-
Notifications
You must be signed in to change notification settings - Fork 4.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Not able to deploy azurerm_storage_account with public access disabled #25978
Comments
Hello all, no updates on this? |
hi @Annesars90 Thanks for opening this issue. Taking a look through this appears to be a duplicate of #2977, where when public network access is disabled on the storgae account the data plane endpoint isn't available - as such rather than having multiple issues open tracking the same thing I'm going to close this issue in favour of that one; would you mind subscribing to #2977 for updates? Thanks! |
Hi Tom, not sure if this is actually related./duplicate My issue here is that the queue properties are called during the creation of the storage account. This is routed to the public endpoint, because there is no private endpoint yet. My question is: why are queue properties being called at all when creating the resource storage account, without even a queue resource in there. |
Is there an existing issue for this?
Community Note
Terraform Version
1.8.3
AzureRM Provider Version
3.103.1
Affected Resource(s)/Data Source(s)
azurerm_storage_account
Terraform Configuration Files
Debug Output/Panic Output
Expected Behaviour
During the creation of the storage account, don't call queue properties before private endpoints are created.
Actual Behaviour
Halfway through provisioning the resource and its settings, the queue properties are being called, but this is done before a private endpoint is in place. This means the call is going outside of Azure, thereby over our firewall, which is blocking the traffic. So we would have to put a rule *.queue.core.windows.net in our firewall to allow the creation of new storage accounts (as we don't know all the storage account names that will be created in the future, but of course this is not desired).
Steps to Reproduce
No response
Important Factoids
No response
References
No response
The text was updated successfully, but these errors were encountered: