AWS

Guidance on access controls, data protection, logging and availability for AWS resources defined with Pulumi.

Documentation

Article Path
Review API Gateway access logging pulumi/aws/api_gateway_access_logging_disabled
Review API Gateway backend client certificate settings pulumi/aws/api_gateway_without_ssl_certificate
Review DocumentDB log exports pulumi/aws/docdb_logging_disabled
DynamoDB point-in-time recovery disabled pulumi/aws/dynamodb_table_point_in_time_recovery_disabled
Review EC2 EBS optimization pulumi/aws/ec2_not_ebs_optimized
Review EC2 detailed monitoring pulumi/aws/ec2_instance_monitoring_disabled
Review ECS Container Insights settings pulumi/aws/ecs_cluster_container_insights_disabled
Review automatic backups for ElastiCache Redis pulumi/aws/elasticache_redis_cluster_without_backup
Review Availability Zone distribution for ElastiCache Memcached pulumi/aws/elasticache_nodes_not_created_across_multi_az
Review HTTPS enforcement for Elasticsearch pulumi/aws/elasticsearch_with_https_disabled
Review Elasticsearch log publishing pulumi/aws/elasticsearch_logs_disabled
Review the IAM password minimum length pulumi/aws/iam_password_without_minimum_length
DMS replication instance enables public access or leaves it unspecified pulumi/aws/amazon_dms_replication_instance_is_publicly_accessible
RDS instance enables public access pulumi/aws/rds_db_instance_publicly_accessible
Review the encryption key for a DynamoDB table pulumi/aws/dynamodb_table_not_encrypted

Related pages15

Review API Gateway access logging

Collect access logs needed for request tracing and investigation.

Review API Gateway backend client certificate settings

Configure the API Gateway client certificate required by the backend.

Review DocumentDB log exports

Generate and collect DocumentDB logs needed for audit and performance analysis.

DynamoDB point-in-time recovery disabled

Use DynamoDB point-in-time recovery to provide recovery options for mistakes or data corruption.

Review EC2 EBS optimization

Check instance-type support and defaults to provide appropriate EBS performance for the workload.

Review EC2 detailed monitoring

Choose detailed monitoring according to required metric resolution and cost.

Review ECS Container Insights settings

Collect the Container Insights metrics needed for your Pulumi ECS cluster.

Review automatic backups for ElastiCache Redis

Choose snapshot retention according to the cache data you need to recover.

Review Availability Zone distribution for ElastiCache Memcached

Review failure scope and recovery for a multi-node cache.

Review HTTPS enforcement for Elasticsearch

Require HTTPS at the domain endpoint to protect data in transit.

Review Elasticsearch log publishing

Configure required log types and their generation settings for operational and security investigations.

Review the IAM password minimum length

Set the minimum length of IAM users’ console passwords to meet your organization’s requirements.

DMS replication instance enables public access or leaves it unspecified

Limit public addressing for Pulumi DMS replication instances and protect replication with private connectivity and a replacement plan.

RDS instance enables public access

Public access can create an unnecessary external connection path to RDS. Use private connections for internal databases and restrict network paths and permissions.

Review the encryption key for a DynamoDB table

Distinguish default DynamoDB encryption from KMS key-management requirements