import * as cdk from "aws-cdk-lib"; import { Match, Template } from "aws-cdk-lib/assertions"; import * as fs from "node:fs"; import * as path from "node:path"; import { FileShareStack } from "../lib/file-share-stack"; const context = JSON.parse( fs.readFileSync(path.join(__dirname, "..", "cdk.context.json"), "utf8"), ) as Record; const app = new cdk.App({ context }); const stack = new FileShareStack(app, "TestFileShare", { env: { account: "328440206208", region: "us-east-1" }, }); const template = Template.fromStack(stack); describe("FileShareStack security group", () => { it("allows SMB, FileBrowser, and SFTP from the office VPN", () => { template.hasResourceProperties("AWS::EC2::SecurityGroup", { GroupName: "file-share", SecurityGroupIngress: Match.arrayWith([ Match.objectLike({ CidrIp: "10.10.0.0/16", FromPort: 445, ToPort: 445, IpProtocol: "tcp", }), Match.objectLike({ CidrIp: "10.10.0.0/16", FromPort: 8080, ToPort: 8080, IpProtocol: "tcp", }), Match.objectLike({ CidrIp: "10.10.0.0/16", FromPort: 22, ToPort: 22, IpProtocol: "tcp", }), ]), }); }); it("allows SMB and FileBrowser from the VPC CIDR", () => { template.hasResourceProperties("AWS::EC2::SecurityGroup", { SecurityGroupIngress: Match.arrayWith([ Match.objectLike({ CidrIp: "10.20.0.0/16", FromPort: 445, ToPort: 445, IpProtocol: "tcp", }), Match.objectLike({ CidrIp: "10.20.0.0/16", FromPort: 8080, ToPort: 8080, IpProtocol: "tcp", }), ]), }); }); }); describe("FileShareStack instance IAM", () => { it("attaches AmazonSSMManagedInstanceCore to the instance role", () => { template.hasResourceProperties("AWS::IAM::Role", { RoleName: "file-share-instance", ManagedPolicyArns: Match.arrayWith([ Match.objectLike({ "Fn::Join": Match.arrayWith([ Match.arrayWith([ Match.stringLikeRegexp("AmazonSSMManagedInstanceCore"), ]), ]), }), ]), }); }); it("scopes Secrets Manager GetSecretValue to file-share/*", () => { template.hasResourceProperties("AWS::IAM::Policy", { PolicyDocument: { Statement: Match.arrayWith([ Match.objectLike({ Action: "secretsmanager:GetSecretValue", Effect: "Allow", Resource: "arn:aws:secretsmanager:us-east-1:328440206208:secret:file-share/*", }), ]), }, }); }); }); describe("FileShareStack instance", () => { it("uses t4g.small with an encrypted root volume", () => { template.hasResourceProperties("AWS::EC2::Instance", { InstanceType: "t4g.small", BlockDeviceMappings: Match.arrayWith([ Match.objectLike({ DeviceName: "/dev/xvda", Ebs: Match.objectLike({ Encrypted: true, VolumeType: "gp3", }), }), ]), }); }); }); describe("FileShareStack DLM and data volume", () => { it("enables the nightly snapshot lifecycle policy", () => { template.hasResourceProperties("AWS::DLM::LifecyclePolicy", { State: "ENABLED", Description: "Nightly EBS snapshots for file share data volume", }); }); it("attaches the imported data volume by ID", () => { template.hasResourceProperties("AWS::EC2::VolumeAttachment", { VolumeId: "vol-04d951cccacc435b5", Device: "/dev/xvdf", }); }); });