stelligent / cfn_nag

Linting tool for CloudFormation templates
MIT License
1.26k stars 212 forks source link

F27 on StorageEncrypted for Replica DB's #624

Open gerrievisagie opened 8 months ago

gerrievisagie commented 8 months ago

When SourceDBInstanceIdentifier is set for AWS::RDS::DBInstance (a replica in a cluster), cf-nag (latest version) alerts with

FAIL F27
Resource: [our replica name>]
Line Numbers: [the line number]
RDS DBInstance should have StorageEncrypted enabled

see aws-resource-rds-dbinstance

This was also previously addressed in 184