Coalfire-CF / terraform-aws-account-setup

Coalfire AWS Account Setup Terraform Module
https://coalfire.com/opensource
MIT License
2 stars 1 forks source link

Packer & EBS KMS IAM Updates #35

Open herman-wong-cf opened 4 days ago

herman-wong-cf commented 4 days ago

Packer

EBS KMS Key Policy

github-actions[bot] commented 4 days ago

Checkov Scan Results 📖:

File Check ID Description Resource Checkov Result
/kms.tf CKV_AWS_356 Ensure no IAM policies documents allow "*" as a statement's resource for restrictable actions aws_iam_policy_document.dynamo_key FAILED
/kms.tf CKV_AWS_356 Ensure no IAM policies documents allow "*" as a statement's resource for restrictable actions aws_iam_policy_document.ebs_key FAILED
/kms.tf CKV_AWS_356 Ensure no IAM policies documents allow "*" as a statement's resource for restrictable actions aws_iam_policy_document.s3_key FAILED
/kms.tf CKV_AWS_356 Ensure no IAM policies documents allow "*" as a statement's resource for restrictable actions aws_iam_policy_document.sns_key FAILED
/kms.tf CKV_AWS_356 Ensure no IAM policies documents allow "*" as a statement's resource for restrictable actions aws_iam_policy_document.secrets_manager_key FAILED
/kms.tf CKV_AWS_356 Ensure no IAM policies documents allow "*" as a statement's resource for restrictable actions aws_iam_policy_document.cloudwatch_key FAILED
/kms.tf CKV_AWS_356 Ensure no IAM policies documents allow "*" as a statement's resource for restrictable actions aws_iam_policy_document.config_key FAILED

Please review the above report. ⚠️