Skip to content

Upwind Scanner

We will be deploying the Upwind Scanner for Azure using the Upwind per subscription Terraform module: https://console.upwind.io/onboarding?newAccount=true&onboardingStepView=CONNECT_AZURE_SUBSCRIPTION . The per subscription method, rather than per tenant, has been selected to reduce difficulties in deploying this in all customer tenants.

The scanner will report to Upwind on activity across the network as well as scan VMs to look for software with known CVEs. These details can be seen here: https://console.upwind.io/inventory?mainPageTab=Images%20%26%20CI%2FCD&filters=scannedImage=Yes,cloudProvider=AZURE

The scanner is deployed via the repo: https://github.com/rhapsody-health/raas-azure-terraform-upwind . This is deployed as part of the standard Terraform v2 deployment.

Upwind Sensor

We will not be deploying the Upwind Sensor, this comes from our personal experience, as well as the experiences of the AWS RaaS, EMPI, and CaaS teams. The Sensor has a tendency to cause outages by either using up all of the vm resources, between the teams, we’ve seen disk io exhaustion, memory exhaustion, and process locking.

For machines where the sensor has been deployed, it will need to be removed.