Alibaba Cloud

Security and operational configuration guidance for Alibaba Cloud resources managed with Terraform.

Documentation

Article Path
Alicloud RAM policy grants broad permissions terraform/alicloud/ram_policy_admin_access_not_attached_to_users_groups_roles
Review NetworkPolicy support in Alicloud ACK terraform/alicloud/kubernetes_cluster_without_terway_as_cni_network_plugin
Review customer-managed keys for an Alicloud OSS bucket terraform/alicloud/oss_bucket_cmk_encryption_disabled
Review Alibaba Cloud VPC flow log collection terraform/alicloud/vpc_flow_logs_disabled
Alicloud API Gateway API allows HTTP terraform/alicloud/api_gateway_api_protocol_not_https
Alicloud ALB listener uses HTTP terraform/alicloud/alb_listening_on_http
Review IP access restrictions for Alicloud OSS buckets terraform/alicloud/oss_bucket_ip_restriction_disabled
Review KMS keys for Alicloud ECS data disks terraform/alicloud/ecs_data_disk_kms_key_id_undefined
Review customer-managed KMS keys for Alicloud NAS terraform/alicloud/nas_file_system_without_kms
Alicloud OSS lifecycle rule is disabled terraform/alicloud/oss_bucket_lifecycle_disabled
Review transfer acceleration for Alicloud OSS terraform/alicloud/oss_bucket_transfer_acceleration_disabled
Review the minimum Alicloud RAM password length terraform/alicloud/ram_account_password_policy_not_required_minimum_length
Review the uppercase requirement for Alicloud RAM passwords terraform/alicloud/ram_password_security_policy_not_require_at_least_one_uppercase_character
Review the lowercase requirement for Alicloud RAM passwords terraform/alicloud/ram_password_security_policy_not_require_at_least_one_lowercase_character
Review the number requirement for Alicloud RAM passwords terraform/alicloud/ram_account_password_policy_not_required_numbers
Review the symbol requirement for Alicloud RAM passwords terraform/alicloud/ram_account_password_policy_not_required_symbols
Review mandatory MFA for Alicloud RAM console access terraform/alicloud/ram_security_preference_not_enforce_mfa
Review Alicloud RDS SQL record retention terraform/alicloud/rds_instance_retention_not_recommended
Review Alibaba Cloud RDS log collection coverage terraform/alicloud/rds_instance_events_not_logged
Alicloud ROS stack has no event notifications terraform/alicloud/ros_stack_notifications_disabled
Review Alibaba Cloud RDS TLS connection settings terraform/alicloud/rds_instance_ssl_action_disabled
Alicloud OSS bucket does not require HTTPS terraform/alicloud/oss_buckets_securetransport_disabled
Review protection policies for Alibaba Cloud ROS stack updates terraform/alicloud/no_ros_stack_policy
Review stack retention when removing an Alibaba Cloud ROS stack instance terraform/alicloud/ros_stack_retention_disabled
TDE is disabled on an Alicloud RDS instance terraform/alicloud/rds_instance_tde_status_disabled
Alicloud ACK node pool has no automatic repair terraform/alicloud/cs_kubernetes_node_pool_auto_repair_disabled
RDS IP allow-list is unrestricted or invalid terraform/alicloud/rds_instance_publicly_accessible
Public access to an ActionTrail OSS bucket terraform/alicloud/actiontrail_trail_oss_bucket_is_publicly_accessible
Public access enabled on an Alicloud OSS bucket terraform/alicloud/oss_bucket_public_access_enabled
Review data-disk encryption in Alicloud Launch Templates terraform/alicloud/launch_template_is_not_encrypted
Review Alicloud Simple Log Service retention terraform/alicloud/log_retention_is_not_greater_than_90_days
Alicloud OSS bucket has no access logging terraform/alicloud/oss_bucket_logging_disabled
Review Alibaba Cloud ActionTrail log coverage terraform/alicloud/action_trail_logging_all_regions_disabled
OSS bucket policy contains wildcards in actions and principals terraform/alicloud/oss_bucket_allows_all_actions_from_all_principals
Wildcard principals in Alicloud OSS listing policies terraform/alicloud/oss_bucket_allows_list_action_from_all_principals
OSS bucket policy combines wildcard principals with delete actions terraform/alicloud/oss_bucket_allows_delete_from_all_principals
OSS bucket policy combines wildcard principals with put actions terraform/alicloud/oss_bucket_allows_put_action_from_all_principals
Alicloud security group rule exposes sensitive ports terraform/alicloud/public_security_group_rule_sensitive_port
Alicloud OSS bucket versioning is disabled terraform/alicloud/oss_bucket_versioning_disabled
Alicloud RAM password reuse prevention is disabled terraform/alicloud/ram_account_password_policy_without_reuse_prevention
Alicloud RAM policy is attached directly to a user terraform/alicloud/ram_policy_attached_to_user
Review the enabled state of an Alicloud KMS key terraform/alicloud/cmk_is_unusable
Review Alibaba Cloud RDS PostgreSQL duration logging terraform/alicloud/rds_instance_log_duration_disabled
Alicloud disk is not encrypted terraform/alicloud/disk_encryption_disabled
Unencrypted Alicloud NAS file system terraform/alicloud/nas_file_system_not_encrypted
Review Alibaba Cloud RDS PostgreSQL connection logging terraform/alicloud/rds_instance_log_connections_disabled
Review Alibaba Cloud RDS PostgreSQL disconnection logging terraform/alicloud/rds_instance_log_disconnections_disabled
Alicloud SLB policy allows outdated TLS versions terraform/alicloud/slb_policy_with_insecure_tls_version_in_use
Public ports in an Alicloud security group need a documented purpose terraform/alicloud/public_security_group_rule_unknown_port
RDS instance uses an unsupported address setting terraform/alicloud/rds_instance_address_publicly_accessible
Alicloud security group rule allows all ports or protocols from the internet terraform/alicloud/public_security_group_rule_all_ports_or_protocols
Alicloud OSS bucket configured as a static website terraform/alicloud/oss_bucket_has_static_website
Review the Alicloud RAM failed sign-in limit terraform/alicloud/ram_account_password_policy_max_login_attempts_unrecommended
Review the Alicloud RAM password expiration period terraform/alicloud/ram_account_password_policy_max_password_age_unrecommended
Review the template configuration for Alibaba Cloud ROS stacks terraform/alicloud/ros_stack_without_template
Review automatic rotation of Alicloud KMS keys terraform/alicloud/high_kms_key_rotation_period

Related pages56

Alicloud RAM policy grants broad permissions

Allow only the actions and resources required by users and roles.

Review NetworkPolicy support in Alicloud ACK

Use networking that can enforce Pod communication policies.

Review customer-managed keys for an Alicloud OSS bucket

Use a customer-managed key when separate key control is required.

Review Alibaba Cloud VPC flow log collection

Record traffic flows for the network scope you need to investigate.

Alicloud API Gateway API allows HTTP

Accept API requests over HTTPS only.

Alicloud ALB listener uses HTTP

Protect traffic between clients and ALB with TLS.

Review IP access restrictions for Alicloud OSS buckets

Configure network restrictions for OSS bucket policies according to their purpose and verify actual request source addresses.

Review KMS keys for Alicloud ECS data disks

Verify the encryption state and KMS key of ECS data disks against your key-management requirements.

Review customer-managed KMS keys for Alicloud NAS

Review NAS encryption and key-management requirements, using a customer-managed KMS key where needed.

Alicloud OSS lifecycle rule is disabled

Apply object lifecycle rules that match retention needs.

Review transfer acceleration for Alicloud OSS

Choose acceleration according to long-distance performance and cost needs.

Review the minimum Alicloud RAM password length

Require a sufficient minimum password length.

Review the uppercase requirement for Alicloud RAM passwords

Apply uppercase-character requirements consistently.

Review the lowercase requirement for Alicloud RAM passwords

Align the lowercase setting with organizational character requirements.

Review the number requirement for Alicloud RAM passwords

Align the number requirement with organizational password rules.

Review the symbol requirement for Alicloud RAM passwords

Match the symbol requirement to organizational password policy.

Review mandatory MFA for Alicloud RAM console access

Require an additional factor for RAM console sign-in.

Review Alicloud RDS SQL record retention

Retain SQL records for the period needed for investigation.

Review Alibaba Cloud RDS log collection coverage

Verify that required RDS audit, slow-query and performance logs reach their destination.

Alicloud ROS stack has no event notifications

Configure a callback for stack status changes.

Review Alibaba Cloud RDS TLS connection settings

Configure RDS TLS support together with client certificate validation.

Alicloud OSS bucket does not require HTTPS

Deny unencrypted requests in the bucket policy.

Review protection policies for Alibaba Cloud ROS stack updates

Define the resources and operations that need protection during stack updates.

Review stack retention when removing an Alibaba Cloud ROS stack instance

Decide whether the underlying stack must survive removal of its stack instance.

TDE is disabled on an Alicloud RDS instance

Check TDE and actual data encryption on supported Alicloud RDS instances.

Alicloud ACK node pool has no automatic repair

Enable required automatic repair for managed node pools.

RDS IP allow-list is unrestricted or invalid

Replace unrestricted IPv4 ranges and invalid RDS allow-list entries with required client addresses, and review connection paths and database permissions.

Public access to an ActionTrail OSS bucket

Restrict public access to the OSS bucket that stores ActionTrail audit logs.

Public access enabled on an Alicloud OSS bucket

Review public OSS bucket ACLs and restrict unintended anonymous reads and writes.

Review data-disk encryption in Alicloud Launch Templates

Verify encryption for data disks created from an ECS Launch Template.

Review Alicloud Simple Log Service retention

Keep logs for the period needed for investigation and audit.

Alicloud OSS bucket has no access logging

Retain access records for the bucket and its objects.

Review Alibaba Cloud ActionTrail log coverage

Include the required regions and read and write events in audit logs.

OSS bucket policy contains wildcards in actions and principals

Restrict wildcard grants in OSS bucket policies to the principals, actions, and resources needed to prevent unintended data access and changes.

Wildcard principals in Alicloud OSS listing policies

Limit OSS listing permissions to required principals and resources to avoid unnecessary exposure of object names and structure.

OSS bucket policy combines wildcard principals with delete actions

Restrict OSS deletion permissions to required accounts and roles to prevent unintended data loss and removal of settings.

OSS bucket policy combines wildcard principals with put actions

Restrict OSS upload and configuration permissions to required principals to prevent unwanted content and operational changes.

Alicloud security group rule exposes sensitive ports

Avoid unnecessary internet-wide access to administrative or sensitive services.

Alicloud OSS bucket versioning is disabled

Retain earlier object versions for recovery.

Alicloud RAM password reuse prevention is disabled

Restrict reuse of previous passwords.

Alicloud RAM policy is attached directly to a user

Manage shared permissions through groups aligned with responsibilities.

Review the enabled state of an Alicloud KMS key

Check the state of keys that protect data still in use.

Review Alibaba Cloud RDS PostgreSQL duration logging

Record completed SQL statement durations for operational analysis.

Alicloud disk is not encrypted

Encrypt data stored on disks.

Unencrypted Alicloud NAS file system

Enable encryption at rest for Alicloud NAS file systems.

Review Alibaba Cloud RDS PostgreSQL connection logging

Configure connection logs to support investigation of database access attempts.

Review Alibaba Cloud RDS PostgreSQL disconnection logging

Keep logs for investigating session end times and durations.

Alicloud SLB policy allows outdated TLS versions

Remove TLS 1.0 and TLS 1.1 from the allowed versions.

Public ports in an Alicloud security group need a documented purpose

Identify the services and purpose of public ports, then allow only the required access.

RDS instance uses an unsupported address setting

Remove the unsupported top-level address setting and restrict the RDS instance's IP allow-list and connection paths to required clients.