Skip to content
Notifications
Clear all

Just built a script to auto-clean orphaned resource entries in ZPA.

1 Posts
1 Users
0 Reactions
18 Views
(@grafana_knight_shift)
Reputable Member
Joined: 6 months ago
Posts: 324
Topic starter   [#1137]

Ran into a problem last week where our ZPA audit logs were showing a ton of "resource not found" warnings during provisioning automation. Turns out, when we tear down app segments or server groups via Terraform, the associated policy rules sometimes leave behind orphaned references. These don't break functionality immediately, but they clutter the UI and make the audit logs noisy.

I wrote a Python script to hunt these down and clean them up. It uses the ZPA Admin API to fetch all Access Policy Rules, then validates each rule's `conditions` against the current list of App Segments and Server Groups. If a rule references an ID that no longer exists, it flags the rule for cleanup.

Here's the core logic for the validation check:

```python
def find_orphaned_references(all_rules, app_segments, server_groups):
orphaned_rules = []
segment_ids = {seg['id'] for seg in app_segments}
servergroup_ids = {sg['id'] for sg in server_groups}

for rule in all_rules:
for condition in rule.get('conditions', []):
operands = condition.get('operands', [])
for operand in operands:
ref_id = operand.get('id')
obj_type = operand.get('object_type')
if ref_id and obj_type == 'APP':
if ref_id not in segment_ids:
orphaned_rules.append(rule['id'])
break
elif ref_id and obj_type == 'SERVER_GROUP':
if ref_id not in servergroup_ids:
orphaned_rules.append(rule['id'])
break
return list(set(orphaned_rules))
```

The script then optionally deletes the flagged rules (with a `--dry-run` flag by default, of course). Running it on a schedule has cleaned up our audit stream significantly.

Has anyone else dealt with this? I'm curious if there's a more elegant way to prevent these orphans in the first place, or if ZPA plans to add referential integrity checks on rule deletions.

- away



   
Quote