to merge 2 commits into
microsoft:devfrom
Chaithanyanallamothu:Chaithanyanallamothu/adx-double-encryption

Conversation

@Chaithanyanallamothu

Copy link
Copy Markdown

🛠️ Description

Adds Azure Data Explorer disk and double encryption options to FinOps Hub.

  • Added enableAdxDiskEncryption and enableAdxDoubleEncryption, both disabled by default.
  • Passed both settings through the FinOps Hub and Analytics modules.
  • Applied the settings to the corresponding Kusto cluster properties.
  • Added a test deployment with both encryption options enabled.
  • Updated the FinOps toolkit changelog.

Fixes #2196

📷 Screenshots

Not applicable. This change only updates the FinOps Hub deployment templates.

📋 Checklist

🔬 How did you test this change?

  • 🤏 Lint tests
  • 🤞 PS -WhatIf / az validate
  • 👍 Manually deployed + verified
  • 💪 Unit tests
  • 🙌 Integration tests

Validated the updated Bicep templates locally and successfully ran Build-Toolkit finops-hub.

📦 Deploy to test?

  • Hubs + ADX (managed)
  • Hubs + Fabric (manual) — URI:
  • Hubs (manual)
  • Hubs (no data)
  • Workbooks
  • Alerts

🙋‍♀️ Do any of the following that apply?

  • 🚨 This is a breaking change.
  • 🤏 The change is less than 20 lines of code.

📑 Did you update docs/changelog.md?

  • ✅ Updated changelog (required for dev PRs)
  • ➡️ Will add log in a future PR (feature branch PRs only)
  • ❎ Log not needed (small/internal change)

📖 Did you update documentation?

  • ✅ Public docs in docs (required for dev)
  • ✅ Public docs in docs-mslearn (required for dev)
  • ✅ Internal dev docs in docs-wiki (required for dev)
  • ✅ Internal dev docs in src (required for dev)
  • ➡️ Will add docs in a future PR (feature branch PRs only)
  • ❎ Docs not needed (small/internal change)

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Warning

Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.

Copilot review overview

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Adds configurable Azure Data Explorer (ADX) disk and double encryption options to the FinOps Hub Bicep templates and wires them through module boundaries to the ADX (Kusto) cluster resource.

Changes:

  • Introduced enableAdxDiskEncryption and enableAdxDoubleEncryption parameters (default false) in main.bicep, modules/hub.bicep, and Analytics/app.bicep.
  • Applied both flags to the Microsoft.Kusto/clusters resource properties.
  • Added a test deployment scenario enabling both encryption options and updated the toolkit changelog.
File Description
src/​templates/​finops-hub/​test/​main.test.bicep Adds a second test module deployment enabling both ADX encryption flags.
src/​templates/​finops-hub/​modules/​hub.bicep Adds params and forwards them into the Analytics module.
src/​templates/​finops-hub/​modules/​Microsoft.FinOpsHubs/​Analytics/​app.bicep Adds params and sets Kusto cluster encryption properties based on them.
src/​templates/​finops-hub/​main.bicep Adds top-level params and passes them to the hub module.
docs-mslearn/​toolkit/​changelog.md Notes the new ADX encryption options in the changelog.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment on lines 314 to 317
enableStreamingIngest: true
enableDiskEncryption: enableAdxDiskEncryption
enableDoubleEncryption: enableAdxDoubleEncryption
enableAutoStop: false
@Chaithanyanallamothu

Copy link
Copy Markdown
Author

@microsoft-github-policy-service agree

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Needs: Review 👀 PR that is ready to be reviewed

Projects

None yet

Development

Successfully merging this pull request may close these issues.

add support for Azure Data Explorer Encryption and Double Encryption

4 participants