mirror of
https://github.com/storytold/terraform-aws-observability-accelerator.git
synced 2026-10-09 00:09:43 +00:00
Initial commit
This commit is contained in:
committed by
Rodrigue Koffi
parent
eaee1ddedd
commit
0262a8a45d
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"checks": [
|
||||
{
|
||||
"code": "CUS002",
|
||||
"description": "Check to IMDSv2 is required on EC2 instances created by this Launch Template",
|
||||
"impact": "Instance metadata service can be interacted with freely",
|
||||
"resolution": "Enable HTTP token requirement for IMDS",
|
||||
"requiredTypes": [
|
||||
"resource"
|
||||
],
|
||||
"requiredLabels": [
|
||||
"aws_launch_configuration"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"matchSpec": {
|
||||
"action": "isPresent",
|
||||
"name": "metadata_options",
|
||||
"subMatch": {
|
||||
"action": "and",
|
||||
"predicateMatchSpec": [
|
||||
{
|
||||
"action": "equals",
|
||||
"name": "http_tokens",
|
||||
"value": "required"
|
||||
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
|
||||
"errorMessage": "is missing `metadata_options` block - it is required with `http_tokens` set to `required` to make Instance Metadata Service more secure.",
|
||||
"relatedLinks": [
|
||||
"https://tfsec.dev/docs/aws/ec2/enforce-http-token-imds#aws/ec2",
|
||||
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata-options",
|
||||
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,39 @@
|
||||
{
|
||||
"checks": [
|
||||
{
|
||||
"code": "CUS001",
|
||||
"description": "Check to IMDSv2 is required on EC2 instances created by this Launch Template",
|
||||
"impact": "Instance metadata service can be interacted with freely",
|
||||
"resolution": "Enable HTTP token requirement for IMDS",
|
||||
"requiredTypes": [
|
||||
"resource"
|
||||
],
|
||||
"requiredLabels": [
|
||||
"aws_launch_template"
|
||||
],
|
||||
"severity": "CRITICAL",
|
||||
"matchSpec": {
|
||||
"action": "isPresent",
|
||||
"name": "metadata_options",
|
||||
"subMatch": {
|
||||
"action": "and",
|
||||
"predicateMatchSpec": [
|
||||
{
|
||||
"action": "equals",
|
||||
"name": "http_tokens",
|
||||
"value": "required"
|
||||
|
||||
}
|
||||
]
|
||||
}
|
||||
},
|
||||
|
||||
"errorMessage": "is missing `metadata_options` block - it is required with `http_tokens` set to `required` to make Instance Metadata Service more secure.",
|
||||
"relatedLinks": [
|
||||
"https://tfsec.dev/docs/aws/ec2/enforce-http-token-imds#aws/ec2",
|
||||
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_template#metadata-options",
|
||||
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
{
|
||||
"checks": [
|
||||
{
|
||||
"code": "CUS003",
|
||||
"description": "Use `aws_launch_template` over `aws_launch_configuration",
|
||||
"impact": "Launch configurations are not capable of versions",
|
||||
"resolution": "Convert resource type and attributes to `aws_launch_template`",
|
||||
"requiredTypes": [
|
||||
"resource"
|
||||
],
|
||||
"requiredLabels": [
|
||||
"aws_launch_configuration"
|
||||
],
|
||||
"severity": "MEDIUM",
|
||||
"matchSpec": {
|
||||
"action": "notPresent",
|
||||
"name": "image_id"
|
||||
},
|
||||
|
||||
"errorMessage": "should be changed to `aws_launch_template` since the functionality is the same but templates can be versioned.",
|
||||
"relatedLinks": [
|
||||
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_template",
|
||||
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
{
|
||||
"checks": [
|
||||
{
|
||||
"code": "CUS005",
|
||||
"description": "Security group rules should be defined with `aws_security_group_rule` instead of embedded.",
|
||||
"impact": "Embedded security group rules can cause issues during configuration updates.",
|
||||
"resolution": "Move `egress` rules to `aws_security_group_rule` and attach to `aws_security_group`.",
|
||||
"requiredTypes": [
|
||||
"resource"
|
||||
],
|
||||
"requiredLabels": [
|
||||
"aws_security_group"
|
||||
],
|
||||
"severity": "MEDIUM",
|
||||
"matchSpec": {
|
||||
"action": "notPresent",
|
||||
"name": "egress"
|
||||
},
|
||||
|
||||
"errorMessage": "`egress` rules should be moved to `aws_security_group_rule` and attached to `aws_security_group` instead of embedded.",
|
||||
"relatedLinks": [
|
||||
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule",
|
||||
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
@@ -0,0 +1,27 @@
|
||||
{
|
||||
"checks": [
|
||||
{
|
||||
"code": "CUS004",
|
||||
"description": "Security group rules should be defined with `aws_security_group_rule` instead of embedded.",
|
||||
"impact": "Embedded security group rules can cause issues during configuration updates.",
|
||||
"resolution": "Move `ingress` rules to `aws_security_group_rule` and attach to `aws_security_group`.",
|
||||
"requiredTypes": [
|
||||
"resource"
|
||||
],
|
||||
"requiredLabels": [
|
||||
"aws_security_group"
|
||||
],
|
||||
"severity": "MEDIUM",
|
||||
"matchSpec": {
|
||||
"action": "notPresent",
|
||||
"name": "ingress"
|
||||
},
|
||||
|
||||
"errorMessage": "`ingress` rules should be moved to `aws_security_group_rule` and attached to `aws_security_group` instead of embedded.",
|
||||
"relatedLinks": [
|
||||
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule",
|
||||
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group"
|
||||
]
|
||||
}
|
||||
]
|
||||
}
|
||||
Reference in New Issue
Block a user