mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-10-02 01:23:13 +00:00
chore(iam): add Checkov skip comments for HCP IAM documents
Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates, exec boundary DescribeLogGroups star, and the drop-uploader user policy.
This commit is contained in:
parent
dc65496a44
commit
dd933f9460
4 changed files with 6 additions and 0 deletions
|
|
@ -19,6 +19,7 @@ resource "aws_iam_role" "dlm" {
|
|||
}
|
||||
|
||||
data "aws_iam_policy_document" "dlm" {
|
||||
# checkov:skip=CKV_AWS_111: DLM CreateSnapshot/Describe* require Resource=*. Role is boundary-attached and limited to the tagged Grafana volume.
|
||||
statement {
|
||||
sid = "DlmSnapshots"
|
||||
effect = "Allow"
|
||||
|
|
|
|||
|
|
@ -587,6 +587,7 @@ data "aws_iam_policy_document" "hcptf_apply_data" {
|
|||
|
||||
# Split from hcptf_apply_services: IAM inline policies cap at 10240 bytes.
|
||||
data "aws_iam_policy_document" "hcptf_apply_network" {
|
||||
# checkov:skip=CKV_AWS_111: EC2/ELB describe and tagged-create APIs require Resource=*. Writes use RequestTag/ResourceTag Project=apm-wo-analysis.
|
||||
statement {
|
||||
sid = "Ec2Describe"
|
||||
effect = "Allow"
|
||||
|
|
|
|||
|
|
@ -3,6 +3,9 @@
|
|||
# edits to this document need the hcptf-bootstrap window.
|
||||
|
||||
data "aws_iam_policy_document" "exec_boundary" {
|
||||
# checkov:skip=CKV_AWS_108: Boundary is an upper bound, not a grant. DescribeLogGroups requires Resource=*. Bucket, secret, DLQ, and Athena are ARN-prefixed.
|
||||
# checkov:skip=CKV_AWS_109: Boundary is an upper bound, not a grant. No IAM permission-management actions.
|
||||
# checkov:skip=CKV_AWS_111: AWS requires Resource=* for logs:DescribeLogGroups. Exports, secrets, DLQ, and Athena are ARN-pinned.
|
||||
statement {
|
||||
sid = "CloudWatchLogsWrite"
|
||||
effect = "Allow"
|
||||
|
|
|
|||
|
|
@ -125,6 +125,7 @@ data "aws_iam_policy_document" "drop_uploader" {
|
|||
}
|
||||
|
||||
resource "aws_iam_user_policy" "drop_uploader" {
|
||||
# checkov:skip=CKV_AWS_40: Drop-folder identity is an IAM user by design (local launchd profile). Policy is s3:PutObject on raw/* only.
|
||||
name = "PutRawExportsOnly"
|
||||
user = aws_iam_user.drop_uploader.name
|
||||
policy = data.aws_iam_policy_document.drop_uploader.json
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue