✨ New Policies
b54d258
- added non compatible policies (see the list in the commit message)5e4393b
- added a number of terraform files for policies (see the list in the commit message)3e9aed2
- added policy ecc-aws-807-unused_efs_filesystem4d48faf
- added policy ecc-aws-1005-ebs_volumes_too_old_snapshots737f6e8
- added policy ecc-aws-526-waf_global_rulegroup_not_empty075a903
- added policy ecc-aws-529-ebs_attached_volume_delete_on_termination_enablede7208b3
- added policy ecc-aws-543-cloudfront_realtime_logging_enabledad35d4c
- added policy ecc-aws-546-kinesis_streams_retention_period_set_correctly5810523
- added policy ecc-aws-548-ebs_volumes_are_of_type_gp3_instead_of_gp29f014d6
- added policy ecc-aws-547-rds_instance_generation11ef8ce
- added policy ecc-aws-552-dynamodb_tables_unusedf0dc7d1
- added policy ecc-aws-553-unused_clbcbe41ca
- added policy ecc-aws-560-unused_sns_topic5254033
- added policy ecc-aws-571-stopped_rds_instances_removed738f42b
- added policy ecc-aws-572-disabled_kms_keys_removedbeb24ca
- added policy ecc-aws-573-unused_nat_gatewaycd5cc3f
- added policy ecc-aws-575-ebs_volumes_attached_to_stopped_ec2_instancesbb3e948
- added policy ecc-aws-576-ec2_instance_dedicated_tenancy0a9ea6d
- added policy ecc-aws-577-reserved_ec2_instance_payment_failed2115d78
- added policy ecc-aws-578-reserved_ec2_instance_payment_pending6a6db51
- added policy ecc-aws-579-reserved_ec2_instance_recent_purchasesdeffe48
- added policy ecc-aws-580-reserved_instance_lease_expiration_in_30_days6edbb11
- added policy ecc-aws-581-reserved_instance_lease_expiration_in_7_daysf7c3aa5
- added policy ecc-aws-582-ecs_service_placement_strategy26ebbec
- added policy ecc-aws-610-idle_ec2_instance27c142e
- added policy ecc-aws-594-underutilized_rds_instance_storage3f062a3
- added policy ecc-aws-614-idle_rds_instance9dabefa
- added policy ecc-aws-604-efs_without_lifecycle_management537e1fe
- added policy ecc-aws-601-auto_scaling_group_statically_configured96f4899
- added policy ecc-aws-067-unauthorized_api_calls_alarm_existse0902d1
- added policy ecc-aws-493-ecs_container_insights_enabled1e356f7
- added policy ecc-aws-376-api_gateway_http_api_and_websocket_api_logs_not_enableda68480d
- added policy ecc-aws-872-access_to_cloudshell_restrictedf96d13e
- added policy ecc-aws-549-ec2_instance_previous_generation6d7b1f0
- added policy ecc-aws-583-elb_classic_metadatacff94e1
- added policy ecc-aws-570-ebs_volumes_are_of_type_gp3_instead_of_io15c119e8
- added policy ecc-aws-590-rds_general_purpose_ssd_storage_typeee0c927
- added policy ecc-aws-598-redshift_instance_generation113c7d8
- added policy ecc-aws-566-opensearch_auto_tune_enabled4471865
- added policy ecc-aws-602-cloudwatch_logs_with_no_log_retention_period203dd37
- added policy ecc-aws-586-elasticsearch_general_purpose_ssd_volume6ec8467
- added policy ecc-aws-630-ec2_ami_not_in_use22888bc
- added policy ecc-aws-591-reserved_rds_instance_payment_failed4267de2
- added policy ecc-aws-569-asg_propagate_tags_to_ec2_instances3477e96
- added policy ecc-aws-077-sign_in_without_mfa_alarm_exist4c9c06e
- added policy ecc-aws-080-cloudtrail_configuration_changes_alarm_existse49896e
- added policy ecc-aws-079-iam_policy_changes_alarm_exist4c25919
- added policy ecc-aws-145-organizations_changes_alarm_exists3658a3b
- added policy ecc-aws-094-s3_bucket_policy_changes_alarm_exists743ef15
- added policy ecc-aws-082-cmk_key_disabling_or_deletion_alarm_exists710bdbb
- added policy ecc-aws-095-aws_config_configuration_changes_alarm_exists1b7779f
- added policy ecc-aws-081-console_auth_failure_alarm_exists0d01684
- added policy ecc-aws-097-network_access_control_lists_changes_alarm_existse664fca
- added policy ecc-aws-100-vpc_changes_alarm_exists4e3e5ff
- added policy ecc-aws-096-security_group_changes_alarm_exists8ce9cd5
- added policy ecc-aws-078-root_usage_alarm_existscc9c290
- added policy ecc-aws-098-network_gateways_changes_alarm_existsbac0064
- added policy ecc-aws-099-route_table_changes_alarm_existsdfd9278
- added policy ecc-aws-595-reserved_redshift_node_payment_failed897fbc2
- added policy ecc-aws-596-reserved_redshift_node_payment_pending33a6486
- added policy ecc-aws-587-elasticsearch_reserved_instance_payment_failed004e5ea
- added policy ecc-aws-588-elasticsearch_reserved_instance_payment_pending7ac3dee
- added policy ecc-aws-592-reserved_rds_instance_payment_pending092f994
- added policy ecc-aws-589-elasticsearch_reserved_instance_recent_purchasesa47b972
- added policy ecc-aws-593-reserved_rds_instance_recent_purchasesce87620
- added policy ecc-aws-597-reserved_redshift_node_recent_purchases1f3b9fc
- added policy ecc-aws-218-secrets_manager_rotation_enabled7428c6c
- added policy ecc-aws-219-secrets_manager_successful_rotation_checkefd83c8
- added policy ecc-aws-220-secrets_manager_unused_secret
🔧 Updates
84be271
- re-index all policies1fb3342
- added index(comment) to all rules0b6311c
- updated policy ecc-aws-548-ebs_volumes_are_of_type_gp3_instead_of_gp2ea93aa3
- updated comment field for all policiescd33519
- updated policy 04363631e0
- updated policy 499ee05e81
- updated policies 040, 283, 310, 434, 461, 508a638744
- split permissions into two files0dd9539
- updated a number of policies (see the list in the commit message)a1f8c6a
- updated policies 272, 283, 310, 461, 497, 508da86c3c
- update iam/All-permission_*.json files6f9805f
- update terraforms 001-288 to provider version 50bba04a
- update terraforms 289-347 to provider version 5169df56
- update terraform to provider version 5 for policies 348, 349, 366, 377, 378, 379, 458, 462, 469, 471, 472, 489, 490, 517, 5315575d28
- update terraform to provider version 5 for policies 386, 387, 388, 374, 491, 492, 493, 494, 520, 521, 365, 510, 506, 505, 5344d0821b
- update terraforms to provider version 5 for a number of policies (see the list in the commit message)750679f
- update terraforms to provider version 5 for a number of policies (see the list in the commit message)989598f
- update iam permissions for policies 396 and 476
🩹 Policy Fixes
595a1b0
- fixed policy 2980047710
- fixed policy ecc-aws-258-emr_at_rest_and_in_transit_encryption_enabledb2bd85e
- fixed policy 258
🩹 Terraform Fixes
5dd197c
- fixed a number of terraform files for policies (see the list in the commit message)ca732c4
- fixed terraform for policy ecc-aws-258-emr_at_rest_and_in_transit_encryption_enabled3910835
- fixed terraform for policy 2585efb4ac
- fixed terraforms for policies 040, 283, 310, 434, 461001a77f
- fixed terraform for policies 052, 127, 231, 232, 233, 234, 235, 236, 237, 238, 239, 240, 241, 242, 243, 244, 245, 304, 305, 306, 307, 362, 394, 425, 444, 446, 447, 448, 5083608353
- fixed terraform for policy 186f333850
- fix terraform for policies 383, 384, 385, 474, 475, 476, 479, 488, 513, 514, 529, 552, 503, 504, 461
🩹 Test Fixes
a9870e4
- fixed tests for policy 490e54a209
- fixed tests for policy 111e3ad0f1
- fixed tests for policy 2585e27957
- fixed tests for policies 040, 283, 310, 434, 461, 508
📝 Documentation Changes
55363ec
- added README.md for non-compatible-policies
➖ Deletions
205475a
- delete terraform for policy 016
📂 Other Changes
8d09867
- Added issue templates9d82bcd
- Added Public Policies963f7d3
- Added Terraform17fbbb0
- Added Tests2dd9819
- github workflow addede9c1a9f
- update_ci15e2d9f
- fix tests2ab7151
- Added CONTRIBUTING.md11dd809
- Updated CONTRIBUTING.md726b552
- Update CONTRIBUTING.md6cf9e24
- Merge branch 'pipeline' into public_rules5986db1
- upload iam/All-permissions.json filef1aae25
- update workflow file0f78bc8
- Create changelog actionf17b570
- new_rules_from_sprint9aea0d8
- Merge pull request epam#4 from epam/new_rules_from_sprint
new_rules_from_sprint
New rules
Added issue templates
Public rules