IaC

IaC documentation covering security, configuration, and resource inventory.

Browse 1,811 IaC documents on security risks, configuration checks, and resource inventory by platform and provider.

Overview

Browse by platform

TitleTarget
Ansible (226)ansible
Azure Resource Manager (42)azureresourcemanager
Buildah (1)buildah
CI/CD (4)cicd
CloudFormation (284)cloudformation
Common (1)common
Crossplane (18)crossplane
Docker Compose (21)dockercompose
Dockerfile (48)dockerfile
Google Deployment Manager (35)googledeploymentmanager
gRPC (1)grpc
Kubernetes (142)k8s
Knative (1)knative
OpenAPI (194)openapi
Pulumi (21)pulumi
Serverless Framework (10)serverlessfw
Terraform (762)terraform

All documentation

Platform Article
Ansible ALB listener accepts HTTP traffic
Ansible Review encryption of AMI EBS snapshots
Ansible AMI sharing targets need review
Ansible Review the exposure of an API Gateway REST API
Ansible Review CloudWatch log collection for API Gateway
Ansible Review authorization for an API Gateway REST API
Ansible Review certificate validation in Ansible API Gateway management
Ansible Review WAF protection for an API Gateway REST API
Ansible API Gateway X-Ray tracing is disabled
Ansible Review MFA protection when assuming AWS roles
Ansible Review traffic distribution for an Auto Scaling Group
Ansible Review RDS automatic minor upgrades
Ansible Review IAM user password-change permissions
Ansible AWS Batch job definition using privileged mode
Ansible RDS uses an expired or unsupported CA certificate
Ansible Review CloudFront distribution configuration
Ansible Expired SSL/TLS certificate
Ansible Review RSA certificate key strength
Ansible CloudFront logging settings need review
Ansible CloudFront minimum TLS version needs review
Ansible CloudFront WAF association needs review
Ansible CloudTrail log file integrity validation is disabled
Ansible No KMS key is specified for CloudTrail logs
Ansible CloudTrail trail logging is stopped
Ansible CloudTrail multi-Region logging is disabled
Ansible CloudTrail is not integrated with CloudWatch Logs
Ansible CloudTrail log-delivery notification topic is not configured
Ansible Review CloudWatch Logs retention
Ansible An in-use KMS key is disabled or pending deletion
Ansible Review rotation settings for customer-managed KMS keys
Ansible Review the CodeBuild artifact encryption key
Ansible Review AWS Config aggregation Region coverage
Ansible AWS Config configuration lacks an ENCRYPTED_VOLUMES rule
Ansible IAM trust policy external ID or MFA protections need review
Ansible RDS storage encryption settings need review
Ansible Security group inbound access scope needs review
Ansible Security group rule allows all IPv4 addresses
Ansible Security group rule allows all IPv4 or IPv6 addresses
Ansible EBS volume encryption settings need review
Ansible Security group ingress allows all IPv4 or IPv6 sources
Ansible EC2 instance has a public IP address
Ansible EC2 instance uses the default security group
Ansible Review EC2 default VPC use
Ansible Review EC2 EBS optimization settings
Ansible ECR repository permits image tag changes
Ansible ECR repository policy uses a wildcard principal
Ansible ECS service role permissions need review
Ansible Review ECS service deployment availability
Ansible ECS service assigns public IP addresses
Ansible Review the ECS task definition network mode
Ansible EFS encryption at rest settings need review
Ansible Review the EFS customer managed KMS key
Ansible Review EFS operational tags
Ansible Review ElastiCache ports and access controls
Ansible Review ElastiCache VPC subnet selection
Ansible Review HTTPS enforcement for an OpenSearch domain
Ansible Review the TLS security policy on an ELB listener
Ansible ELB listener security policy needs review
Ansible Possible AWS credential exposure in EC2 user data
Ansible Possible secret key in a Lambda task's aws_access_key field
Ansible HTTP port is open to the Internet
Ansible Review active IAM user access keys
Ansible Review IAM database authentication for RDS
Ansible Review IAM group membership
Ansible Review IAM password minimum length
Ansible IAM policies attached directly to a user
Ansible IAM policy allows all actions on all resources
Ansible Review wildcard principals in IAM policies
Ansible IAM policy uses wildcards for both actions and resources
Ansible Review account principals in IAM policies
Ansible Review EC2 instance metadata access protection
Ansible Review EC2 VPC subnet selection
Ansible Kinesis encryption settings need review
Ansible KMS key policy permissions need review
Ansible Review Lambda operational tags
Ansible Lambda active X-Ray tracing is not configured
Ansible Review allowed actions in a Lambda resource policy
Ansible Lambda permission uses a wildcard principal
Ansible EBS encryption in EC2 launch settings needs review
Ansible Review IAM password expiration policy
Ansible Review CloudFormation resource update protection
Ansible Review IAM password reuse prevention
Ansible Review API Gateway’s Lambda invocation scope
Ansible Security group exposes a port range to all addresses
Ansible RDS-linked subnet uses a /0 CIDR
Ansible RDS instance has public access enabled
Ansible Review RDS ports and access controls
Ansible Automated backups are disabled for an RDS instance
Ansible ElastiCache engine version and security requirements need review
Ansible Redshift encryption settings need review
Ansible Redshift configuration enables public access
Ansible Review Redshift default-port use
Ansible Port 3389 may be exposed to all IPv4 sources
Ansible Active IAM user access key needs review
Ansible Route 53 task has no record value
Ansible S3 bucket policy uses a wildcard principal
Ansible Public-read ACLs in S3
Ansible S3 ACL grants read access to every AWS account
Ansible S3 bucket policy with delete actions and a wildcard principal
Ansible Wildcard principals in S3 object-read policies
Ansible Wildcard principals in S3 listing policies
Ansible S3 bucket policy with Put actions and a wildcard principal
Ansible Review API diagnostic logging for the Ansible S3 task
Ansible S3 bucket policy with wildcard actions and principals
Ansible Legacy aws_s3 task specifies a public ACL
Ansible S3 CORS permissions need review
Ansible S3 bucket configuration requests removal of default encryption
Ansible S3 bucket versioning needs review
Ansible Review the CloudFront viewer TLS security policy
Ansible Security group ingress may allow excessive access
Ansible Security group exposes SSH too broadly
Ansible SES policy may grant excessive permissions
Ansible SNS topic policy has a wildcard or missing principal
Ansible Security group allows TCP 2383 from all IPv4 sources
Ansible SQS queue policy specifies Action '*'
Ansible SQS policy grants broad permissions to wildcard principals
Ansible SQS queue policy uses Principal '*'
Ansible Review encryption at rest for SQS messages
Ansible CloudFormation stack notifications are not configured
Ansible Review stack retention when deleting a StackSet
Ansible Review CloudFormation stack template inputs
Ansible Service ports allow all source addresses
Ansible Security group ingress allows all source addresses
Ansible Review encoded key material in user data
Ansible CloudFront viewer protocol policy allows HTTP
Ansible CloudFront viewer certificate settings need review
Ansible Review the Microsoft Entra administrator for Azure SQL
Ansible The Azure Container Registry admin account is enabled
Ansible AKS monitoring settings need review
Ansible Review AKS network policy settings
Ansible Kubernetes RBAC is disabled for AKS
Ansible Review resource locks for Azure Container Registry
Ansible Azure Linux VM allows SSH password authentication
Ansible Review Cosmos DB account IP access restrictions
Ansible Cosmos DB account tags are missing
Ansible Storage account may lack public network restrictions
Ansible Redis Cache firewall permits an excessive address range
Ansible Review Azure Key Vault soft-delete protection
Ansible PostgreSQL log retention needs review
Ansible Azure log profile omits activity export categories
Ansible TLS enforcement is disabled for Azure MySQL
Ansible PostgreSQL checkpoint logging is disabled
Ansible PostgreSQL connection logging is disabled
Ansible PostgreSQL disconnection logging is disabled
Ansible PostgreSQL duration logging needs review
Ansible PostgreSQL login-failure throttling is disabled
Ansible Storage account network rules may allow broad access
Ansible Redis Cache permits unencrypted connections
Ansible Redis firewall allows all IPv4 addresses
Ansible Review the Redis firewall address range
Ansible Azure role permits custom role creation
Ansible Review subnet NSG associations
Ansible Review access scope for service ports in Azure NSGs
Ansible Review Azure Activity Log retention
Ansible Azure SQL firewall rule covers the entire IPv4 range
Ansible Review the Ansible Azure authentication user
Ansible Review the Azure SQL administrator login name
Ansible TLS enforcement is disabled for Azure PostgreSQL
Ansible Azure Storage account does not require HTTPS
Ansible Review the minimum TLS setting for Azure Storage
Ansible Azure blob container allows anonymous reads
Ansible Review trusted-service exceptions for Azure Storage
Ansible Review broad Azure SQL firewall ranges
Ansible Review Azure VM network-interface configuration
Ansible Review WAF protection for Azure Application Gateway
Ansible Azure Web App permits HTTP access
Ansible Ansible enables the legacy allow_unsafe_lookups option
Ansible Ansible Galaxy server uses HTTP
Ansible Sensitive data exposure in Ansible default logging settings
Ansible Review Ansible’s default user-switching settings
Ansible BigQuery access for all authenticated users
Ansible Legacy client certificate authentication in GKE
Ansible Review Cloud DNS DNSSEC settings
Ansible Cloud SQL contained database authentication is enabled
Ansible Cross-database ownership chaining is enabled in Cloud SQL
Ansible Cloud Storage bucket public access needs review
Ansible Review Cloud Storage usage logging
Ansible Review Cloud Storage object versioning
Ansible GKE cluster labels are missing
Ansible Review GKE control plane authentication
Ansible Compute Engine instance has an external IP
Ansible Review GKE node image selection
Ansible Review Compute Engine disk encryption key management
Ansible Review Cloud DNS DNSSEC signing algorithms
Ansible Review legacy Basic authentication settings in GKE
Ansible GKE cluster configuration enables legacy ABAC
Ansible Review authorized networks for the GKE control plane
Ansible GKE nodes use the default service account
Ansible Review access allowed by GCP default firewall rules
Ansible Review GCP firewall port ranges
Ansible GCP firewall rule allows all ports
Ansible Review the minimum TLS version in a Compute SSL policy
Ansible Review subnet Private Google Access settings
Ansible Review GKE node pool auto-repair settings
Ansible Review Cloud KMS key rotation periods
Ansible Review GKE VPC-native networking settings
Ansible IP forwarding is enabled on a Compute Engine VM
Ansible Cloud SQL MySQL permits local file loading
Ansible Review network policy enforcement in GKE
Ansible Review GKE node auto-upgrade settings
Ansible OS Login is disabled on a VM instance
Ansible PostgreSQL checkpoint logging is disabled
Ansible PostgreSQL connection logging is disabled
Ansible Review PostgreSQL temporary-file logging coverage
Ansible Review PostgreSQL server log levels
Ansible Review PostgreSQL statement-duration logging thresholds
Ansible Review public access to GKE nodes and the control plane
Ansible VM instance allows project-wide SSH keys
Ansible GCP firewall allows unrestricted RDP access
Ansible Interactive serial console is enabled for a VM
Ansible Review Shielded VM protection settings
Ansible Review Cloud SQL automatic backups
Ansible Cloud SQL instance needs a network-access configuration review
Ansible Encrypting Cloud SQL database connections
Ansible GCP firewall allows SSH from all IPv4 addresses
Ansible GKE logging is disabled
Ansible GKE monitoring is disabled
Ansible Review permissions of a VM’s default service account
Ansible Review a VM’s Cloud API scopes and IAM permissions
Ansible HTTP communication in an Ansible task
Ansible Review Ansible file path resolution
Ansible Sensitive information exposed in Ansible logs
Ansible Check the intended execution of Ansible become settings
Ansible Ansible file creation with potentially unsafe permissions
Ansible Unpinned package versions
Ansible Review internet exposure of Ansible Tower
Azure Resource Manager Review Azure SQL account-administrator alert emails
Azure Resource Manager AKS network policies are not configured
Azure Resource Manager Review Kubernetes RBAC settings for an AKS cluster
Azure Resource Manager Review AKS Dashboard use
Azure Resource Manager AKS container log collection is disabled
Azure Resource Manager Review AKS API server access scope
Azure Resource Manager Review App Service authentication settings
Azure Resource Manager SSH password authentication is allowed on an Azure Linux VM
Azure Resource Manager Review Azure managed disk encryption requirements
Azure Resource Manager Azure Storage account allows broad network access
Azure Resource Manager Review Defender for Cloud email notifications
Azure Resource Manager secureString parameter has a hardcoded default
Azure Resource Manager Azure Key Vault recovery protection needs review
Azure Resource Manager Review Azure Log Profile export categories
Azure Resource Manager Review TLS enforcement for Azure MySQL
Azure Resource Manager Azure NSG allows broad RDP access
Azure Resource Manager Azure NSG does not restrict SSH sources
Azure Resource Manager Review Azure security contact phone details
Azure Resource Manager Review connection throttling for Azure PostgreSQL
Azure Resource Manager Azure PostgreSQL checkpoint logging is disabled
Azure Resource Manager Azure PostgreSQL connection logging is disabled
Azure Resource Manager Review TLS enforcement for Azure PostgreSQL
Azure Resource Manager Azure role definition permits custom-role creation
Azure Resource Manager Azure Key Vault secret has no expiration date
Azure Resource Manager Review Azure SQL security alert email recipients
Azure Resource Manager Azure SQL server firewall rule specifies the full IPv4 range
Azure Resource Manager Azure SQL security alert types are disabled
Azure Resource Manager Review Azure SQL audit log retention
Azure Resource Manager Azure SQL Database auditing is not configured
Azure Resource Manager Review Defender for Cloud protection plans
Azure Resource Manager Review Storage Account default network access
Azure Resource Manager Storage account allows insecure transfer
Azure Resource Manager Azure Blob container permits public access
Azure Resource Manager Azure Queue Storage operation logs are disabled
Azure Resource Manager Review Trusted Microsoft Services exceptions
Azure Resource Manager Review Azure Activity Log retention
Azure Resource Manager Review Network Watcher flow log retention
Azure Resource Manager Review the Web App minimum TLS version
Azure Resource Manager Review App Service managed identity use
Azure Resource Manager Review Web App HTTPS redirection
Azure Resource Manager Review Web App client certificate settings
Azure Resource Manager Review App Service HTTP/2 settings
Buildah apt used in Buildah automation
CI/CD GitHub Actions run block command injection
CI/CD GitHub Actions script block injection
CI/CD GitHub Actions not pinned to a full commit SHA
CI/CD GitHub Actions permits insecure commands
CloudFormation Review the access key age threshold
CloudFormation ALB is not associated with AWS WAF
CloudFormation ALB uses an HTTP listener
CloudFormation Alexa Skill secret storage needs review
CloudFormation AWS DMS replication instance has public accessibility enabled or unset
CloudFormation Amazon MQ encryption key settings need review
CloudFormation Exposed Amplify app access token
CloudFormation Exposed Amplify app Basic Auth password
CloudFormation Exposed Amplify app OAuth token
CloudFormation Exposed Amplify branch Basic Auth password
CloudFormation Review API Gateway stage logging
CloudFormation API Gateway cache cluster not configured
CloudFormation API Gateway cache encryption is disabled
CloudFormation Review access logging for an API Gateway deployment stage
CloudFormation Usage plan not associated with the deployed API stage
CloudFormation Review API Gateway endpoint exposure
CloudFormation Review API Gateway API key usage management
CloudFormation API Gateway stage not associated with a usage plan
CloudFormation Review the API Gateway compression threshold
CloudFormation Review API Gateway method authentication
CloudFormation Review API Gateway authentication configuration
CloudFormation Review the TLS policy for an API Gateway custom domain
CloudFormation Review API Gateway backend client certificate settings
CloudFormation Review AWS WAF protection for API Gateway
CloudFormation API Gateway X-Ray tracing disabled
CloudFormation Review load balancer attachment for an Auto Scaling group
CloudFormation Review RDS automatic minor upgrade settings
CloudFormation AWS Batch job definition with privileged mode enabled
CloudFormation EBS block-device encryption needs review
CloudFormation Review CloudFront distribution and origin configuration
CloudFormation Credentials are embedded in a CloudFormation template
CloudFormation CloudFront request logging is not configured
CloudFormation CloudFront allows HTTP viewer connections
CloudFormation CloudFront minimum TLS version is too low
CloudFormation CloudFront is not associated with AWS WAF
CloudFormation CloudTrail log file validation disabled
CloudFormation CloudTrail logs without a configured KMS key
CloudFormation CloudTrail trail logging is stopped
CloudFormation CloudTrail multi-Region logging disabled
CloudFormation CloudTrail not integrated with CloudWatch Logs
CloudFormation CloudTrail SNS notification topic not configured
CloudFormation Review Route 53 public DNS logging to CloudWatch
CloudFormation Review API Gateway detailed CloudWatch metrics
CloudFormation KMS key availability needs review
CloudFormation KMS customer managed key automatic rotation disabled
CloudFormation Database storage encryption needs review
CloudFormation CodeBuild artifact encryption key needs review
CloudFormation Cognito user pool without MFA
CloudFormation AWS Config aggregator limited to selected Regions
CloudFormation EBS encryption monitoring needs review
CloudFormation Traffic between CloudFront and the origin is not encrypted
CloudFormation Cross-account role trust needs external-ID or MFA review
CloudFormation DAX cluster encryption at rest is disabled
CloudFormation Security group permits a broad source range
CloudFormation RDS-associated security group has an unrestricted ingress range
CloudFormation Default database KMS key usage
CloudFormation Default security group retains traffic rules
CloudFormation Plaintext password in Directory Service Microsoft AD
CloudFormation Plaintext password in Directory Service Simple AD
CloudFormation Plaintext password in DMS MongoDB endpoint settings
CloudFormation Plaintext password in a DMS endpoint
CloudFormation Plaintext master password in a DocumentDB cluster
CloudFormation Review DocumentDB audit and profiler logging
CloudFormation DynamoDB encryption key settings need review
CloudFormation DynamoDB point-in-time recovery disabled
CloudFormation DynamoDB uses an AWS owned key
CloudFormation Invalid DynamoDB billing mode
CloudFormation EBS volume encryption needs review
CloudFormation EBS volume not attached to an instance
CloudFormation EBS volume without a specified KMS key
CloudFormation Review the IAM role association for the EC2 instance
CloudFormation Review EC2 detailed monitoring
CloudFormation Automatic public IP assignment enabled for a subnet
CloudFormation EC2 instance uses the default security group
CloudFormation EC2 instance uses the default VPC
CloudFormation Duplicate network ACL rule number
CloudFormation Review the scope of network ACL deny rules
CloudFormation Overlapping port ranges in network ACL rules
CloudFormation Review EC2 EBS optimization
CloudFormation Review protocols allowed by a network ACL
CloudFormation Public EC2 instance exposure through its subnet
CloudFormation EC2 security group exposes a sensitive port to all addresses
CloudFormation ECR image tags can be overwritten
CloudFormation ECR repository policy uses a wildcard principal
CloudFormation ECR repository without a customer managed KMS key
CloudFormation Review ECS Container Insights settings
CloudFormation ECS EFS transport encryption needs review
CloudFormation Review load balancer attachment for an ECS service
CloudFormation ECS service role permissions need review
CloudFormation Review ECS service deployment availability
CloudFormation Public IP assignment for ECS tasks
CloudFormation ECS container health check not configured
CloudFormation Invalid Fargate task CPU and memory combination
CloudFormation Review the ECS task network mode
CloudFormation EFS file system with encryption disabled
CloudFormation EFS transit encryption settings need review
CloudFormation Review the EFS customer managed KMS key
CloudFormation EFS tags missing
CloudFormation EKS encryption key configuration needs review
CloudFormation Insufficient restrictions on EKS node group remote access
CloudFormation Memcached nodes placed in one Availability Zone
CloudFormation Review default ElastiCache port use
CloudFormation ElastiCache Redis replication group with encryption at rest disabled
CloudFormation ElastiCache transit encryption is disabled
CloudFormation Review ElastiCache VPC and subnet-group selection
CloudFormation Elasticsearch encryption key configuration needs review
CloudFormation OpenSearch node-to-node encryption needs review
CloudFormation Elasticsearch domain with encryption at rest disabled
CloudFormation OpenSearch domain does not require HTTPS
CloudFormation Review Elasticsearch and OpenSearch audit logging
CloudFormation Review Elasticsearch and OpenSearch error logging
CloudFormation Elasticsearch domain principals need review
CloudFormation OpenSearch and Elasticsearch slow logs not configured
CloudFormation ELB access logging disabled
CloudFormation ELB security group exposes a sensitive port to all addresses
CloudFormation Review ELB protocol security settings
CloudFormation ELB TLS security policy needs review
CloudFormation ALB access logging is disabled
CloudFormation Review ELB inbound access rules
CloudFormation Review ELB outbound access rules
CloudFormation Review ELB transport encryption
CloudFormation Review IAM roles for an ECS task
CloudFormation EMR cluster has no security configuration attached
CloudFormation Encryption disabled in an EMR security configuration
CloudFormation Review EMR cluster VPC subnet selection
CloudFormation Security group allows all ports from all addresses
CloudFormation Review GameLift inbound port ranges
CloudFormation Review the need for CloudFront geographic restrictions
CloudFormation GitHub repository visibility needs review
CloudFormation GuardDuty is disabled
CloudFormation Possible AWS credential exposure in Lambda environment variables
CloudFormation HTTP port open to all addresses
CloudFormation IAM Access Analyzer not enabled
CloudFormation RDS IAM database authentication is not enabled
CloudFormation Database cluster IAM authentication is not enabled
CloudFormation IAM group has no users
CloudFormation IAM group uses an inline policy
CloudFormation Managed IAM policy is attached directly to a user
CloudFormation IAM password below the minimum length
CloudFormation IAM policies are attached directly to a user
CloudFormation IAM policy allows full privileges
CloudFormation IAM policy attached directly to users
CloudFormation IAM policy grants excessive data read access
CloudFormation AssumeRole permission targets all roles
CloudFormation IAM policy allows all actions and resources
CloudFormation IAM policy resource is attached directly to users
CloudFormation Review account-wide trust in an IAM role
CloudFormation IAM login password may be exposed in the template
CloudFormation Review the number of IAM user access keys
CloudFormation IAM user without group membership
CloudFormation ECS service role references a policy
CloudFormation Review EC2 metadata service version settings
CloudFormation Review EC2 instance VPC association
CloudFormation IoT policy allows all actions
CloudFormation IoT policy allows all resources
CloudFormation Kinesis stream without server-side encryption
CloudFormation Review principals allowed by a KMS key policy
CloudFormation KMS automatic key rotation needs review
CloudFormation KMS key policy permissions need review
CloudFormation Retention not configured for failed asynchronous Lambda events
CloudFormation Lambda function tags missing
CloudFormation Lambda execution role may have excessive permissions
CloudFormation Lambda functions share an execution role
CloudFormation Lambda active X-Ray tracing not configured
CloudFormation Lambda invocation permission misconfigured
CloudFormation Lambda invocation principal uses a wildcard
CloudFormation Insufficient RDS backup retention
CloudFormation Amazon MQ broker has public access enabled
CloudFormation Review Amazon MQ broker logging
CloudFormation Amazon MSK brokers have public access enabled
CloudFormation MSK cluster encryption settings need review
CloudFormation MSK broker log export needs review
CloudFormation Neptune cluster has IAM database authentication disabled
CloudFormation Neptune database cluster with storage encryption disabled
CloudFormation Neptune audit log export needs review
CloudFormation API Gateway invocation scope for Lambda needs review
CloudFormation RDS-linked subnet uses a /0 CIDR
CloudFormation RDS instance enables public access
CloudFormation RDS deletion protection disabled
CloudFormation RDS Multi-AZ deployment is not enabled
CloudFormation RDS cluster storage encryption settings need review
CloudFormation RDS instance storage encryption settings need review
CloudFormation Review default RDS port use
CloudFormation RDS automated backups are disabled
CloudFormation Redshift audit log export needs review
CloudFormation Review the Redshift cluster encryption key
CloudFormation Review Redshift VPC and subnet-group selection
CloudFormation Redshift storage encryption settings need review
CloudFormation Redshift public-access settings need review
CloudFormation Review default Redshift port use
CloudFormation Plaintext Alexa ASK skill refresh token
CloudFormation RDP port is open to the internet
CloudFormation AWS access key ownership and permissions need review
CloudFormation Review service records in a Route 53 hosted zone
CloudFormation Review VPC default-route purpose
CloudFormation S3 bucket policy has a wildcard or missing principal
CloudFormation S3 bucket ACL is PublicReadWrite
CloudFormation S3 bucket ACL permits listing by all users
CloudFormation S3 bucket ACL permits listing by any AWS account
CloudFormation S3 bucket policy uses a wildcard principal for delete actions
CloudFormation S3 Get permissions for a wildcard principal
CloudFormation S3 listing permissions for a wildcard principal
CloudFormation Review S3 public ACL blocking
CloudFormation S3 bucket policy uses a wildcard principal for put actions
CloudFormation S3 object restoration permissions for a wildcard principal
CloudFormation CloudTrail log bucket access logging needs review
CloudFormation S3 bucket access logging needs review
CloudFormation S3 bucket policy not associated with its target
CloudFormation S3 bucket policy uses wildcards for Action and Principal
CloudFormation Review S3 public-policy blocking
CloudFormation Review S3 CORS scope
CloudFormation Review S3 public ACL handling
CloudFormation Review access restrictions for S3 public policies
CloudFormation Review S3 bucket default encryption policy
CloudFormation Review TLS enforcement for S3 writes
CloudFormation S3 bucket versioning is not enabled
CloudFormation S3 bucket has static website hosting configured
CloudFormation SageMaker notebook encryption key settings need review
CloudFormation Direct internet access for a SageMaker notebook
CloudFormation Review the SageMaker endpoint volume encryption key
CloudFormation SageMaker notebook has no VPC subnet specified
CloudFormation Review SimpleDB domain use
CloudFormation Secrets Manager KMS key not specified
CloudFormation Review the Secrets Manager encryption key
CloudFormation Review the CloudFront TLS security policy
CloudFormation Security group egress allows all destination addresses
CloudFormation Security group egress allows all protocols
CloudFormation Review security group egress port ranges
CloudFormation Review single-IP security-group access
CloudFormation Security group ingress allows all protocols
CloudFormation Review security group ingress port ranges
CloudFormation Security-group or rule description missing
CloudFormation Security group allows unrestricted outbound traffic
CloudFormation Security group permits RDP from the entire internet
CloudFormation Security group exposes administrative ports
CloudFormation Security group allows all ports from the internet
CloudFormation Security group allows SSH from all addresses
CloudFormation Review security-group VPC selection
CloudFormation Review the need for Shield Advanced
CloudFormation SNS topic policy has a wildcard or missing principal
CloudFormation NotAction in an SNS allow policy
CloudFormation SNS topic KMS encryption not configured
CloudFormation Public access in an SQS queue policy
CloudFormation Review SQS message encryption settings
CloudFormation CloudFormation stack notifications not configured
CloudFormation Review StackSet retention on account removal
CloudFormation AWS Support policy without an attachment target
CloudFormation RDS snapshot tag copying disabled
CloudFormation Network ACL TCP/UDP port ranges need review
CloudFormation Externally allowed port range needs review
CloudFormation Security group ingress allows all source addresses
CloudFormation Review ECR image scanning configuration
CloudFormation Encoded private key in user data
CloudFormation IAM user console password-reset policy needs review
CloudFormation VPC gateway attachment limit exceeded
CloudFormation VPC Flow Logs coverage needs review
CloudFormation Review the purpose of a VPC without subnets
CloudFormation Review the Network Firewall inspection path for a VPC
CloudFormation Review CloudFront domain and certificate settings
CloudFormation Review a web ACL default-allow policy
CloudFormation Invalid ACM certificate domain name
CloudFormation WorkSpaces without configured encryption
CloudFormation Amazon Keyspaces table inventory
CloudFormation Amazon DynamoDB table inventory
CloudFormation Amazon EBS volume inventory
CloudFormation Amazon EFS file-system inventory
CloudFormation Amazon ElastiCache cache inventory
CloudFormation Amazon Kinesis Data Streams inventory
CloudFormation Amazon MQ broker inventory
CloudFormation Amazon MSK cluster inventory
CloudFormation Amazon RDS instance inventory
CloudFormation Amazon S3 bucket inventory
CloudFormation Amazon SNS topic inventory
CloudFormation Amazon SQS queue inventory
CloudFormation Access logging not configured for a SAM API
CloudFormation SAM API cache cluster not configured
CloudFormation Public endpoint for an internal SAM API
CloudFormation Review SAM API compression settings
CloudFormation X-Ray tracing disabled for a SAM REST API
CloudFormation Customer managed key not specified for SAM function environment variables
CloudFormation SAM function without retention for failed asynchronous events
CloudFormation SAM function without operational tags
CloudFormation Serverless functions share an execution role
CloudFormation SAM function without active X-Ray tracing
Common Passwords and secrets in infrastructure code
Crossplane Review CloudFront access logging
Crossplane Review the minimum TLS version for CloudFront viewers
Crossplane CloudFront distribution without a WAF web ACL
Crossplane Review CloudWatch log retention
Crossplane RDS instance without configured storage encryption
Crossplane Security group rule allows all IPv4 addresses
Crossplane Review DocumentDB audit and profiler logging
Crossplane Review ECS Container Insights settings
Crossplane EFS file system without configured encryption
Crossplane Review the EFS customer managed KMS key
Crossplane Review the ELB listener TLS security policy
Crossplane Neptune DB cluster without configured storage encryption
Crossplane RDS instance may receive a public IP address
Crossplane Review SQS KMS encryption settings
Crossplane AKS Kubernetes RBAC is disabled
Crossplane Redis allows unencrypted connections
Crossplane Review Cloud Storage usage logging
Crossplane GKE node pool auto-repair disabled
Docker Compose Custom cgroup_parent
Docker Compose Excessive container capabilities
Docker Compose Container port binding is too broad
Docker Compose Docker Compose CPU usage limit missing
Docker Compose Default seccomp profile disabled
Docker Compose Docker socket is mounted in a container
Docker Compose Review container healthcheck settings
Docker Compose Shared host PID namespace
Docker Compose Review container memory limits
Docker Compose Container lacks no-new-privileges protection
Docker Compose Review container process limits
Docker Compose Container runs in privileged mode
Docker Compose Review low port mappings and privileges
Docker Compose Review on-failure restart limits
Docker Compose Container security options not specified
Docker Compose Shared host IPC namespace
Docker Compose Shared host network namespace
Docker Compose Shared host user namespace
Docker Compose Review volumes shared between containers
Docker Compose Sensitive host directory is mounted in a container
Docker Compose Bind mount permits mount propagation
Dockerfile Use COPY instead of ADD
Dockerfile Review apk installation cache management
Dockerfile Review apt-get package-list cleanup
Dockerfile Missing package version pins in apt-get installs
Dockerfile Review apt-get installation prompts
Dockerfile Review apt-get recommended package installation
Dockerfile Changing the default shell with RUN
Dockerfile Review COPY file ownership and write permissions
Dockerfile COPY --from references its own build stage
Dockerfile Invalid COPY destination for multiple sources
Dockerfile Review integrity checks for remote artifacts
Dockerfile Review the container SSH port declaration
Dockerfile Gem package versions are not pinned
Dockerfile Review container health-check configuration
Dockerfile Base-image version is not specified
Dockerfile Base image uses the latest tag
Dockerfile Dockerfile ends with root as the selected user
Dockerfile Use of the MAINTAINER instruction
Dockerfile Review dnf installation cache cleanup
Dockerfile Review dnf installation prompts
Dockerfile Dockerfile has no USER instruction
Dockerfile dnf package versions are not pinned
Dockerfile Review zypper cache cleanup
Dockerfile Missing zypper non-interactive option
Dockerfile Multiple CMD instructions in one build stage
Dockerfile Multiple ENTRYPOINT instructions in one build stage
Dockerfile Review Dockerfile layers and temporary files
Dockerfile CMD and ENTRYPOINT without JSON form
Dockerfile npm package versions are not pinned
Dockerfile Review pip caches included in container images
Dockerfile Working directory set with RUN cd
Dockerfile Review apt use in Dockerfile automation
Dockerfile Using sudo in RUN
Dockerfile Review overlapping use of wget and curl
Dockerfile Review diagnostic commands in RUN
Dockerfile Duplicate build-stage names
Dockerfile Pipeline without pipefail
Dockerfile Review the range of EXPOSE port numbers
Dockerfile apk package versions are not pinned
Dockerfile pip package versions are not pinned
Dockerfile Review separate package-index refresh and installation
Dockerfile Review the intent of FROM platform selection
Dockerfile Build stage referenced by number
Dockerfile Review relative WORKDIR paths
Dockerfile Review yum installation cache cleanup
Dockerfile Review yum installation prompts
Dockerfile yum package versions are not pinned
Dockerfile zypper package versions are not pinned
Google Deployment Manager BigQuery dataset grants access to a public group
Google Deployment Manager Bucket versioning is not configured
Google Deployment Manager Review GKE client certificate settings
Google Deployment Manager Review Cloud DNS DNSSEC configuration
Google Deployment Manager Cloud Storage bucket ACLs need review
Google Deployment Manager Review public Cloud Storage ACL principals
Google Deployment Manager Cloud Storage versioning is disabled
Google Deployment Manager GKE cluster labels are not configured
Google Deployment Manager Review GKE authentication and access permissions
Google Deployment Manager Review Compute Engine external IP access paths
Google Deployment Manager Review GKE node image selection
Google Deployment Manager Review Compute Engine disk encryption key management
Google Deployment Manager DNSSEC uses RSASHA1
Google Deployment Manager Legacy ABAC authorization is enabled in GKE
Google Deployment Manager Review GKE control-plane authorized networks
Google Deployment Manager Uniform bucket-level access is disabled
Google Deployment Manager Review GKE Alias IP allocation
Google Deployment Manager IP forwarding is enabled
Google Deployment Manager MySQL local_infile is enabled
Google Deployment Manager Review GKE Network Policy enforcement
Google Deployment Manager Review GKE node auto-upgrades
Google Deployment Manager Review GCP IAM user account management
Google Deployment Manager Review VM instance OS Login settings
Google Deployment Manager Review GKE private cluster settings
Google Deployment Manager Review VM access through project-wide SSH keys
Google Deployment Manager Firewall rule permits unrestricted RDP access
Google Deployment Manager Review Shielded VM protection settings
Google Deployment Manager Review Cloud SQL automatic backup settings
Google Deployment Manager Cloud SQL connection encryption settings need review
Google Deployment Manager SSH access is not restricted
Google Deployment Manager Review GKE Cloud Logging integration
Google Deployment Manager Review GKE Cloud Monitoring collection settings
Google Deployment Manager GCP Persistent Disk resource inventory
Google Deployment Manager GCP Pub/Sub Topic resource inventory
Google Deployment Manager GCP Cloud Storage bucket resource inventory
gRPC Review Protocol Buffers enum type naming
Kubernetes AlwaysAdmit admission plugin is configured
Kubernetes AlwaysPullImages admission plugin not enabled
Kubernetes Anonymous authentication is not disabled
Kubernetes Review Kubernetes audit log retention settings
Kubernetes Review Kubernetes audit log backup count
Kubernetes Review Kubernetes audit log rotation size
Kubernetes Audit log path is not configured
Kubernetes Audit policy file is not configured
Kubernetes Review Kubernetes audit policy coverage
Kubernetes Review Node authorizer settings
Kubernetes Review RBAC authorization settings
Kubernetes Authorization mode is set to AlwaysAllow
Kubernetes etcd automatic TLS is enabled
Kubernetes kube-apiserver uses a basic authentication file
Kubernetes Review control plane bind-address access scope
Kubernetes Review Kubernetes client-certificate CA configuration
Kubernetes Review Kubernetes cluster-admin binding permissions
Kubernetes Kubernetes configuration permits unsafe sysctls
Kubernetes Review NetworkPolicy enforcement configuration
Kubernetes Kubernetes container runs in privileged mode
Kubernetes Kubernetes configuration allows an Unmasked proc mount
Kubernetes Review container UID settings
Kubernetes Review container protection against root execution
Kubernetes Container with added Linux capabilities
Kubernetes Kubernetes container has the SYS_ADMIN capability
Kubernetes Review Kubernetes container CPU limits
Kubernetes Review Kubernetes container CPU requests
Kubernetes Review the Kubernetes CronJob start deadline
Kubernetes Review Kubernetes Dashboard use
Kubernetes Review Kubernetes Deployment Pod placement
Kubernetes Review Kubernetes Deployment PodDisruptionBudget configuration
Kubernetes Docker daemon socket exposed to a container
Kubernetes Encryption provider configuration is not specified
Kubernetes Review encryption provider configuration
Kubernetes Review administrative boundaries for Kubernetes resources
Kubernetes Review etcd client certificate authentication
Kubernetes API server etcd CA file configuration needs review
Kubernetes Review etcd peer certificate authentication
Kubernetes Review etcd peer TLS certificate and key settings
Kubernetes etcd TLS certificate file configuration is incomplete
Kubernetes Incomplete etcd TLS client certificate settings in kube-apiserver
Kubernetes Review Kubernetes Event request limits
Kubernetes Review replica management for HPA-targeted Deployments
Kubernetes Review Kubernetes HPA Object metric references
Kubernetes Review Kubernetes image admission policy
Kubernetes Review Kubernetes container image pull policy
Kubernetes Review Kubernetes image digest pinning
Kubernetes Review StatefulSet volume access modes
Kubernetes Workload exposure through an Ingress controller
Kubernetes Review legacy kube-apiserver insecure binding settings
Kubernetes Review the legacy kube-apiserver insecure port setting
Kubernetes Review Kubernetes container image version selection
Kubernetes Kubelet certificate authority is not configured
Kubernetes Kubelet client certificate or key is not configured
Kubernetes Kubelet client certificate rotation is disabled
Kubernetes Review Kubernetes kubelet event rate settings
Kubernetes Review kubelet hostname override settings
Kubernetes Kubelet HTTPS is disabled
Kubernetes Review kubelet iptables utility-chain settings
Kubernetes Review kubelet kernel-setting protection
Kubernetes Unauthenticated kubelet read-only port enabled
Kubernetes Review kubelet streaming connection timeouts
Kubernetes Review whether a container needs a liveness probe
Kubernetes Review container memory limits
Kubernetes Review container memory requests
Kubernetes Review Kubernetes metadata label syntax
Kubernetes Review Kubernetes AppArmor profiles
Kubernetes Review Kubernetes NamespaceLifecycle admission settings
Kubernetes PSP does not require dropping NET_RAW
Kubernetes Review removal of NET_RAW capability
Kubernetes Review Kubernetes NetworkPolicy Pod selection
Kubernetes Review Kubernetes container Linux capability reduction
Kubernetes NodeRestriction admission plugin is not enabled
Kubernetes Workload outside kube-system uses hostPath
Kubernetes Review capability restrictions in legacy PodSecurityPolicy
Kubernetes Review control plane certificate authority trust
Kubernetes Review Kubernetes API version support
Kubernetes etcd peer auto TLS is enabled
Kubernetes Broad Pod creation permissions
Kubernetes Misconfigured Pod NetworkPolicy
Kubernetes Review Kubernetes namespace LimitRange configuration
Kubernetes Review Kubernetes namespace resource quotas
Kubernetes Review Kubernetes Pod and container security contexts
Kubernetes Legacy PodSecurityPolicy enforcement needs review on kube-apiserver
Kubernetes Kubernetes container permits privilege escalation
Kubernetes Review Kubernetes control plane profiling settings
Kubernetes PodSecurityPolicy permits privilege escalation
Kubernetes PodSecurityPolicy permits sharing host IPC
Kubernetes PSP allows host PID sharing
Kubernetes PodSecurityPolicy permits sharing the host network namespace
Kubernetes PodSecurityPolicy permits privileged containers
Kubernetes Additional capability permissions need review in PodSecurityPolicy
Kubernetes HostPath restrictions need review in PodSecurityPolicy
Kubernetes RBAC roles permit privilege escalation
Kubernetes RBAC permits attaching to containers
Kubernetes RBAC permits command execution in containers
Kubernetes RBAC permits impersonation
Kubernetes RBAC permits Pod port forwarding
Kubernetes RBAC permits reading Secrets
Kubernetes Kubernetes RBAC rule with wildcard permissions
Kubernetes Readiness probe is not configured
Kubernetes Review API server request timeouts
Kubernetes RoleBinding targets a default ServiceAccount
Kubernetes Review controller API server CA trust settings
Kubernetes Review Kubernetes container root filesystem write access
Kubernetes Root containers admitted
Kubernetes Review kubelet serving certificate rotation
Kubernetes Review seccomp profile settings
Kubernetes Review Kubernetes Secret delivery through environment variables
Kubernetes kube-apiserver secure-port is set to zero
Kubernetes Review policies replacing SecurityContextDeny
Kubernetes ServiceAccount admission plugin disabled
Kubernetes ServiceAccount access to Secrets
Kubernetes Review service account token verification keys
Kubernetes kube-apiserver service-account-lookup is false
Kubernetes ServiceAccount name not specified
Kubernetes Review service account token signing keys
Kubernetes Automatic service account token mounting not disabled
Kubernetes Review Kubernetes Service targets and port mapping
Kubernetes Review Kubernetes NodePort access scope
Kubernetes External LoadBalancer Service in use
Kubernetes Shared host IPC namespace
Kubernetes Shared host network namespace
Kubernetes Kubernetes workload shares the host PID namespace
Kubernetes ServiceAccount shared between workloads
Kubernetes Review StatefulSet replica placement
Kubernetes Review StatefulSet persistent storage requirements
Kubernetes Review StatefulSet PodDisruptionBudget settings
Kubernetes Review the StatefulSet headless Service connection
Kubernetes Review terminated Pod cleanup thresholds
Kubernetes Tiller access from within the cluster needs restriction
Kubernetes Kubernetes workload runs Tiller from Helm 2
Kubernetes Tiller Service has not been removed
Kubernetes Review TLS serving certificate configuration
Kubernetes Review kube-apiserver static token file authentication
Kubernetes Individual controller service account credentials disabled
Kubernetes Review Kubernetes Secret management
Kubernetes Review workload namespace organization
Kubernetes Kubernetes OS directory mount protections need review
Kubernetes Review Kubernetes TLS cipher suites
Kubernetes Review direct hostPort bindings
Kubernetes Kubernetes workload mounts a sensitive OS directory
Knative Review Knative request timeout settings
OpenAPI Invalid basePath format (OpenAPI 2.0)
OpenAPI Invalid body parameter property (OpenAPI 2.0)
OpenAPI Body parameter is missing schema (OpenAPI 2.0)
OpenAPI Review enum constraints in OpenAPI 2.0
OpenAPI Incorrect consumes format for file upload (OpenAPI 2.0)
OpenAPI Global OpenAPI schemes include HTTP
OpenAPI Global authentication uses the OAuth2 password flow
OpenAPI Invalid host format (OpenAPI 2.0)
OpenAPI An OpenAPI 2.0 scheme uses the OAuth2 implicit flow
OpenAPI Invalid media type syntax in OpenAPI 2.0
OpenAPI Invalid OAuth2 token URL in OpenAPI 2.0
OpenAPI Invalid OAuth2 authorization URL in OpenAPI 2.0
OpenAPI Parameter reference does not exist (OpenAPI 2.0)
OpenAPI Response reference does not exist (OpenAPI 2.0)
OpenAPI Schema reference does not exist (OpenAPI 2.0)
OpenAPI Multiple body parameters in one operation (OpenAPI 2.0)
OpenAPI Invalid location for collectionFormat: multi (OpenAPI 2.0)
OpenAPI Non-body parameter uses schema (OpenAPI 2.0)
OpenAPI OAuth2 scopes used with non-OAuth2 authentication
OpenAPI Required properties missing from an OpenAPI 2.0 object
OpenAPI Response examples differ from produces in OpenAPI 2.0
OpenAPI Operation mixes body and formData parameters (OpenAPI 2.0)
OpenAPI Missing request media type for an operation
OpenAPI Missing response media type for an operation
OpenAPI Review operation summary length in OpenAPI 2.0
OpenAPI Review Basic authentication for an OpenAPI 2.0 operation
OpenAPI An operation uses the OAuth2 implicit flow
OpenAPI An operation uses the OAuth2 password flow
OpenAPI File parameter has an invalid location (OpenAPI 2.0)
OpenAPI Incorrect parameter object reference (OpenAPI 2.0)
OpenAPI An OpenAPI operation allows HTTP
OpenAPI Review model property names in OpenAPI 2.0
OpenAPI Incorrect response object reference (OpenAPI 2.0)
OpenAPI Incorrect schema object reference (OpenAPI 2.0)
OpenAPI Review additional property policy in OpenAPI 2.0
OpenAPI HTTP transport documented in OpenAPI 2.0
OpenAPI OAuth2 password flow in security definitions
OpenAPI Authentication schemes are missing from an OpenAPI 2.0 document
OpenAPI Review the Basic authentication definition in OpenAPI 2.0
OpenAPI OpenAPI 2.0 security references an undefined authentication scheme
OpenAPI Undefined OAuth2 scope in global security requirements
OpenAPI Undefined OAuth2 scope in operation security requirements
OpenAPI Review media type prefixes in OpenAPI 2.0
OpenAPI Unknown properties in an OpenAPI 2.0 object
OpenAPI Unused global parameter definition (OpenAPI 2.0)
OpenAPI Unused global response definition (OpenAPI 2.0)
OpenAPI Unused global schema definition (OpenAPI 2.0)
OpenAPI Additional properties are too permissive (OpenAPI 3.0)
OpenAPI Additional properties are too restrictive (OpenAPI 3.0)
OpenAPI Review API key authentication (OpenAPI 3.0)
OpenAPI Incorrect callback object reference (OpenAPI 3.0)
OpenAPI Review transport protection for Basic authentication on an OpenAPI 3.0 operation
OpenAPI Unused OpenAPI 3.0 callback component
OpenAPI Unused example component (OpenAPI 3.0)
OpenAPI Unused header component (OpenAPI 3.0)
OpenAPI Unused OpenAPI 3.0 link component
OpenAPI Invalid OpenAPI 3.0 component name
OpenAPI Unused parameter component (OpenAPI 3.0)
OpenAPI Unused request body component (OpenAPI 3.0)
OpenAPI Unused response component (OpenAPI 3.0)
OpenAPI Unused schema component (OpenAPI 3.0)
OpenAPI Review empty arrays in OpenAPI 3.0
OpenAPI Misplaced Content-Type in OpenAPI 3.0 encoding
OpenAPI OpenAPI 3.0 encoding key does not match a schema property
OpenAPI Incorrect example object reference (OpenAPI 3.0)
OpenAPI Review the reusable Basic authentication definition in OpenAPI 3.0
OpenAPI Review HTTPS use for global OpenAPI servers
OpenAPI Incorrect header object reference (OpenAPI 3.0)
OpenAPI Missing header value definition
OpenAPI Review content type for multiple file uploads in OpenAPI 3.0
OpenAPI Invalid media type syntax in OpenAPI 3.0
OpenAPI Invalid OAuth2 token URL in OpenAPI 3.0
OpenAPI Invalid OAuth2 authorization URL in OpenAPI 3.0
OpenAPI Missing OpenAPI 3.0 callback reference target
OpenAPI Missing OpenAPI 3.0 example reference target
OpenAPI Missing OpenAPI 3.0 header reference target
OpenAPI Missing OpenAPI 3.0 link reference target
OpenAPI Missing OpenAPI 3.0 parameter reference target
OpenAPI Missing OpenAPI 3.0 request body reference target
OpenAPI Missing OpenAPI 3.0 response reference target
OpenAPI Missing OpenAPI 3.0 schema reference target
OpenAPI Incorrect link object reference (OpenAPI 3.0)
OpenAPI OpenAPI link operationId has no matching operation
OpenAPI OpenAPI link defines both operationId and operationRef
OpenAPI Missing schema for API body content
OpenAPI An OpenAPI 3.0 scheme uses the OAuth2 implicit flow
OpenAPI An OpenAPI 3.0 scheme uses the OAuth2 password flow
OpenAPI Required property missing from an OpenAPI 3.0 object
OpenAPI Multiple content entries in an OpenAPI 3.0 parameter
OpenAPI Incorrect parameter object reference (OpenAPI 3.0)
OpenAPI Parameter object defines both schema and content
OpenAPI Parameter object lacks schema or content
OpenAPI Missing parameter value definition
OpenAPI An OpenAPI operation server uses HTTP
OpenAPI Review parameter allowEmptyValue applicability
OpenAPI Review Encoding Object allowReserved applicability
OpenAPI allowReserved is set for an inapplicable parameter location
OpenAPI Review Encoding Object explode applicability
OpenAPI Review Encoding Object style applicability
OpenAPI Incorrect request body reference (OpenAPI 3.0)
OpenAPI Request body encoding conflicts with its media type
OpenAPI Incorrect response object reference (OpenAPI 3.0)
OpenAPI Incorrect schema object reference (OpenAPI 3.0)
OpenAPI Schema property has conflicting readOnly and writeOnly settings
OpenAPI Global security requirement references an undefined scheme
OpenAPI Operation security requirement references an undefined scheme
OpenAPI Scopes specified for an incompatible security scheme
OpenAPI Missing security scheme definition
OpenAPI Review protection for OpenAPI HTTP Basic authentication
OpenAPI Review HTTP Digest authentication (OpenAPI 3.0)
OpenAPI Review HTTP Negotiate authentication (OpenAPI 3.0)
OpenAPI Review the HTTP authentication scheme
OpenAPI Review the legacy OAuth security scheme
OpenAPI Server variable is not used in the URL
OpenAPI Review the base address of a relative server URL
OpenAPI Server URL variable definition is missing
OpenAPI Review the default OpenAPI server address
OpenAPI TRACE success response is undefined (OpenAPI 3.0)
OpenAPI Undefined OAuth2 scope in global OpenAPI 3 security requirements
OpenAPI Undefined OAuth2 scope in an OpenAPI 3 operation
OpenAPI Review the OpenAPI media type prefix
OpenAPI Review OpenAPI property names and placement
OpenAPI Review transport security for global API keys (OpenAPI 3.0)
OpenAPI Review transport security for operation API keys (OpenAPI 3.0)
OpenAPI Array item type is undefined (OpenAPI 3.0)
OpenAPI Array without an item limit
OpenAPI Default value does not match the type (OpenAPI 3.0)
OpenAPI Default response is undefined (OpenAPI 3.0)
OpenAPI Example value does not match the schema type (OpenAPI 3.0)
OpenAPI An OpenAPI document has no global authentication requirement
OpenAPI Review an Accept header parameter definition
OpenAPI Review an Authorization header parameter definition
OpenAPI Review a Content-Type header parameter definition
OpenAPI Review response header definitions and HTTP semantics
OpenAPI Review the OpenAPI contact email
OpenAPI Review the OpenAPI contact URL
OpenAPI Numeric format does not match the type (OpenAPI 3.0)
OpenAPI Review the global external documentation URL
OpenAPI Review the OpenAPI license URL
OpenAPI Review the operation’s external documentation URL
OpenAPI Review the schema’s external documentation URL
OpenAPI Review tag external documentation URLs
OpenAPI Array item definition is missing
OpenAPI Object schema without defined properties
OpenAPI Object schema without a type constraint
OpenAPI Review additional properties on reference objects
OpenAPI Maximum string length is undefined (OpenAPI 3.0)
OpenAPI An OpenAPI operation has no declared authentication requirement
OpenAPI Review schema type and items usage
OpenAPI Numeric format is unspecified (OpenAPI 3.0)
OpenAPI Maximum numeric value is undefined (OpenAPI 3.0)
OpenAPI Minimum numeric value is undefined (OpenAPI 3.0)
OpenAPI Review enum and additional schema constraints
OpenAPI Duplicate operationId values
OpenAPI Review normal operation response definitions
OpenAPI Review duplicate header parameter names
OpenAPI Review parameter identities and usage locations
OpenAPI Ambiguous path definitions
OpenAPI Path parameter is not marked as required
OpenAPI Path parameter has no matching path placeholder
OpenAPI Path placeholder has an empty name
OpenAPI Review operation visibility for an OpenAPI path
OpenAPI Review the paths published in OpenAPI
OpenAPI String pattern is undefined (OpenAPI 3.0)
OpenAPI Review schema definitions for required properties
OpenAPI allowEmptyValue is used in an unsupported location
OpenAPI Schema minimum exceeds its maximum
OpenAPI Review required properties and default-value behavior
OpenAPI Expected response code is missing (OpenAPI 3.0)
OpenAPI A body is defined for a bodyless response (OpenAPI 3.0)
OpenAPI Response body without a documented schema
OpenAPI Review OpenAPI response definitions
OpenAPI Invalid HTTP response status code
OpenAPI Review discriminator property definitions
OpenAPI Discriminator property is not required
OpenAPI Review discriminator value types and mappings
OpenAPI Review enum values against the schema type
OpenAPI Empty Schema Object
OpenAPI Review property constraints in composed schemas
OpenAPI Review direct self-references in schema composition
OpenAPI Review type definitions for required properties
OpenAPI The global security array is empty
OpenAPI Global security contains an empty object
OpenAPI An operation-level security array is empty
OpenAPI An operation-level security value contains an empty object
OpenAPI String pattern is too broad (OpenAPI 3.0)
OpenAPI DELETE success response is undefined (OpenAPI 3.0)
OpenAPI GET success response is undefined (OpenAPI 3.0)
OpenAPI HEAD success response is undefined (OpenAPI 3.0)
OpenAPI PATCH success response is undefined (OpenAPI 3.0)
OpenAPI POST success response is undefined (OpenAPI 3.0)
OpenAPI PUT success response is undefined (OpenAPI 3.0)
OpenAPI Path placeholder has no corresponding path parameter
OpenAPI Review schema constraints for the declared type
Pulumi DMS replication instance enables public access or leaves it unspecified
Pulumi Review API Gateway access logging
Pulumi Review API Gateway backend client certificate settings
Pulumi Review DocumentDB log exports
Pulumi Review the encryption key for a DynamoDB table
Pulumi DynamoDB point-in-time recovery disabled
Pulumi Review EC2 detailed monitoring
Pulumi Review EC2 EBS optimization
Pulumi Review ECS Container Insights settings
Pulumi Review Availability Zone distribution for ElastiCache Memcached
Pulumi Review automatic backups for ElastiCache Redis
Pulumi Review Elasticsearch log publishing
Pulumi Review HTTPS enforcement for Elasticsearch
Pulumi Review the IAM password minimum length
Pulumi RDS instance enables public access
Pulumi Azure Redis allows non-SSL connections
Pulumi Azure Storage does not enforce HTTPS
Pulumi Review Cloud Storage usage logging
Pulumi Review the minimum TLS version in a GCP SSL policy
Pulumi Review Kubernetes AppArmor protection
Pulumi Pulumi Kubernetes PodSecurityPolicy permits privileged execution
Serverless Framework REST API access logging disabled in Serverless Framework
Serverless Framework Public endpoint for an internal Serverless Framework API
Serverless Framework Review Serverless API response compression
Serverless Framework X-Ray tracing disabled for a Serverless Framework REST API
Serverless Framework Customer managed KMS key not specified for a Serverless Framework function
Serverless Framework Review retention of failed Serverless asynchronous events
Serverless Framework Review Serverless function operational tags
Serverless Framework Review IAM role separation for Serverless Framework functions
Serverless Framework Review Serverless function X-Ray tracing
Serverless Framework Broad privileges in a Serverless Framework IAM role
Terraform Review Alibaba Cloud ActionTrail log coverage
Terraform Public access to an ActionTrail OSS bucket
Terraform Alicloud ALB listener uses HTTP
Terraform Alicloud API Gateway API allows HTTP
Terraform Review the enabled state of an Alicloud KMS key
Terraform Alicloud ACK node pool has no automatic repair
Terraform Alicloud disk is not encrypted
Terraform Review KMS keys for Alicloud ECS data disks
Terraform Review automatic rotation of Alicloud KMS keys
Terraform Review NetworkPolicy support in Alicloud ACK
Terraform Review data-disk encryption in Alicloud Launch Templates
Terraform Review Alicloud Simple Log Service retention
Terraform Unencrypted Alicloud NAS file system
Terraform Review customer-managed KMS keys for Alicloud NAS
Terraform Review protection policies for Alibaba Cloud ROS stack updates
Terraform OSS bucket policy contains wildcards in actions and principals
Terraform OSS bucket policy combines wildcard principals with delete actions
Terraform Wildcard principals in Alicloud OSS listing policies
Terraform OSS bucket policy combines wildcard principals with put actions
Terraform Review customer-managed keys for an Alicloud OSS bucket
Terraform Alicloud OSS bucket configured as a static website
Terraform Review IP access restrictions for Alicloud OSS buckets
Terraform Alicloud OSS lifecycle rule is disabled
Terraform Alicloud OSS bucket has no access logging
Terraform Public access enabled on an Alicloud OSS bucket
Terraform Review transfer acceleration for Alicloud OSS
Terraform Alicloud OSS bucket versioning is disabled
Terraform Alicloud OSS bucket does not require HTTPS
Terraform Alicloud security group rule allows all ports or protocols from the internet
Terraform Alicloud security group rule exposes sensitive ports
Terraform Public ports in an Alicloud security group need a documented purpose
Terraform Review the Alicloud RAM failed sign-in limit
Terraform Review the Alicloud RAM password expiration period
Terraform Review the minimum Alicloud RAM password length
Terraform Review the number requirement for Alicloud RAM passwords
Terraform Review the symbol requirement for Alicloud RAM passwords
Terraform Alicloud RAM password reuse prevention is disabled
Terraform Review the lowercase requirement for Alicloud RAM passwords
Terraform Review the uppercase requirement for Alicloud RAM passwords
Terraform Alicloud RAM policy grants broad permissions
Terraform Alicloud RAM policy is attached directly to a user
Terraform Review mandatory MFA for Alicloud RAM console access
Terraform RDS instance uses an unsupported address setting
Terraform Review Alibaba Cloud RDS log collection coverage
Terraform Review Alibaba Cloud RDS PostgreSQL connection logging
Terraform Review Alibaba Cloud RDS PostgreSQL disconnection logging
Terraform Review Alibaba Cloud RDS PostgreSQL duration logging
Terraform RDS IP allow-list is unrestricted or invalid
Terraform Review Alicloud RDS SQL record retention
Terraform Review Alibaba Cloud RDS TLS connection settings
Terraform TDE is disabled on an Alicloud RDS instance
Terraform Alicloud ROS stack has no event notifications
Terraform Review stack retention when removing an Alibaba Cloud ROS stack instance
Terraform Review the template configuration for Alibaba Cloud ROS stacks
Terraform Alicloud SLB policy allows outdated TLS versions
Terraform Review Alibaba Cloud VPC flow log collection
Terraform AWS ALB deletion protection disabled
Terraform AWS ALB not associated with WAF
Terraform AWS ALB listener using HTTP
Terraform AWS ALB does not drop invalid headers
Terraform DMS replication instance enables public access
Terraform Amazon MQ broker encryption key settings need review
Terraform Unencrypted AWS AMI
Terraform Review AWS AMI account sharing
Terraform Review API Gateway stage logging
Terraform Review access logging on an API Gateway deployment stage
Terraform Review usage plan associations for deployed API Gateway stages
Terraform Review API Gateway endpoint exposure
Terraform Review API Gateway API key usage management
Terraform API Gateway cache without encryption
Terraform Review API Gateway stage usage plan associations
Terraform Review API Gateway CloudWatch log delivery
Terraform Review API Gateway response compression
Terraform Review API Gateway method authentication
Terraform Review API Gateway REST API authentication
Terraform Review the API Gateway custom domain TLS policy
Terraform Review API Gateway backend client certificate settings
Terraform Review AWS WAF protection for API Gateway
Terraform API Gateway X-Ray tracing disabled
Terraform Athena database query-result encryption settings need review
Terraform Athena workgroup result encryption settings need review
Terraform Amazon Aurora storage encryption settings need review
Terraform Review MFA requirements for IAM user access
Terraform Review the Auto Scaling group load-balancer association
Terraform RDS automatic minor upgrades are disabled
Terraform Auto Scaling group tags are missing
Terraform Review Elastic IP usage and association
Terraform Review IAM users’ password-change permissions
Terraform AWS Batch job definition enables privileged containers
Terraform AWS block-device mappings without encryption
Terraform RDS instance uses an outdated CA certificate
Terraform Review CloudFront content delivery configuration
Terraform Expired TLS certificate
Terraform TLS certificate has a short RSA key
Terraform Review CloudFront request logging
Terraform CloudFront viewer policy allows HTTP
Terraform CloudFront security policy allows older TLS versions
Terraform Review the CloudFront WAF association
Terraform CloudTrail log integrity digests are disabled
Terraform Review KMS key settings for CloudTrail logs
Terraform CloudTrail log bucket public access needs review
Terraform Review access logging for the CloudTrail log bucket
Terraform AWS CloudTrail logging disabled
Terraform Review CloudTrail regional and global-event coverage
Terraform CloudTrail is not integrated with CloudWatch Logs
Terraform CloudTrail log-file delivery notifications are not configured
Terraform CloudWatch alarm missing for AWS Config changes
Terraform Missing alarm for AWS Organizations changes
Terraform CloudWatch alarm missing for network ACL changes
Terraform CloudWatch alarm missing for CloudTrail changes
Terraform CloudWatch alarm missing for KMS key changes
Terraform Missing alarm for IAM policy changes
Terraform Review the encryption key for a CloudWatch log group
Terraform Route 53 public DNS query logging is not configured
Terraform CloudWatch Logs destination policy grants excessive access
Terraform CloudWatch alarm missing for console sign-in failures
Terraform Missing alarm for console sign-ins without MFA
Terraform API Gateway detailed method metrics are disabled
Terraform Missing alarm for network gateway changes
Terraform CloudWatch alarm missing for root user activity
Terraform Missing alarm for route table changes
Terraform CloudWatch alarm missing for S3 bucket policy changes
Terraform CloudWatch alarm missing for security group changes
Terraform CloudWatch monitoring for unauthorized API calls needs review
Terraform CloudWatch alarm missing for VPC changes
Terraform Review CloudWatch log retention
Terraform Review use of a disabled customer managed KMS key
Terraform Review customer managed KMS key rotation
Terraform CodeBuild project using an AWS managed key
Terraform Review Cognito User Pool MFA coverage
Terraform Review the Regions included in AWS Config aggregation
Terraform Configuration without an ENCRYPTED_VOLUMES AWS Config rule
Terraform Cross-account IAM role trust conditions need review
Terraform AWS DAX cluster without encryption at rest
Terraform AWS DB instance without storage encryption
Terraform Legacy DB security group allows all source addresses
Terraform Legacy DB security-group source range needs review
Terraform EC2-Classic DB security group allows all IPv4 addresses
Terraform AWS default security group allows traffic with all addresses
Terraform Review AWS default VPC configuration
Terraform Review DocumentDB encryption key management
Terraform Amazon DocumentDB cluster without storage encryption
Terraform DocumentDB encryption key settings need review
Terraform Review DocumentDB log exports
Terraform DynamoDB table encryption key settings need review
Terraform DynamoDB point-in-time recovery is disabled
Terraform Review DynamoDB gateway endpoint routing associations
Terraform EBS encryption by default disabled in an account and Region
Terraform AWS EBS volume without encryption
Terraform AWS snapshot created from an unencrypted EBS volume
Terraform Review public IP assignment for EC2 instances
Terraform EC2 detailed monitoring disabled
Terraform AWS access keys deployed directly to an EC2 instance
Terraform Review default security group use on EC2 instances
Terraform Review an EC2 instance’s use of the default VPC
Terraform Review EC2 EBS optimization settings
Terraform Mutable image tags in an AWS ECR repository
Terraform ECR repository policy uses wildcard principals
Terraform Review ECR repository encryption key management
Terraform Review ECR repository access policies
Terraform Review ECS Container Insights settings
Terraform AWS ECS service role permissions need review
Terraform Review the required ECS service task count
Terraform ECS service assigned public IP addresses
Terraform Review the ECS task network mode
Terraform AWS EFS file system without encryption
Terraform EFS volume with transit encryption disabled
Terraform EFS file system policy access needs review
Terraform Review the EFS customer managed KMS key
Terraform Review EKS encryption key settings
Terraform Public access enabled for an EKS cluster
Terraform EKS public access CIDRs allow the entire internet
Terraform EKS cluster logging disabled
Terraform EKS node remote access has no source security groups
Terraform ElastiCache nodes not distributed across Availability Zones
Terraform ElastiCache Redis automatic backups disabled
Terraform AWS ElastiCache replication group without encryption at rest
Terraform ElastiCache replication group with transit encryption disabled
Terraform Review ElastiCache default ports and access controls
Terraform Review ElastiCache subnet group selection
Terraform Elasticsearch domain without node-to-node encryption
Terraform Elasticsearch domain policy access needs review
Terraform Review Elasticsearch encryption key settings
Terraform Review Elasticsearch log publishing
Terraform AWS Elasticsearch domain without encryption at rest
Terraform Elasticsearch domain does not enforce HTTPS
Terraform Review IAM access controls for an Elasticsearch domain
Terraform Review Elasticsearch slow-log settings
Terraform Classic ELB access logging disabled
Terraform Review SSL/TLS protocols in ELB policies
Terraform AWS Classic ELB cipher policies need review
Terraform Review ELBv2 load-balancer access logging
Terraform Review EMR cluster subnet selection
Terraform AWS Global Accelerator flow logs disabled
Terraform Review Glue Data Catalog and connection password encryption
Terraform Review Glue Security Configuration encryption settings
Terraform AWS Glue Data Catalog policy permissions need review
Terraform IAM group has excessive glue:UpdateDevEndpoint permissions
Terraform IAM group permissions for iam:AddUserToGroup need review
Terraform IAM group permissions for iam:AttachGroupPolicy need review
Terraform IAM group permissions for iam:AttachRolePolicy need review
Terraform IAM group permissions for iam:AttachUserPolicy need review
Terraform IAM group has excessive iam:CreateAccessKey permissions
Terraform IAM group has excessive iam:CreateLoginProfile permissions
Terraform IAM group permissions for iam:CreatePolicyVersion need review
Terraform IAM group has excessive CloudFormation and PassRole permissions
Terraform IAM group has excessive EC2 launch and PassRole permissions
Terraform IAM group has excessive Glue creation and PassRole permissions
Terraform IAM group has excessive Lambda creation, invocation and PassRole permissions
Terraform IAM group permissions for iam:PutGroupPolicy need review
Terraform IAM group permissions for iam:PutRolePolicy need review
Terraform IAM group permissions for iam:PutUserPolicy need review
Terraform IAM group permissions for iam:SetDefaultPolicyVersion need review
Terraform IAM group has excessive trust-policy update and role-assumption permissions
Terraform IAM group has excessive iam:UpdateLoginProfile permissions
Terraform IAM group has excessive lambda:UpdateFunctionCode permissions
Terraform GuardDuty detector is disabled
Terraform Review AWS credentials in EC2 user data
Terraform Review AWS credentials in Lambda environment variables
Terraform HTTP port 80 is open to the internet
Terraform Review IAM Access Analyzer configuration
Terraform Review access keys for an IAM user named root
Terraform IAM database authentication is not enabled for an RDS instance
Terraform IAM database authentication is not enabled for an RDS cluster
Terraform IAM group has no users
Terraform Review IAM password minimum length
Terraform IAM policy attached directly to a user
Terraform IAM policy administrative permissions need review
Terraform IAM policy can be abused for data exfiltration
Terraform IAM service-role trust principals need review
Terraform IAM policy grants excessive permissions
Terraform IAM role account-wide trust needs review
Terraform iam:PassRole allows every role
Terraform IAM role trust policy needs review
Terraform Review MFA requirements in IAM user policies
Terraform Review the number of access keys for an IAM user
Terraform IAM user has console access
Terraform Review IMDSv1 access to EC2 metadata
Terraform Review EC2 subnet and security-group selection
Terraform AWS Kinesis stream without KMS encryption
Terraform Amazon Data Firehose encryption settings need review
Terraform KMS key access policy needs review
Terraform Review the KMS key deletion waiting period
Terraform AWS Lambda function with an overly privileged execution role
Terraform Review retention of failed Lambda asynchronous events
Terraform Review Lambda X-Ray tracing configuration
Terraform Review IAM resource scope for Lambda InvokeFunction
Terraform Review the action in Lambda permission
Terraform Lambda invocation permission uses a wildcard principal
Terraform Lambda function policy grants broad actions
Terraform Review IAM password expiration policy
Terraform EKS control plane log types missing
Terraform Publicly accessible AWS MQ broker
Terraform Review MQ broker logging
Terraform Publicly accessible AWS MSK broker
Terraform Review MSK cluster encryption settings
Terraform Review MSK broker logging
Terraform Publicly accessible AWS Neptune cluster instance
Terraform Neptune cluster has IAM database authentication disabled
Terraform AWS Neptune cluster without encryption at rest
Terraform Review Neptune audit log exports
Terraform AWS Network ACL allows RDP from all addresses
Terraform Network ACL allows SSH from a broad address range
Terraform Review IAM user initial password settings
Terraform CloudFormation stack policy missing
Terraform Review IAM password reuse prevention
Terraform Resource-based policy has no Principal
Terraform Review query logging settings for RDS for PostgreSQL
Terraform Public and private EC2 instances share an IAM role
Terraform Review the scope of API Gateway permission to invoke Lambda
Terraform RDS configuration uses a /0 subnet CIDR
Terraform Review RDS cluster backup retention
Terraform Review RDS cluster snapshot encryption
Terraform RDS public-access configuration needs review
Terraform Review RDS cluster storage encryption
Terraform Review RDS default ports and access controls
Terraform RDS instance automated backups disabled
Terraform Review RDS CloudWatch log exports
Terraform Review the ElastiCache engine choice
Terraform Review the AWS ElastiCache Redis OSS engine version
Terraform Review Redshift audit logging
Terraform Review Redshift cluster network selection
Terraform Review Redshift encryption at rest
Terraform AWS Redshift cluster public-access settings need review
Terraform Review Redshift default ports and access controls
Terraform AWS security group allows RDP from all addresses
Terraform Operational tags are missing
Terraform API Gateway REST API policy grants excessive access
Terraform IAM role can escalate privileges through glue:UpdateDevEndpoint
Terraform IAM role permissions for iam:AddUserToGroup need review
Terraform IAM role permissions for iam:AttachGroupPolicy need review
Terraform IAM role permissions for iam:AttachRolePolicy need review
Terraform IAM role permissions for iam:AttachUserPolicy need review
Terraform IAM role can escalate privileges through iam:CreateAccessKey
Terraform IAM role can escalate privileges through iam:CreateLoginProfile
Terraform IAM role permissions for iam:CreatePolicyVersion need review
Terraform IAM role can escalate privileges through cloudformation:CreateStack and iam:PassRole
Terraform IAM role can escalate privileges through ec2:RunInstances and iam:PassRole
Terraform IAM role can escalate privileges through glue:CreateDevEndpoint and iam:PassRole
Terraform IAM role can escalate privileges through lambda:CreateFunction, lambda:InvokeFunction and iam:PassRole
Terraform IAM role permissions for iam:PutGroupPolicy need review
Terraform IAM role permissions for iam:PutRolePolicy need review
Terraform IAM role permissions for iam:PutUserPolicy need review
Terraform IAM role permissions for iam:SetDefaultPolicyVersion need review
Terraform IAM role can escalate privileges through iam:UpdateAssumeRolePolicy and sts:AssumeRole
Terraform IAM role can escalate privileges through iam:UpdateLoginProfile
Terraform IAM role can escalate privileges through lambda:UpdateFunctionCode
Terraform Review active access keys for an IAM user
Terraform Empty values in an AWS Route 53 record
Terraform S3 bucket policy uses wildcard principals
Terraform S3 bucket configuration uses a public canned ACL
Terraform S3 bucket ACL grants read access to any authenticated AWS account
Terraform S3 bucket ACL specifies WRITE_ACP permission
Terraform S3 bucket policy combines wildcard principals with delete actions
Terraform S3 bucket policy grants Get permissions to all principals
Terraform S3 bucket policy grants listing permissions to all principals
Terraform Review S3 public ACL blocking
Terraform S3 bucket policy combines wildcard principals with put actions
Terraform Review S3 server access logging
Terraform Review S3 bucket event notifications
Terraform Review S3 object-level CloudTrail data event coverage
Terraform Review S3 object server-side encryption settings
Terraform Review HTTPS enforcement for the S3 bucket
Terraform S3 bucket combines a public ACL with Block Public Access
Terraform S3 bucket policy uses wildcard actions and principals
Terraform Review S3 public bucket policy blocking
Terraform Review S3 CORS settings
Terraform Review S3 bucket MFA Delete use
Terraform Review S3 public ACL suppression
Terraform Review restrictions on public S3 buckets
Terraform Review S3 versioning settings
Terraform Review public exposure of an AWS S3 static website
Terraform Review SageMaker endpoint storage encryption keys
Terraform Review SageMaker notebook encryption keys
Terraform Secrets Manager secret access policy needs review
Terraform Secrets Manager secret encrypted with an AWS managed key
Terraform Review encryption key settings for a Secrets Manager secret
Terraform Review the CloudFront TLS security policy
Terraform Security group rule descriptions are missing
Terraform Security group allows SSH from the entire internet
Terraform Review security group descriptions
Terraform Review unused security groups
Terraform AWS security group allows management or internal-service ports from all addresses
Terraform Review source ranges for sensitive service ports
Terraform Review private-network access to sensitive service ports
Terraform AWS Organizations configuration cannot use Service Control Policies
Terraform SES identity-policy access needs review
Terraform Review the need for AWS Shield Advanced
Terraform SNS topic encrypted with an AWS managed key
Terraform SNS topic policy uses a wildcard principal
Terraform SNS topic without message encryption
Terraform SNS topic policy combines Effect: Allow and NotAction
Terraform SQL Analysis Services port 2383 allows unrestricted access
Terraform SQS queue policy grants broad actions
Terraform SQS queue policy public principals need review
Terraform AWS SQS queue policy access needs review
Terraform Review DNS settings for the SQS VPC endpoint
Terraform Review SQS queue-level encryption
Terraform Review additional KMS encryption for SSM sessions
Terraform Review IAM Identity Center permission-set session duration
Terraform Identity Center permission set grants excessive access
Terraform AWS Identity Center users created directly with Terraform
Terraform Review CloudFormation stack notifications
Terraform Review StackSet stack retention
Terraform CloudFormation stack template is missing
Terraform Review RDS snapshot tag copying
Terraform AWS security-group port exposure needs review
Terraform AWS security group allows ingress from all source addresses
Terraform Review ECR image vulnerability scanning
Terraform Review Base64-encoded private keys in launch configuration user data
Terraform IAM user has excessive glue:UpdateDevEndpoint permissions
Terraform IAM user permissions for iam:AddUserToGroup need review
Terraform IAM user permissions for iam:AttachGroupPolicy need review
Terraform IAM user permissions for iam:AttachRolePolicy need review
Terraform IAM user permissions for iam:AttachUserPolicy need review
Terraform IAM user has excessive iam:CreateAccessKey permissions
Terraform IAM user has excessive iam:CreateLoginProfile permissions
Terraform IAM user permissions for iam:CreatePolicyVersion need review
Terraform IAM user has excessive CloudFormation creation and PassRole permissions
Terraform IAM user has excessive EC2 launch and PassRole permissions
Terraform IAM user has excessive Glue creation and PassRole permissions
Terraform IAM user has excessive Lambda creation, invocation and PassRole permissions
Terraform IAM user permissions for iam:PutGroupPolicy need review
Terraform IAM user permissions for iam:PutRolePolicy need review
Terraform IAM user permissions for iam:PutUserPolicy need review
Terraform IAM user permissions for iam:SetDefaultPolicyVersion need review
Terraform IAM user has excessive trust-policy update and role-assumption permissions
Terraform IAM user has excessive iam:UpdateLoginProfile permissions
Terraform IAM user has excessive lambda:UpdateFunctionCode permissions
Terraform Default security-group traffic permissions need review
Terraform Review VPC Flow Logs coverage
Terraform Review destination ranges for VPC peering routes
Terraform VPC subnet automatically assigns public IP addresses
Terraform Review Network Firewall use in the VPC
Terraform Review certificates for CloudFront custom domains
Terraform WorkSpace without volume encryption
Terraform AWS DynamoDB resource inventory
Terraform AWS EBS volume inventory
Terraform AWS EFS file-system inventory
Terraform AWS ElastiCache resource inventory
Terraform AWS Kinesis Data Streams inventory
Terraform Amazon MQ broker inventory
Terraform BOM - AWS MSK resource inventory
Terraform AWS RDS resource inventory
Terraform AWS S3 bucket inventory
Terraform AWS SNS topic inventory
Terraform AWS SQS queue inventory
Terraform Review Activity Log alerts for Network Security Group creation and updates
Terraform Review Activity Log alerts for Public IP creation and updates
Terraform Review Activity Log alerts for Security Solution creation and updates
Terraform Review Activity Log alerts for SQL Server firewall rule creation and updates
Terraform Review Activity Log alerts for Policy Assignment creation and updates
Terraform Review Activity Log alerts for Network Security Group deletion
Terraform Review Activity Log alerts for Policy Assignment deletion
Terraform Review Activity Log alerts for Public IP deletion
Terraform Review Activity Log alerts for Security Solution deletion
Terraform Review Activity Log alerts for SQL Server firewall-rule deletion
Terraform Review Service Health Activity Log alerts
Terraform Review the Microsoft Entra administrator for Azure SQL
Terraform Container Registry admin user is enabled
Terraform Review customer-managed keys for AKS disks
Terraform Review AKS network policy settings
Terraform Review private access to the AKS API server
Terraform AKS RBAC is disabled
Terraform Review Azure Policy configuration for AKS
Terraform Review AKS audit log collection
Terraform Review App Service built-in authentication
Terraform Review App Service FTP transport protection
Terraform Review App Service HTTP/2 settings
Terraform Review App Service managed identity use
Terraform Review App Service minimum TLS settings
Terraform Review managed identity use for App Service slots
Terraform Review App Service PHP runtime support
Terraform Review App Service Python runtime support
Terraform Review Service Fabric management authentication
Terraform Review App Service client certificate requirements
Terraform Review public network access to Azure AI Search
Terraform Review Azure Container Registry permission scope
Terraform Review Azure Container Registry deletion locks
Terraform Review WAF policy associations for Azure Front Door
Terraform Password authentication is allowed for an Azure Linux VM
Terraform Review Azure Backup Vault immutability
Terraform Review Azure Backup Vault soft delete
Terraform Review Azure Blob soft-delete retention
Terraform Container App has no managed identity configured
Terraform Container Group has no managed identity configured
Terraform Review Azure Container Instances network exposure
Terraform Review Azure Blob container soft-delete retention
Terraform Cosmos DB account has no tags
Terraform Cosmos DB IP firewall configuration needs review
Terraform Review Kubernetes Dashboard use in AKS
Terraform Review Databricks diagnostic log collection
Terraform Review Azure Databricks virtual-network placement
Terraform Review customer-managed key coverage for Azure Databricks
Terraform Azure Storage Account default network access needs review
Terraform Review Diagnostic Setting log categories
Terraform Review customer-managed keys for Managed Disk
Terraform Security alert emails are disabled
Terraform Review Managed Disk encryption methods
Terraform Review Azure file share soft delete
Terraform Review the allowed address range for Azure Redis
Terraform Review Function App authentication settings
Terraform Review Function App client certificate requirements
Terraform Review the minimum TLS version of a Function App deployment slot
Terraform Review Function App FTP transport protection
Terraform Review Function App HTTP/2 settings
Terraform Function App has no managed identity configured
Terraform Review the Function App minimum TLS version
Terraform Review geo-redundant backups for Azure PostgreSQL
Terraform Review Key Vault key expiration
Terraform Review Azure Key Vault purge protection
Terraform Key Vault secret has no content type
Terraform Review HSM protection for Key Vault keys
Terraform Review managed identity use in AKS
Terraform Review Azure PostgreSQL log retention
Terraform Logic App has no managed identity configured
Terraform Public network access is enabled on an Azure MariaDB Server
Terraform Prepare regional disaster recovery for MariaDB workloads
Terraform Review the minimum TLS version for Azure SQL
Terraform Review Azure SQL server auditing policies
Terraform Review Azure SQL server security alerts
Terraform Azure MSSQL Server public network access needs review
Terraform Legacy Azure MySQL Server public network access needs review
Terraform Review TLS enforcement for Azure MySQL
Terraform Review IP forwarding on Azure network interfaces
Terraform Review public IP associations on Azure network interfaces
Terraform Azure Network Watcher flow logs are disabled
Terraform Azure PostgreSQL checkpoint logging is disabled
Terraform Review Azure PostgreSQL connection logging
Terraform Azure PostgreSQL disconnection logging is disabled
Terraform Review Azure PostgreSQL statement duration logging
Terraform Review the minimum TLS version for Azure PostgreSQL
Terraform Review Azure PostgreSQL encryption at rest
Terraform Review Azure PostgreSQL threat detection
Terraform Review Azure PostgreSQL throttling of failed authentication
Terraform Azure Storage Account public-access settings need review
Terraform Azure RDP rule public-access scope needs review
Terraform Azure Recovery Services Vault public network access needs review
Terraform Review Recovery Services Vault backup immutability
Terraform Review Recovery Services Vault deleted-backup protection
Terraform Azure Redis allows unencrypted connections
Terraform Review managed identity use for Azure Redis
Terraform Review the minimum TLS version for Azure Redis
Terraform Redis firewall allows all IPv4 addresses
Terraform Review the Azure Redis maintenance schedule
Terraform Redis firewall access range needs review
Terraform Review Azure resource diagnostic settings
Terraform Review Azure role permissions for guest users
Terraform Azure custom role permits role-definition changes
Terraform Review Key Vault secret expiration
Terraform Review Defender for Cloud protection plans
Terraform Azure security contact email is missing
Terraform Azure subnet NSG association needs review
Terraform Azure management and internal service port access needs review
Terraform Review sensitive-port access in Azure NSGs
Terraform Review private-network access to sensitive ports in Azure NSGs
Terraform Review Azure service resource-log collection
Terraform Review Activity Log retention
Terraform Review Azure flow-log retention
Terraform Review Azure SQL audit log retention
Terraform Review retention in Azure SQL auditing policies
Terraform Review Azure PostgreSQL server log retention
Terraform Review Azure SQL Database threat detection
Terraform Review Azure SQL Database encryption at rest
Terraform Review administrator emails for Azure SQL security alerts
Terraform Review Azure SQL server audit logging
Terraform Azure database firewall rule specifies the full IPv4 range
Terraform Review the Microsoft Entra administrator name for Azure SQL
Terraform Review Azure SQL administrator login names
Terraform Azure NSG allows internet access to SSH
Terraform Review Azure PostgreSQL connection encryption
Terraform Review secure transfer for Azure Storage
Terraform Review the Azure Files SMB version policy
Terraform Review the minimum TLS version for Azure Storage
Terraform Review the Azure Files SMB channel cipher policy
Terraform Azure Storage allows cross-tenant object replication
Terraform Azure Storage allows Shared Key access
Terraform Review customer-managed keys for Azure Storage
Terraform Beta - Azure storage account deletion protection needs review
Terraform Azure Storage Container allows anonymous reads
Terraform Excessive permissions in an Azure file-share access policy
Terraform Excessive permissions in an Azure Table access policy
Terraform Review trusted-service exceptions for Azure Storage
Terraform Azure database firewall permits broad access
Terraform Review Azure User Access Administrator assignment scope
Terraform Review Azure Key Vault audit-log collection
Terraform Review Virtual Network DDoS protection plans
Terraform Review Azure VM network-interface attachment
Terraform Review Windows VM automatic updates
Terraform Review Azure VM extension operations
Terraform Review administrator SSH keys for Azure VMs
Terraform Review Azure VM encryption at host
Terraform Review Azure VM migration to managed disks
Terraform Review WAF configuration for Azure Application Gateway
Terraform Review Azure Web App HTTPS enforcement
Terraform Databricks autoscaling bounds are incomplete
Terraform Review Databricks AWS node allocation
Terraform Review Databricks Azure node allocation
Terraform Review Databricks GCP node allocation
Terraform Review Databricks job and cluster permissions
Terraform Review Databricks group membership and permissions
Terraform Databricks OBO token lifetime is unspecified
Terraform Databricks personal access token lifetime is unspecified
Terraform Databricks IP allow-list permits all IPv4 addresses
Terraform Review Databricks Runtime support policy
Terraform Review Databricks spark_submit_task usage
Terraform Broad authenticated-user access to a GCP BigQuery dataset
Terraform Review Cloud Asset Inventory API enablement
Terraform Review GCP Cloud DNS DNSSEC configuration
Terraform Cloud Storage IAM binding permissions need review
Terraform Review public IAM grants on a Cloud Storage bucket
Terraform Review Cloud Storage bucket logging
Terraform Review Cloud Storage object-version and recovery settings
Terraform GKE cluster labels are not configured
Terraform Review GKE network policy support
Terraform Review GKE node image selection
Terraform Review GCP disk encryption key management
Terraform Review GCP DNSSEC signing algorithms
Terraform Review essential contacts for a Google Cloud organization
Terraform Review GKE release channels and upgrade schedules
Terraform Legacy ABAC authorization enabled in GKE
Terraform Review GKE node service-account permissions
Terraform Review access allowed by GCP default firewall rules
Terraform GCP firewall rule allows all ports
Terraform Review allowed port ranges in a Google Cloud firewall
Terraform Review the minimum TLS version in a GCP SSL policy
Terraform Review GCP subnet VPC Flow Logs collection
Terraform Review Private Google Access for the subnet
Terraform Review GKE node pool auto-repair settings
Terraform Review GCP DNS policy query logging
Terraform Review Alpha features in a production GKE cluster
Terraform Review GCP project default-network creation
Terraform GCP Project IAM Binding service-account delegation needs review
Terraform GCP Project IAM Member service-account administration needs review
Terraform GCP Project IAM Member service-account delegation needs review
Terraform GCP Storage Bucket Uniform Bucket-Level Access needs review
Terraform Review the Cloud KMS key rotation period
Terraform Review Google Cloud Data Access audit-log configuration
Terraform Review GKE VPC-native networking
Terraform GCP instance IP forwarding enabled
Terraform Review separation of Cloud KMS administration and decryption
Terraform Public permission scope on a GCP KMS Crypto Key needs review
Terraform Review legacy GKE Kubernetes Dashboard use
Terraform Review legacy client certificates in GKE
Terraform Review GCP network type and subnet creation mode
Terraform Review audit-configuration change logs and alerts
Terraform Review custom-role change logs and alerts
Terraform Review project-owner change logs and alerts
Terraform Review GKE NetworkPolicy enforcement
Terraform Review GKE node auto-upgrade settings
Terraform Review organizational management of Google Cloud IAM accounts
Terraform Review GCP project OS Login settings
Terraform Review OS Login disabling overrides on GCP VMs
Terraform Review GKE version support and updates
Terraform Review Pod security policy enforcement in GKE
Terraform Review GKE node and control-plane access paths
Terraform Review project-wide SSH key access on GCP VMs
Terraform Unrestricted RDP access in a GCP firewall
Terraform Review excessive IAM privileges on GCP service accounts
Terraform Shielded GKE node integrity monitoring disabled
Terraform Review Shielded GKE node protection
Terraform Review Shielded protection settings on GCP VMs
Terraform Review Cloud SQL automated backup settings
Terraform Review external script execution in GCP Cloud SQL
Terraform Google Cloud SQL network settings need review
Terraform Review contained database authentication in GCP Cloud SQL
Terraform Review Cloud SQL MySQL database-listing privileges
Terraform Review Cloud SQL SQL Server error-information exposure
Terraform Review Cloud SQL SQL Server session defaults
Terraform Review Cloud SQL SQL Server connection limits
Terraform Review Cloud SQL MySQL local file loading
Terraform Review Cloud SQL PostgreSQL duration-based SQL logging
Terraform Review Cloud SQL SQL Server cross-database ownership chaining
Terraform Review remote procedure execution in GCP Cloud SQL
Terraform Encrypted connections not enforced in GCP Cloud SQL
Terraform Review the Cloud SQL PostgreSQL error-statement logging threshold
Terraform Review the Cloud SQL PostgreSQL server-log threshold
Terraform Review Cloud SQL PostgreSQL pgAudit configuration
Terraform Review Cloud SQL PostgreSQL connection logging
Terraform Review Cloud SQL PostgreSQL disconnection logging
Terraform Review GCP SSH ingress access scope
Terraform Review GKE Cloud Logging integration
Terraform Review GKE Cloud Monitoring integration
Terraform Review per-user IAM access management in Google Cloud
Terraform Review GCP VM service accounts and effective permissions
Terraform Review interactive serial console access on GCP VMs
Terraform Review GCP VM API scopes and IAM permissions
Terraform Google Cloud Dataflow job inventory
Terraform Google Cloud Filestore inventory
Terraform Google Cloud Persistent Disk inventory
Terraform Google Cloud Pub/Sub topic inventory
Terraform Google Cloud Memorystore for Redis inventory
Terraform Google Cloud Storage bucket inventory
Terraform Git module revision not specified
Terraform Naming does not follow snake_case
Terraform Terraform output has no description
Terraform Terraform input variable has no description
Terraform Variable type not specified
Terraform GitHub organization webhook TLS certificate verification is disabled
Terraform Review GitHub repository visibility
Terraform Review cluster-admin ClusterRoleBinding permissions
Terraform Kubernetes configuration permits unsafe sysctls
Terraform Container shares the host PID namespace
Terraform Kubernetes container runs in privileged mode
Terraform Review container resource requests and limits
Terraform Kubernetes security policy permits Unmasked proc mounts
Terraform Review added Linux capabilities in containers
Terraform SYS_ADMIN capability added to a Kubernetes container
Terraform Review container CPU limits
Terraform Review container CPU requests
Terraform Review CronJob start deadlines
Terraform Review default ServiceAccount permissions and token automounting
Terraform Review Deployment pod placement
Terraform Review the Deployment PodDisruptionBudget
Terraform Review container access to the Docker daemon socket
Terraform Review HPA Object metric references
Terraform Review container image pull policies
Terraform Review container image digest pinning
Terraform Review volume claim access modes
Terraform Review workload exposure through Kubernetes Ingress
Terraform Review container image references
Terraform Review the need for container liveness probes
Terraform Review container memory limits
Terraform Review container memory requests
Terraform Review Kubernetes metadata label syntax
Terraform Review effective AppArmor protection for containers
Terraform Review policy requirements to drop NET_RAW
Terraform Review removal of NET_RAW from containers
Terraform Review NetworkPolicy pod selection
Terraform Review Linux capability reduction for containers
Terraform Review hostPath use in ordinary Kubernetes workloads
Terraform Pod-creation permissions are too broad
Terraform Review Pod and container security contexts
Terraform Privilege escalation allowed in a Kubernetes container
Terraform Kubernetes PodSecurityPolicy permits host network sharing
Terraform Kubernetes PodSecurityPolicy permits privilege escalation
Terraform Kubernetes PodSecurityPolicy permits host IPC sharing
Terraform Kubernetes PodSecurityPolicy permits privileged execution
Terraform Kubernetes PodSecurityPolicy permits additional capabilities
Terraform RBAC Role has Secret-read permissions
Terraform Review container readiness probes
Terraform RoleBinding targets the default ServiceAccount
Terraform Review container root filesystem write protection
Terraform Review policies allowing containers to run as root
Terraform Review container seccomp profiles
Terraform Review exposure of Secrets in environment variables
Terraform Review ServiceAccount access to Secrets
Terraform ServiceAccount name is not specified
Terraform Review ServiceAccount token automounting
Terraform Review Kubernetes NodePort access scope
Terraform Review exposure of Kubernetes LoadBalancer Services
Terraform Pod shares the host IPC namespace
Terraform Pod shares the host network namespace
Terraform Review ServiceAccount sharing
Terraform Review StatefulSet persistent-storage requirements
Terraform Review the StatefulSet PodDisruptionBudget
Terraform Review the StatefulSet headless Service association
Terraform Tiller (Helm v2) deployed in a Kubernetes environment
Terraform Review use of the Kubernetes default namespace
Terraform Review protection of Kubernetes OS directory mounts
Terraform Review whether workload host_port is needed
Terraform Kubernetes workload uses sensitive host directories
Terraform NIFCLOUD instance uses the common private network
Terraform Review all-address access in NIFCLOUD computing security groups
Terraform Review the security-group association of a NIFCLOUD instance
Terraform NIFCLOUD security group has no description
Terraform NIFCLOUD security group rule has no description
Terraform Review NIFCLOUD RDB backup retention
Terraform Review public access to a NIFCLOUD RDB instance
Terraform NIFCLOUD RDB uses the common private network
Terraform NIFCLOUD DB security group has no description
Terraform Review all-address access in a NIFCLOUD RDB security group
Terraform NIFCLOUD DNS verification TXT record remains
Terraform NIFCLOUD ELB uses the common private network
Terraform NIFCLOUD ELB listener uses HTTP
Terraform NIFCLOUD ELB uses HTTP
Terraform Review HTTP traffic through a NIFCLOUD load balancer listener
Terraform Review HTTP traffic through a NIFCLOUD load balancer
Terraform Review the NIFCLOUD load balancer TLS policy ID
Terraform Review the NIFCLOUD load balancer TLS policy name
Terraform NIFCLOUD NAS uses the common private network
Terraform NIFCLOUD NAS security group has no description
Terraform Review all-address access in a NIFCLOUD NAS security group
Terraform NIFCLOUD router uses the common private network
Terraform Review the security-group association of a NIFCLOUD router
Terraform Review the security-group association of a NIFCLOUD VPN gateway
Terraform Internet service enabled on a Tencent Cloud CDB instance
Terraform Review the default Tencent Cloud CDB intranet port
Terraform CDB backup policy is not explicitly managed
Terraform Tencent Cloud CLB access logging is not configured
Terraform Review transport encryption on a Tencent Cloud CLB listener
Terraform Tencent Cloud CVM monitoring agent installation is disabled
Terraform Review public IP use on a Tencent Cloud CVM instance
Terraform Review default security group use by Tencent Cloud CVM
Terraform Review default VPC use by Tencent Cloud CVM
Terraform API secrets in Tencent Cloud CVM user data
Terraform Tencent Cloud CBS disk encryption is disabled
Terraform Tencent Cloud security-group rule allows all traffic from every address
Terraform Review Secret encryption at rest in Tencent Cloud TKE
Terraform Review public IP assignment to Tencent Cloud TKE nodes
Terraform Tencent Cloud TKE log agent is disabled
Terraform Tencent Cloud VPC flow logging is disabled

Related pages17

Ansible

Security and operational configuration guidance for cloud resources and tasks managed with Ansible.

Azure Resource Manager

Security and service configuration guidance for Azure Resource Manager templates.

Buildah

Guidance on package installation in Buildah container builds.

CI/CD

Guidance on command execution and external action references in CI/CD workflows.

CloudFormation

Security, operational configuration and inventory guidance for resources defined with CloudFormation and AWS SAM.

Common

Guidance on handling secrets across infrastructure code.

Crossplane

Guidance on access controls and data protection for cloud resources defined with Crossplane.

Docker Compose

Guidance on Docker Compose resource limits, container isolation, networking and volume settings.

Dockerfile

Guidance on Dockerfile build instructions, package management and container runtime settings.

Google Deployment Manager

Security, operational configuration and resource inventory guidance for existing Google Deployment Manager templates.

gRPC

Guidance on Protocol Buffers enum naming conventions used with gRPC.

Kubernetes

Security, availability and operational configuration guidance for Kubernetes components and workloads.

Knative

Guidance on request timeout settings in Knative Serving.

OpenAPI

Guidance on security settings, request and response contracts, and schemas across OpenAPI versions.

Pulumi

Security and operational configuration guidance for cloud and Kubernetes resources defined with Pulumi.

Serverless Framework

Guidance on API, function, and deployment settings in Serverless Framework.

Terraform

Security, operational configuration and inventory guidance for resources defined with Terraform.