Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[WIP] - [NA-000] - tfsec fixes and ignores #171

Merged
merged 14 commits into from
Sep 7, 2022
Merged

Conversation

francardoso93
Copy link
Collaborator

@francardoso93 francardoso93 commented Sep 5, 2022

  • IAM policies
  • Bucket visibility, logging and versioning
  • ECR Image Immutability
  • EC2 IMDS v2 (tokens required)

@francardoso93
Copy link
Collaborator Author

Opened issue for a better experience with tag immutability
hashicorp/terraform-provider-aws#26658

@francardoso93
Copy link
Collaborator Author

How IMDS works and why it's important to secure it:
https://www.cloudyali.io/blogs/understanding-instance-metadata-service-imds

@francardoso93 francardoso93 marked this pull request as ready for review September 6, 2022 20:26
@francardoso93 francardoso93 requested a review from blucas September 6, 2022 20:26
Copy link
Contributor

@blucas blucas left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approved. Minor comments but nothing that would stop this from being merged.

terraspace/app/stacks/bucket-mirror/main.tf Show resolved Hide resolved
terraspace/app/stacks/event/secrets.tf Outdated Show resolved Hide resolved
terraspace/app/stacks/publishing/main.tf Show resolved Hide resolved
terraspace/app/stacks/shared/main.tf Outdated Show resolved Hide resolved
@francardoso93 francardoso93 merged commit 6e570aa into main Sep 7, 2022
@francardoso93 francardoso93 deleted the tfsec-iam-policies branch September 7, 2022 14:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants