AWS

Security and operational configuration guidance for AWS resources managed with Ansible.

Documentation

Article Path
API Gateway X-Ray tracing is disabled ansible/aws/api_gateway_xray_disabled
Review API Gateway’s Lambda invocation scope ansible/aws/public_lambda_via_api_gateway
Review AWS Config aggregation Region coverage ansible/aws/config_configuration_aggregator_to_all_regions_disabled
Review IAM user password-change permissions ansible/aws/aws_password_policy_with_unchangeable_passwords
Review authorization for an API Gateway REST API ansible/aws/api_gateway_without_configured_authorizer
Review CloudFront distribution configuration ansible/aws/cdn_configuration_is_missing
CloudFormation stack notifications are not configured ansible/aws/stack_notifications_disabled
Review CloudFormation stack template inputs ansible/aws/stack_without_template
CloudTrail is not integrated with CloudWatch Logs ansible/aws/cloudtrail_not_integrated_with_cloudwatch
CloudTrail log-delivery notification topic is not configured ansible/aws/cloudtrail_sns_topic_name_undefined
CloudTrail multi-Region logging is disabled ansible/aws/cloudtrail_multi_region_disabled
No KMS key is specified for CloudTrail logs ansible/aws/cloudtrail_log_files_not_encrypted_with_kms
CloudTrail log file integrity validation is disabled ansible/aws/cloudtrail_log_file_validation_disabled
Review CloudWatch Logs retention ansible/aws/cloudwatch_without_retention_period_specified
Review CloudWatch log collection for API Gateway ansible/aws/api_gateway_with_cloudwatch_logging_disabled
Security group rule allows all IPv4 addresses ansible/aws/db_security_group_with_public_scope
Review EC2 instance metadata access protection ansible/aws/instance_uses_metadata_service_IMDSv1
Review EC2 VPC subnet selection ansible/aws/instance_with_no_vpc
Review EC2 default VPC use ansible/aws/ec2_instance_using_default_vpc
Review EC2 EBS optimization settings ansible/aws/ec2_not_ebs_optimized
ECR repository policy uses a wildcard principal ansible/aws/ecr_repository_is_publicly_accessible
Review ECS service deployment availability ansible/aws/ecs_service_without_running_tasks
Review the EFS customer managed KMS key ansible/aws/efs_without_kms
Review EFS operational tags ansible/aws/efs_without_tags
AWS Config configuration lacks an ENCRYPTED_VOLUMES rule ansible/aws/config_rule_for_encrypted_volumes_is_disabled
Review ElastiCache VPC subnet selection ansible/aws/elasticache_without_vpc
Review ElastiCache ports and access controls ansible/aws/elasticache_using_default_port
IAM trust policy external ID or MFA protections need review ansible/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa
Review HTTPS enforcement for an OpenSearch domain ansible/aws/elasticsearch_with_https_disabled
ALB listener accepts HTTP traffic ansible/aws/alb_listening_on_http
CloudFront viewer protocol policy allows HTTP ansible/aws/viewer_protocol_policy_allows_http
Review IAM database authentication for RDS ansible/aws/iam_database_auth_not_enabled
Review IAM password expiration policy ansible/aws/misconfigured_password_policy_expiration
Review IAM password reuse prevention ansible/aws/password_without_reuse_prevention
Review IAM password minimum length ansible/aws/iam_password_without_minimum_length
Review rotation settings for customer-managed KMS keys ansible/aws/cmk_rotation_disabled
Kinesis encryption settings need review ansible/aws/kinesis_not_encrypted_with_kms
Lambda active X-Ray tracing is not configured ansible/aws/lambda_functions_without_x-ray_tracing
Review allowed actions in a Lambda resource policy ansible/aws/lambda_permission_misconfigured
Review Lambda operational tags ansible/aws/lambda_function_without_tags
Possible secret key in a Lambda task's aws_access_key field ansible/aws/hardcoded_aws_access_key_in_lambda
Review MFA protection when assuming AWS roles ansible/aws/authentication_without_mfa
Review the exposure of an API Gateway REST API ansible/aws/api_gateway_endpoint_config_is_not_private
AWS Batch job definition using privileged mode ansible/aws/batch_job_definition_with_privileged_container_properties
Review RDS ports and access controls ansible/aws/rds_using_default_port
Review RDS automatic minor upgrades ansible/aws/automatic_minor_upgrades_disabled
Review RSA certificate key strength ansible/aws/certificate_rsa_key_bytes_lower_than_256
Review Redshift default-port use ansible/aws/redshift_using_default_port
Security group exposes SSH too broadly ansible/aws/security_group_with_unrestricted_access_to_ssh
Review certificate validation in Ansible API Gateway management ansible/aws/api_gateway_without_ssl_certificate
Review CloudFormation resource update protection ansible/aws/no_stack_policy
Review stack retention when deleting a StackSet ansible/aws/stack_retention_disabled
Review WAF protection for an API Gateway REST API ansible/aws/api_gateway_without_waf
CloudFront WAF association needs review ansible/aws/cloudfront_without_waf
Security group ingress may allow excessive access ansible/aws/security_group_ingress_not_restricted
Review encoded key material in user data ansible/aws/user_data_contains_encoded_private_key
Route 53 task has no record value ansible/aws/route53_record_undefined
RDS-linked subnet uses a /0 CIDR ansible/aws/rds_associated_with_public_subnet
Redshift configuration enables public access ansible/aws/redshift_publicly_accessible
SQS policy grants broad permissions to wildcard principals ansible/aws/sqs_policy_with_public_access
RDS instance has public access enabled ansible/aws/rds_db_instance_publicly_accessible
Legacy aws_s3 task specifies a public ACL ansible/aws/s3_bucket_with_public_access
SNS topic policy has a wildcard or missing principal ansible/aws/sns_topic_is_publicly_accessible
Security group ingress allows all IPv4 or IPv6 sources ansible/aws/ec2_group_has_public_interface
EC2 instance has a public IP address ansible/aws/ec2_instance_has_public_ip
ECS service assigns public IP addresses ansible/aws/ecs_services_assigned_with_public_ip_address
KMS key policy permissions need review ansible/aws/kms_key_with_full_permissions
ECS service role permissions need review ansible/aws/ecs_service_admin_role_is_present
Review the ECS task definition network mode ansible/aws/ecs_task_definition_network_mode_not_recommended
ElastiCache engine version and security requirements need review ansible/aws/redis_not_compliant
CloudFront viewer certificate settings need review ansible/aws/vulnerable_default_ssl_certificate
EC2 instance uses the default security group ansible/aws/ec2_instance_using_default_security_group
Security group inbound access scope needs review ansible/aws/db_security_group_open_to_large_scope
Security group exposes a port range to all addresses ansible/aws/public_port_wide
CloudFront logging settings need review ansible/aws/cloudfront_logging_disabled
CloudTrail trail logging is stopped ansible/aws/cloudtrail_logging_disabled
Review API diagnostic logging for the Ansible S3 task ansible/aws/s3_bucket_logging_disabled
Expired SSL/TLS certificate ansible/aws/certificate_has_expired
S3 bucket policy with delete actions and a wildcard principal ansible/aws/s3_bucket_allows_delete_action_from_all_principals
Wildcard principals in S3 object-read policies ansible/aws/s3_bucket_allows_get_action_from_all_principals
Wildcard principals in S3 listing policies ansible/aws/s3_bucket_allows_list_action_from_all_principals
S3 bucket policy with Put actions and a wildcard principal ansible/aws/s3_bucket_allows_put_action_from_all_principals
SES policy may grant excessive permissions ansible/aws/ses_policy_with_allowed_iam_actions
S3 bucket policy uses a wildcard principal ansible/aws/s3_bucket_access_to_any_principal
S3 bucket policy with wildcard actions and principals ansible/aws/s3_bucket_with_all_permissions
Public-read ACLs in S3 ansible/aws/s3_bucket_acl_allows_read_to_all_users
Review wildcard principals in IAM policies ansible/aws/iam_policy_grants_assumerole_permission_across_all_services
SQS queue policy specifies Action '*' ansible/aws/sqs_policy_allows_all_actions
Review account principals in IAM policies ansible/aws/iam_role_allows_all_principals_to_assume
S3 bucket versioning needs review ansible/aws/s3_bucket_without_versioning
Review IAM group membership ansible/aws/iam_group_without_users
IAM policies attached directly to a user ansible/aws/iam_policies_attached_to_user
An in-use KMS key is disabled or pending deletion ansible/aws/cmk_is_unusable
Review encryption at rest for SQS messages ansible/aws/sqs_with_sse_disabled
S3 bucket configuration requests removal of default encryption ansible/aws/s3_bucket_without_server-side_encryption
S3 CORS permissions need review ansible/aws/s3_bucket_with_unsecured_cors_rule
Review the TLS security policy on an ELB listener ansible/aws/elb_using_insecure_protocols
Review the CloudFront viewer TLS security policy ansible/aws/secure_ciphers_disabled
Review the CodeBuild artifact encryption key ansible/aws/codebuild_not_encrypted
EBS volume encryption settings need review ansible/aws/ebs_volume_encryption_disabled
EFS encryption at rest settings need review ansible/aws/efs_not_encrypted
Review encryption of AMI EBS snapshots ansible/aws/ami_not_encrypted
EBS encryption in EC2 launch settings needs review ansible/aws/launch_configuration_is_not_encrypted
Redshift encryption settings need review ansible/aws/redshift_not_encrypted
ELB listener security policy needs review ansible/aws/elb_using_weak_ciphers
AMI sharing targets need review ansible/aws/ami_shared_with_multiple_accounts
Review traffic distribution for an Auto Scaling Group ansible/aws/auto_scaling_group_with_no_associated_elb
RDS uses an expired or unsupported CA certificate ansible/aws/ca_certificate_identifier_is_outdated
Lambda permission uses a wildcard principal ansible/aws/lambda_permission_principal_is_wildcard
SQS queue policy uses Principal '*' ansible/aws/sqs_queue_exposed
S3 ACL grants read access to every AWS account ansible/aws/s3_bucket_acl_allows_read_to_any_authenticated_user
HTTP port is open to the Internet ansible/aws/http_port_open_to_internet
Service ports allow all source addresses ansible/aws/unknown_port_exposed_to_internet
Port 3389 may be exposed to all IPv4 sources ansible/aws/remote_desktop_port_open
Review active IAM user access keys ansible/aws/iam_access_key_is_exposed
Automated backups are disabled for an RDS instance ansible/aws/rds_with_backup_disabled
RDS storage encryption settings need review ansible/aws/db_instance_storage_not_encrypted
IAM policy uses wildcards for both actions and resources ansible/aws/iam_policy_grants_full_permissions
IAM policy allows all actions on all resources ansible/aws/iam_policies_with_full_privileges
Security group rule allows all IPv4 or IPv6 addresses ansible/aws/default_security_groups_with_unrestricted_traffic
Security group ingress allows all source addresses ansible/aws/unrestricted_security_group_ingress
CloudFront minimum TLS version needs review ansible/aws/cloudfront_without_minimum_protocol_tls_1.2
ECR repository permits image tag changes ansible/aws/ecr_image_tag_not_immutable
Security group allows TCP 2383 from all IPv4 sources ansible/aws/sql_analysis_services_port_2383_is_publicly_accessible
Possible AWS credential exposure in EC2 user data ansible/aws/hardcoded_aws_access_key
Active IAM user access key needs review ansible/aws/root_account_has_active_access_keys

Related pages126

API Gateway X-Ray tracing is disabled

Enable API request tracing according to operational needs.

Review API Gateway’s Lambda invocation scope

Allow API Gateway to invoke the function only from required stages, methods and paths.

Review AWS Config aggregation Region coverage

Aggregate Config data from the required accounts and Regions.

Review IAM user password-change permissions

Provide a way for IAM users to change their own passwords when needed.

Review authorization for an API Gateway REST API

Apply appropriate authentication and authorization to protected API operations.

Review CloudFront distribution configuration

Configure origins and the actual delivery path for services that need a CDN.

CloudFormation stack notifications are not configured

Send deployment status to the required operations channels.

Review CloudFormation stack template inputs

Supply a template for new stacks and distinguish intentional reuse of an existing template.

CloudTrail is not integrated with CloudWatch Logs

Configure a monitoring path for audit logs.

CloudTrail log-delivery notification topic is not configured

Connect an SNS topic when log-delivery notifications are needed.

CloudTrail multi-Region logging is disabled

Ensure audit records cover the required Regions.

No KMS key is specified for CloudTrail logs

Choose encryption-key management that meets the log-protection policy.

CloudTrail log file integrity validation is disabled

Generate signed digests for checking log integrity.

Review CloudWatch Logs retention

Keep logs for the period required by the workload.

Review CloudWatch log collection for API Gateway

Configure both the log group and API stage, then verify actual log delivery.

Security group rule allows all IPv4 addresses

Review Ansible security group ingress and egress rules that allow the entire IPv4 address range.

Review EC2 instance metadata access protection

Require IMDSv2 for necessary metadata access and verify application compatibility.

Review EC2 VPC subnet selection

Verify that EC2 uses the intended subnet and network access policies.

Review EC2 default VPC use

Check whether the actual EC2 VPC and subnet meet network isolation requirements.

Review EC2 EBS optimization settings

Check instance-type defaults and the workload’s EBS performance requirements.

ECR repository policy uses a wildcard principal

Review wildcard principals in private ECR repository policies and the image operations they permit.

Review ECS service deployment availability

Review healthy task requirements and spare capacity for ECS deployments together.

Review the EFS customer managed KMS key

Specify EFS encryption and customer managed KMS key requirements when creating a file system.

Review EFS operational tags

Maintain the tags needed to identify the EFS owner and purpose.

AWS Config configuration lacks an ENCRYPTED_VOLUMES rule

Use the AWS Config ENCRYPTED_VOLUMES rule to monitor encryption on attached EBS volumes, and verify that evaluations and notifications work.

Review ElastiCache VPC subnet selection

Verify the cache’s actual VPC and subnets, and allow access only from required applications.

Review ElastiCache ports and access controls

Prioritize actual network scope and supported authentication and encryption over the cache port number.

IAM trust policy external ID or MFA protections need review

Restrict the principals and external ID or MFA conditions in an IAM trust policy to suit how the role is used.

Review HTTPS enforcement for an OpenSearch domain

Restrict requests between clients and the domain to HTTPS.

ALB listener accepts HTTP traffic

Protect sensitive traffic between clients and the ALB with HTTPS.

CloudFront viewer protocol policy allows HTTP

Allowing HTTP in CloudFront can leave requests and responses between viewers and the CDN unencrypted.

Review IAM database authentication for RDS

Reduce reliance on long-lived passwords with IAM authentication where RDS supports it.

Review IAM password expiration policy

Choose password expiration and duration according to authentication and recovery requirements.

Review IAM password reuse prevention

Set the required password history so changes cannot simply return to earlier passwords.

Review IAM password minimum length

Check that IAM console password length meets the organization’s account-protection requirements.

Review rotation settings for customer-managed KMS keys

Use rotation appropriate to the key type and manage access permissions separately.

Kinesis encryption settings need review

Encrypt new records stored in Kinesis with KMS, and verify key permissions and successful writes and reads.

Lambda active X-Ray tracing is not configured

Sample and trace requests for functions that need it.

Review allowed actions in a Lambda resource policy

Allow actions for the actual invocation method and restrict callers and sources.

Review Lambda operational tags

Maintain tags that identify the Lambda function’s owner, purpose and environment.

Possible secret key in a Lambda task's aws_access_key field

Keep real secret keys out of Lambda deployment playbooks and manage deployment authentication separately from the function's execution role.

Review MFA protection when assuming AWS roles

Require MFA for people assuming sensitive roles and verify the actual policy.

Review the exposure of an API Gateway REST API

Make internal APIs callable only from the networks that need them.

AWS Batch job definition using privileged mode

Check privileged mode in AWS Batch jobs defined with Ansible and remove unnecessary host permissions.

Review RDS ports and access controls

Manage database port selection separately from actual access controls.

Review RDS automatic minor upgrades

Manage minor-version patching according to the engine and operating policy.

Review RSA certificate key strength

Use an RSA key size that meets the service and organization’s security requirements.

Review Redshift default-port use

Review the Redshift port policy together with actual network access.

Security group exposes SSH too broadly

Restrict SSH to required management paths to reduce external login attempts and the risk of server compromise.

Review certificate validation in Ansible API Gateway management

Keep server certificate validation enabled when connecting to AWS management APIs.