Gomboc Fix for #20 - tf-test#21
Conversation
|
|
||
| resource "aws_dynamodb_table" "test_table_a" { | ||
|
|
||
| deletion_protection_enabled = true |
There was a problem hiding this comment.
l.9Recommended applying Deletion Protection:- Gomboc Best Practices CIS Critical Security Controls v8.1 (AWS)
- CIS Critical Security Controls v8.1
Leave feedback (ref: d464e376604756a617e8baccc5cc483f0de93c9d80f2d39c7ee5e0a0d2572966)
| resource "aws_dynamodb_table" "test_table_a" { | ||
|
|
||
| deletion_protection_enabled = true | ||
| billing_mode = "PAY_PER_REQUEST" |
There was a problem hiding this comment.
l.10Recommended applying On-Demand Capacity:- Gomboc Best Practices CIS Critical Security Controls v8.1 (AWS)
Leave feedback (ref: 2611ff7b5b3eae44bcc9796c834cd2d2c7935c9e97dd43e531cea620e981feb1)
|
|
||
| deletion_protection_enabled = true | ||
| billing_mode = "PAY_PER_REQUEST" | ||
| tags = "null" |
There was a problem hiding this comment.
l.11Recommended applying Resource Tags:- Gomboc Best Practices CIS Critical Security Controls v8.1 (AWS)
- CIS Critical Security Controls v8.1
Leave feedback (ref: 411f3e36ed53e52f7e3cbaf9072767d6262fc37d250785221664e8503f0fb156)
| billing_mode = "PAY_PER_REQUEST" | ||
| tags = "null" | ||
| server_side_encryption { | ||
| enabled = false |
There was a problem hiding this comment.
l.13Recommended applying Encryption At-Rest with Bespoke Service Implementation:- Gomboc Best Practices CIS Critical Security Controls v8.1 (AWS)
Leave feedback (ref: b0f7e9f4458edaed4cd2552dd0d3c1f1f2afaf3a233e43f01c1c0ba789462c97)
|
|
||
| resource "aws_lambda_function" "myfunction" { | ||
| tracing_config { | ||
| mode = "Active" |
There was a problem hiding this comment.
l.19Recommended applying Request Tracing:- Gomboc Best Practices CIS Critical Security Controls v8.1 (AWS)
- CIS Critical Security Controls v8.1
Leave feedback (ref: 62765aecbde07930d8afdc5696a332e40096397147c55134f82a87707ef492b7)
|
|
||
| resource "aws_appsync_graphql_api" "test_api" { | ||
| authentication_type = "API_KEY" | ||
| xray_enabled = true |
There was a problem hiding this comment.
l.25Recommended applying Request Tracing:- Gomboc Best Practices CIS Critical Security Controls v8.1 (AWS)
- CIS Critical Security Controls v8.1
Leave feedback (ref: af879331249c525901eab405f59e69d22c6054f0f9210c45442068029cac615e)
| resource "aws_keyspaces_table" "mykeyspacestable" { | ||
| } | ||
| encryption_specification { | ||
| type = "AWS_OWNED_KMS_KEY" |
There was a problem hiding this comment.
l.30Recommended applying Encryption At-Rest with Provider Managed Key:- Gomboc Best Practices CIS Critical Security Controls v8.1 (AWS)
Leave feedback (ref: 836e766e32572c9b826b7b6eb5f08575aaa011e2acd90073135728da07e46486)
This fix was produced in response to #20 on the following target:
These recommendations come from the following benchmarks