cloudposse / terraform-aws-security-hub Goto Github PK
View Code? Open in Web Editor NEWTerraform module to provision AWS Security Hub
Home Page: https://cloudposse.com/accelerate
License: Apache License 2.0
Terraform module to provision AWS Security Hub
Home Page: https://cloudposse.com/accelerate
License: Apache License 2.0
It woud be nice to pass down to eventbridge more configuration e.g. filtering by Severity Level to avoid sending Informational or Low findings to SNS. It can be additional input or maybe add possibility to input the whole JSON object.
I would like to send specific severity Findings to SNS.
I want to reduce noise on the slack channel. See only Critical & High findings. Add later low level.
Pass down as input entire JSON object to eventbridge
cloudwatch_event_rule_pattern_detail_type
No response
No response
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
These problems occurred while renovating this repository. View logs.
These updates have been manually edited so Renovate will no longer make changes. To discard all commits and start over, click on a checkbox.
eventbridge.tf
cloudposse/label/null 0.25.0
cloudposse/kms-key/aws 0.12.1
cloudposse/label/null 0.25.0
cloudposse/sns-topic/aws 0.21.0
modules/control-disablements/versions.tf
aws >= 2
hashicorp/terraform >= 1.0
versions.tf
aws >= 2
hashicorp/terraform >= 1.0
Have a question? Please checkout our Slack Community or visit our Slack Archive.
When deploying in to China region the 'partition' in the ARN is aws-cn
, where are the standard partition in only aws
.
This module contains a hard-coded partition of aws
for the root IAM ARN in the KMS Key Policy.
This causes the deployment to fail with the error that the Principle does not exist.
The KME key policy should deploy without issue and reference an ARN that is in the same aws partition.
Such a change is required in order to be able to deploy into China
The data source 'aws_partition' should be used to dynamically generate the partition portion of the ARN for seamless use.
A parameter could be added that is either directly fed into the ARN or used in a lookup table first.
I'm creating a pull request with this feature soon
Have a question? Please checkout our Slack Community or visit our Slack Archive.
A toggle should be provided that is used on the delegated administrator account that activates AWS Organization Auto-enable feature for Security Hub. Thus all new accounts have Security Hub automatically enabled and send data to the delegated admin account.
A single deployment of this module in the security account during the early stages of the landing zone creation should be sufficient to manage all accounts in the org via that security account.
The Security Hub delegated admin account is able to see and control the Security Hub deployment of other accounts in the AWS Organization.
A single toggle should be set to true on the delegated admin account and then there is no need for this module to be deployed in any other account.
Users can manually enable this feature via the console.
I'm creating a pull request with the implementation soon.
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.