Skip to content

updated #1

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 28 commits into from
Feb 22, 2021
Merged

updated #1

merged 28 commits into from
Feb 22, 2021

Conversation

anishmoktan
Copy link
Owner

No description provided.

ja5onhughe5 and others added 28 commits February 12, 2021 19:18
Added "filter_attribute_less_than_equal_to_value" and "filter_attribute_greater_than_equal_to_value" to be used with the restrict SSH and RDP policies that I created.
Created new 3rd Gen policy for restricting SSH with test mock. This has similar targeting as "terraform-foundational-policies-library/cis/aws/networking/aws-cis-4.1-networking-deny-public-ssh-acl-rules" but adds "read" and "no-op" to resource changes, loops through both the aws_security_group and the aws_security_group_rule resources, and provides greater detail of violations.
Created new 3rd Gen policy for restricting RDP with test mock. This has similar targeting as "terraform-foundational-policies-library/cis/aws/networking/aws-cis-4.2-networking-deny-public-rdp-acl-rules" but adds "read" and "no-op" to resource changes, loops through both the aws_security_group and the aws_security_group_rule resources, and provides greater detail of violations.
add restrict-sagemaker-notebooks.sentinel
Added restrict-ingress-sg-rule-ssh and
restrict-ingress-sg-rule-rdp policies to sentinel.hcl as advisory
…olicy

add restrict-s3-bucket-policies.sentinel policy
I added back messages saying what null value is supposed to be in the greater/less filters.
Two new policies restricting SSH and RDP for 0.0.0.0/0 for AWS SGs
…el-hcl

update sentinel.hcl files to add policies
improve policy-set example for script
…entinel-mocks

add Terraform code for two Sentinel policies
…ource

add restrict-resources-by-module-source.sentinel
add restrict-resources-by-module-source to sentinel.hcl
minor fixes for restrict-resources-by-module-source.sentinel
@anishmoktan anishmoktan merged commit f13bb7e into anishmoktan:master Feb 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants