chore(iam): add Checkov skip comments for HCP IAM documents

Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates,
exec boundary DescribeLogGroups star, and the drop-uploader user policy.
This commit is contained in:
Adam Moussa 2026-09-16 16:23:22 -04:00
parent dc65496a44
commit dd933f9460
No known key found for this signature in database
4 changed files with 6 additions and 0 deletions

View file

@ -19,6 +19,7 @@ resource "aws_iam_role" "dlm" {
}
data "aws_iam_policy_document" "dlm" {
# checkov:skip=CKV_AWS_111: DLM CreateSnapshot/Describe* require Resource=*. Role is boundary-attached and limited to the tagged Grafana volume.
statement {
sid = "DlmSnapshots"
effect = "Allow"

View file

@ -587,6 +587,7 @@ data "aws_iam_policy_document" "hcptf_apply_data" {
# Split from hcptf_apply_services: IAM inline policies cap at 10240 bytes.
data "aws_iam_policy_document" "hcptf_apply_network" {
# checkov:skip=CKV_AWS_111: EC2/ELB describe and tagged-create APIs require Resource=*. Writes use RequestTag/ResourceTag Project=apm-wo-analysis.
statement {
sid = "Ec2Describe"
effect = "Allow"

View file

@ -3,6 +3,9 @@
# edits to this document need the hcptf-bootstrap window.
data "aws_iam_policy_document" "exec_boundary" {
# checkov:skip=CKV_AWS_108: Boundary is an upper bound, not a grant. DescribeLogGroups requires Resource=*. Bucket, secret, DLQ, and Athena are ARN-prefixed.
# checkov:skip=CKV_AWS_109: Boundary is an upper bound, not a grant. No IAM permission-management actions.
# checkov:skip=CKV_AWS_111: AWS requires Resource=* for logs:DescribeLogGroups. Exports, secrets, DLQ, and Athena are ARN-pinned.
statement {
sid = "CloudWatchLogsWrite"
effect = "Allow"

View file

@ -125,6 +125,7 @@ data "aws_iam_policy_document" "drop_uploader" {
}
resource "aws_iam_user_policy" "drop_uploader" {
# checkov:skip=CKV_AWS_40: Drop-folder identity is an IAM user by design (local launchd profile). Policy is s3:PutObject on raw/* only.
name = "PutRawExportsOnly"
user = aws_iam_user.drop_uploader.name
policy = data.aws_iam_policy_document.drop_uploader.json