Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

added securityHub alarms KMS multi-Region #379

Merged
merged 1 commit into from
Jan 30, 2024

Conversation

AafAnsari
Copy link
Contributor

@AafAnsari AafAnsari commented Jan 30, 2024

A reference to the issue / Description of it

ministryofjustice/modernisation-platform#5635

How does this PR fix the problem?

Added multi-Region KMS keys for DR replication because existing KMS keys are all single-Region and cannot be converted to multi-Region

How has this been tested?

Created and tested primary multi_region KMS key and it's replica in eu-west-1 in sprinkler account

@AafAnsari AafAnsari requested a review from a team as a code owner January 30, 2024 11:03
Copy link
Contributor

TFSEC Scan Success

Show Output ```hcl

TFSEC will check the following folders:
.


Running TFSEC in .
Excluding the following checks: AWS089, AWS099, AWS009, AWS097, AWS018

======================================================
tfsec is joining the Trivy family

tfsec will continue to remain available
for the time being, although our engineering
attention will be directed at Trivy going forward.

You can read more here:
aquasecurity/tfsec#1994

timings
──────────────────────────────────────────
disk i/o 774.085µs
parsing 515.129344ms
adaptation 1.541849ms
checks 3.048002ms
total 520.49328ms

counts
──────────────────────────────────────────
modules downloaded 1
modules processed 6
blocks processed 256
files read 32

results
──────────────────────────────────────────
passed 27
ignored 18
critical 0
high 0
medium 0
low 0

No problems detected!

tfsec_exitcode=0

</details> #### `Checkov Scan` Success
<details><summary>Show Output</summary>

```hcl

*****************************

Checkov will check the following folders:
.

*****************************

Running Checkov in .
Excluding the following checks: CKV_GIT_1
2024-01-30 11:05:44,304 [MainThread  ] [WARNI]  Failed to download module github.com/ministryofjustice/modernisation-platform-terraform-s3-bucket?ref=8688bc15a08fbf5a4f4eef9b7433c5a417df8df1:None (for external modules, the --download-external-modules flag is required)
terraform scan results:

Passed checks: 288, Failed checks: 0, Skipped checks: 85

github_actions scan results:

Passed checks: 132, Failed checks: 0, Skipped checks: 0


checkov_exitcode=0

CTFLint Scan Success

Show Output
*****************************

Setting default tflint config...
Running tflint --init...
Installing "terraform" plugin...
Installed "terraform" (source: github.com/terraform-linters/tflint-ruleset-terraform, version: 0.5.0)
tflint will check the following folders:
.

*****************************

Running tflint in .
tflint_exitcode=0

Trivy Scan

Show Output

@AafAnsari AafAnsari merged commit b7d3763 into main Jan 30, 2024
4 checks passed
@AafAnsari AafAnsari deleted the feature/kms-keys-multi-region branch January 30, 2024 11:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants