mirror of
https://github.com/storytold/terraform-aws-observability-accelerator.git
synced 2026-10-09 00:09:43 +00:00
40 lines
1.3 KiB
JSON
40 lines
1.3 KiB
JSON
{
|
|
"checks": [
|
|
{
|
|
"code": "CUS001",
|
|
"description": "Check to IMDSv2 is required on EC2 instances created by this Launch Template",
|
|
"impact": "Instance metadata service can be interacted with freely",
|
|
"resolution": "Enable HTTP token requirement for IMDS",
|
|
"requiredTypes": [
|
|
"resource"
|
|
],
|
|
"requiredLabels": [
|
|
"aws_launch_template"
|
|
],
|
|
"severity": "CRITICAL",
|
|
"matchSpec": {
|
|
"action": "isPresent",
|
|
"name": "metadata_options",
|
|
"subMatch": {
|
|
"action": "and",
|
|
"predicateMatchSpec": [
|
|
{
|
|
"action": "equals",
|
|
"name": "http_tokens",
|
|
"value": "required"
|
|
|
|
}
|
|
]
|
|
}
|
|
},
|
|
|
|
"errorMessage": "is missing `metadata_options` block - it is required with `http_tokens` set to `required` to make Instance Metadata Service more secure.",
|
|
"relatedLinks": [
|
|
"https://tfsec.dev/docs/aws/ec2/enforce-http-token-imds#aws/ec2",
|
|
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_template#metadata-options",
|
|
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
|
|
]
|
|
}
|
|
]
|
|
}
|