diff --git a/docs-mslearn/toolkit/changelog.md b/docs-mslearn/toolkit/changelog.md index 6ca4dd7c3..783311a07 100644 --- a/docs-mslearn/toolkit/changelog.md +++ b/docs-mslearn/toolkit/changelog.md @@ -3,7 +3,7 @@ title: FinOps toolkit changelog description: Review the latest features and enhancements in the FinOps toolkit, including updates to FinOps hubs, Power BI reports, and more. author: MSBrett ms.author: brettwil -ms.date: 09/11/2026 +ms.date: 10/07/2026 ms.topic: reference ms.service: finops ms.subservice: finops-toolkit @@ -29,6 +29,7 @@ The following section lists features and enhancements that are currently in deve - **Added** - Added VNet and private network modes, including opt-in NAT Gateway support for private mode; NAT Gateway incurs additional cost when enabled ([#2163](https://github.com/microsoft/finops-toolkit/pull/2163)). + - Added Azure Data Explorer disk and double encryption options for FinOps hub deployments ([#2196](https://github.com/microsoft/finops-toolkit/issues/2196)). - **Changed** - Clarified that the FinOps toolkit exclusively manages the FinOps hub virtual network and documented customer-managed private endpoints as the preferred private-access topology, with virtual network peering as a secondary option ([#2156](https://github.com/microsoft/finops-toolkit/issues/2156)). - Replaced redundant `tolower()` comparisons in hub KQL with case-insensitive operators (`has`, `=~`, `!~`) so the engine can use the term index instead of scanning every row ([#2213](https://github.com/microsoft/finops-toolkit/issues/2213)). diff --git a/src/templates/finops-hub/createUiDefinition.json b/src/templates/finops-hub/createUiDefinition.json index 27c8de8dc..66a40c67e 100644 --- a/src/templates/finops-hub/createUiDefinition.json +++ b/src/templates/finops-hub/createUiDefinition.json @@ -671,6 +671,20 @@ "text": "Configure data retention settings for Azure Data Explorer." } }, + { + "name": "enableDataExplorerDiskEncryption", + "type": "Microsoft.Common.CheckBox", + "label": "Enable Data Explorer disk encryption", + "toolTip": "Enable disk encryption for the Azure Data Explorer cluster.", + "defaultValue": false + }, + { + "name": "enableDataExplorerDoubleEncryption", + "type": "Microsoft.Common.CheckBox", + "label": "Enable Data Explorer double encryption", + "toolTip": "Enable double encryption for the Azure Data Explorer cluster. This setting can only be enabled when the cluster is created.", + "defaultValue": false + }, { "name": "rawDays", "type": "Microsoft.Common.TextBox", @@ -1006,6 +1020,8 @@ "enableNatGateway": "[steps('advanced').networking.enableNatGateway]", "virtualNetworkAddressPrefix": "[steps('advanced').networking.virtualNetworkAddressPrefix]", "dataExplorerSku": "[steps('pricing').dataExplorer.dataExplorerSku]", + "enableDataExplorerDiskEncryption": "[steps('retention').dataExplorer.enableDataExplorerDiskEncryption]", + "enableDataExplorerDoubleEncryption": "[steps('retention').dataExplorer.enableDataExplorerDoubleEncryption]", "exportRetentionInDays": "[steps('retention').storage.msexportsDays]", "ingestionRetentionInMonths": "[steps('retention').storage.ingestionMonths]", "dataExplorerRawRetentionInDays": "[steps('retention').dataExplorer.rawDays]", diff --git a/src/templates/finops-hub/main.bicep b/src/templates/finops-hub/main.bicep index d5b3a8850..f4902faf9 100644 --- a/src/templates/finops-hub/main.bicep +++ b/src/templates/finops-hub/main.bicep @@ -51,6 +51,12 @@ param enableSpotRecommendations bool = false @description('Optional. Name of the Azure Data Explorer cluster to use for advanced analytics. If empty, Azure Data Explorer will not be deployed. Required to use with Power BI if you have more than $2-5M/mo in costs being monitored. Default: "" (do not use).') param dataExplorerName string = '' +@description('Optional. Enable disk encryption on the Azure Data Explorer cluster. Default: false.') +param enableDataExplorerDiskEncryption bool = false + +@description('Optional. Enable double encryption on the Azure Data Explorer cluster. Can only be enabled during cluster creation. Default: false.') +param enableDataExplorerDoubleEncryption bool = false + // https://learn.microsoft.com/azure/templates/microsoft.kusto/clusters?pivots=deployment-language-bicep#azuresku @description('Optional. Name of the Azure Data Explorer SKU. Default: "Dev(No SLA)_Standard_D11_v2".') @allowed([ @@ -184,6 +190,8 @@ module hub 'modules/hub.bicep' = { enableAHBRecommendations: enableAHBRecommendations enableSpotRecommendations: enableSpotRecommendations dataExplorerName: dataExplorerName + enableDataExplorerDiskEncryption: enableDataExplorerDiskEncryption + enableDataExplorerDoubleEncryption: enableDataExplorerDoubleEncryption dataExplorerSku: dataExplorerSku dataExplorerCapacity: dataExplorerCapacity fabricQueryUri: fabricQueryUri diff --git a/src/templates/finops-hub/modules/Microsoft.FinOpsHubs/Analytics/app.bicep b/src/templates/finops-hub/modules/Microsoft.FinOpsHubs/Analytics/app.bicep index 84a29d95c..7161af5f1 100644 --- a/src/templates/finops-hub/modules/Microsoft.FinOpsHubs/Analytics/app.bicep +++ b/src/templates/finops-hub/modules/Microsoft.FinOpsHubs/Analytics/app.bicep @@ -28,6 +28,12 @@ param core CoreMetadata @maxLength(22) param clusterName string = '' +@description('Optional. Enable disk encryption on the Azure Data Explorer cluster. Default: false.') +param enableDataExplorerDiskEncryption bool = false + +@description('Optional. Enable double encryption on the Azure Data Explorer cluster. Can only be enabled during cluster creation. Default: false.') +param enableDataExplorerDoubleEncryption bool = false + // https://learn.microsoft.com/azure/templates/microsoft.kusto/clusters?pivots=deployment-language-bicep#azuresku @description('Optional. Name of the Azure Data Explorer SKU. Default: "Dev(No SLA)_Standard_E2a_v4".') @allowed([ @@ -142,6 +148,13 @@ var ftkReleaseUri = indexOf(finOpsToolkitVersion, '-dev') != -1 var useFabric = !empty(fabricQueryUri) var useAzure = !useFabric && !empty(clusterName) +var diskEncryptionProperties = !enableDataExplorerDiskEncryption ? {} : { + enableDiskEncryption: true +} +var doubleEncryptionProperties = !enableDataExplorerDoubleEncryption ? {} : { + enableDoubleEncryption: true +} + // cSpell:ignore ftkver, privatelink var dataExplorerDnsSuffixLookup = { AzureCloud: 'kusto.windows.net' @@ -306,6 +319,8 @@ resource cluster 'Microsoft.Kusto/clusters@2023-08-15' = if (useAzure) { } properties: { enableStreamingIngest: true + ...diskEncryptionProperties + ...doubleEncryptionProperties enableAutoStop: false publicNetworkAccess: app.hub.options.privateRouting ? 'Disabled' : 'Enabled' // TODO: Figure out why this is breaking upgrades diff --git a/src/templates/finops-hub/modules/hub.bicep b/src/templates/finops-hub/modules/hub.bicep index c5a563d63..ecf98d59d 100644 --- a/src/templates/finops-hub/modules/hub.bicep +++ b/src/templates/finops-hub/modules/hub.bicep @@ -68,6 +68,12 @@ param fabricCapacityUnits int = 2 @description('Optional. Name of the Azure Data Explorer cluster to use for advanced analytics. If empty, Azure Data Explorer will not be deployed. Required to use with Power BI if you have more than $2-5M/mo in costs being monitored. Default: "" (do not use).') param dataExplorerName string = '' +@description('Optional. Enable disk encryption on the Azure Data Explorer cluster. Default: false.') +param enableDataExplorerDiskEncryption bool = false + +@description('Optional. Enable double encryption on the Azure Data Explorer cluster. Can only be enabled during cluster creation. Default: false.') +param enableDataExplorerDoubleEncryption bool = false + // https://learn.microsoft.com/azure/templates/microsoft.kusto/clusters?pivots=deployment-language-bicep#azuresku @description('Optional. Name of the Azure Data Explorer SKU. Ignore when using Microsoft Fabric or not deploying Data Explorer. Default: "Dev(No SLA)_Standard_D11_v2".') @allowed([ @@ -307,6 +313,8 @@ module analytics 'Microsoft.FinOpsHubs/Analytics/app.bicep' = if (useFabric || u fabricQueryUri: fabricQueryUri fabricCapacityUnits: fabricCapacityUnits clusterName: dataExplorerName + enableDataExplorerDiskEncryption: enableDataExplorerDiskEncryption + enableDataExplorerDoubleEncryption: enableDataExplorerDoubleEncryption clusterSku: dataExplorerSku clusterCapacity: dataExplorerCapacity rawRetentionInDays: dataExplorerRawRetentionInDays diff --git a/src/templates/finops-hub/test/main.test.bicep b/src/templates/finops-hub/test/main.test.bicep index 82d7595d9..d1d0362f0 100644 --- a/src/templates/finops-hub/test/main.test.bicep +++ b/src/templates/finops-hub/test/main.test.bicep @@ -15,4 +15,16 @@ module hub '../main.bicep' = { } } +// Test 2 - Creates a FinOps hub with Azure Data Explorer encryption enabled. +module hubWithAdxEncryption '../main.bicep' = { + name: 'finops-hub-adx-encryption' + params: { + hubName: '${uniqueName}-adx' + location: location + dataExplorerName: '${uniqueName}-adx' + enableDataExplorerDiskEncryption: true + enableDataExplorerDoubleEncryption: true + } +} + output hubName string = hub.outputs.name