DataBiosphere / azul

Metadata indexer and query service used for AnVIL, HCA, LungMAP, and CGP
Apache License 2.0
6 stars 2 forks source link

EBS default encryption should be enabled #4704

Open dsotirho-ucsc opened 1 year ago

dsotirho-ucsc commented 1 year ago
{
    "GeneratorIds": [
        "aws-foundational-security-best-practices/v/1.0.0/EC2.7"
    ]
}

https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-standards-fsbp-controls.html#fsbp-ec2-7


hannes-ucsc commented 1 year ago

@danielsotirhos, could be a dupe of #4792. Please outline the difference or merge into that ticket and close this one. Be sure to not close this prematurely. You've got to be 100% sure.

Update: The ticket Iinked to above is definitely not a duplicate. Maybe I fat-fingered the number.

hannes-ucsc commented 1 year ago

This is easy. It just enables a requirement in the account so that volumes can only be attached to an instance if the volume is encrypted. The main work is encrypting volumes and snapshots (#4702).

hannes-ucsc commented 5 months ago

This is about enabling EBS encryption by default in the AWS account.

See https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/ebs_encryption_by_default