Ensure deployment slot is integrated with a virtual network
Description
Integrate function app deployment slots with a virtual network to enable access to resources in or through a non-internet-routable virtual network.
This recommendation applies to function apps using the Premium or Dedicated (App Service) plans, which support deployment slots and virtual networking.
Rationale
Integrate function app deployment slots with a virtual network for increased security and control.
Impact
Additional configuration may be required to ensure that traffic is routed properly.
Audit Procedure
Using Azure Portal
- Go to
App ServicesorFunction App. - Click the name of a function app.
- Under
Deployment, clickDeployment slots. - Click the name of a deployment slot.
- Under
Settings, clickNetworking. - Under
Outbound traffic configuration, next toVirtual network integration, ensure that a virtual network and subnet name are displayed. - Repeat steps 1-6 for each function app and deployment slot.
Using Azure CLI
Run the following command to list function apps:
az functionapp list
For each function app, run the following command to list deployment slots:
az functionapp deployment slot list --resource-group <resource-group-name> --name <function-app-name>
For each deployment slot, ensure that virtualNetworkSubnetId is set to a virtual network subnet ID.
Expected Result
The virtualNetworkSubnetId property should be set to a valid virtual network subnet ID.
Remediation
Using Azure Portal
- Go to
App ServicesorFunction App. - Click the name of a function app.
- Under
Deployment, clickDeployment slots. - Click the name of a deployment slot.
- Under
Settings, clickNetworking. - Under
Outbound traffic configuration, next toVirtual network integration, clickNot configured. - Click
Add virtual network integration. - Select an existing App Service Plan connection, or select
New connectionand select a subscription, virtual network, and subnet. - Click
Connect. - Repeat steps 1-9 for each function app and deployment slot requiring remediation.
Default Value
By default, virtual network integration is not configured.
References
- https://learn.microsoft.com/en-us/azure/azure-functions/functions-networking-options
- https://learn.microsoft.com/en-us/azure/app-service/overview-vnet-integration
- https://learn.microsoft.com/en-us/azure/app-service/configure-vnet-integration-enable
- https://learn.microsoft.com/en-us/cli/azure/functionapp
Profile
Level 1 | Automated