Skip to content

Commit fc223d1

Browse files
docs(queries): update queries catalog
1 parent 0a6e949 commit fc223d1

14 files changed

+2148
-12
lines changed

docs/queries/all-queries.md

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1665,13 +1665,19 @@ This page contains all queries.
16651665
|Private Cluster Disabled<br/><sup><sub>6ccb85d7-0420-4907-9380-50313f80946b</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Insecure Configurations|<a href="../terraform-queries/gcp/6ccb85d7-0420-4907-9380-50313f80946b" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/6ccb85d7-0420-4907-9380-50313f80946b')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/container_cluster">Documentation</a><br/>|
16661666
|Shielded GKE Nodes Disabled<br/><sup><sub>579a0727-9c29-4d58-8195-fc5802a8bdb4</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Insecure Configurations|<a href="../terraform-queries/gcp/579a0727-9c29-4d58-8195-fc5802a8bdb4" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/579a0727-9c29-4d58-8195-fc5802a8bdb4')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/container_cluster#enable_shielded_nodes">Documentation</a><br/>|
16671667
|Shielded VM Disabled<br/><sup><sub>1b44e234-3d73-41a8-9954-0b154135280e</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Insecure Configurations|<a href="../terraform-queries/gcp/1b44e234-3d73-41a8-9954-0b154135280e" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/1b44e234-3d73-41a8-9954-0b154135280e')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_instance#shielded_instance_config">Documentation</a><br/>|
1668+
|Beta - SQL DB Instance With Exposed Show Privileges<br/><sup><sub>b5b70198-2a34-4792-b0d9-ce99abe485bb</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Insecure Defaults|<a href="../terraform-queries/gcp/b5b70198-2a34-4792-b0d9-ce99abe485bb" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/b5b70198-2a34-4792-b0d9-ce99abe485bb')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/sql_database_instance.html#settings-1">Documentation</a><br/>|
1669+
|Beta - SQL DB Instance With Local Data Loading Enabled<br/><sup><sub>51a2c34d-dfd0-436f-aa34-e8f796e052fd</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Insecure Defaults|<a href="../terraform-queries/gcp/51a2c34d-dfd0-436f-aa34-e8f796e052fd" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/51a2c34d-dfd0-436f-aa34-e8f796e052fd')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/sql_database_instance.html#settings-1">Documentation</a><br/>|
16681670
|GKE Using Default Service Account<br/><sup><sub>1c8eef02-17b1-4a3e-b01d-dcc3292d2c38</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Insecure Defaults|<a href="../terraform-queries/gcp/1c8eef02-17b1-4a3e-b01d-dcc3292d2c38" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/1c8eef02-17b1-4a3e-b01d-dcc3292d2c38')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/container_cluster#node_config">Documentation</a><br/>|
16691671
|Using Default Service Account<br/><sup><sub>3cb4af0b-056d-4fb1-8b95-fdc4593625ff</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Insecure Defaults|<a href="../terraform-queries/gcp/3cb4af0b-056d-4fb1-8b95-fdc4593625ff" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/3cb4af0b-056d-4fb1-8b95-fdc4593625ff')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_instance">Documentation</a><br/>|
16701672
|Google Compute Network Using Default Firewall Rule<br/><sup><sub>40abce54-95b1-478c-8e5f-ea0bf0bb0e33</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Networking and Firewall|<a href="../terraform-queries/gcp/40abce54-95b1-478c-8e5f-ea0bf0bb0e33" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/40abce54-95b1-478c-8e5f-ea0bf0bb0e33')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_firewall#name">Documentation</a><br/>|
16711673
|Google Compute Network Using Firewall Rule that Allows All Ports<br/><sup><sub>22ef1d26-80f8-4a6c-8c15-f35aab3cac78</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Networking and Firewall|<a href="../terraform-queries/gcp/22ef1d26-80f8-4a6c-8c15-f35aab3cac78" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/22ef1d26-80f8-4a6c-8c15-f35aab3cac78')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_firewall#allow">Documentation</a><br/>|
16721674
|IP Forwarding Enabled<br/><sup><sub>f34c0c25-47b4-41eb-9c79-249b4dd47b89</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Networking and Firewall|<a href="../terraform-queries/gcp/f34c0c25-47b4-41eb-9c79-249b4dd47b89" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/f34c0c25-47b4-41eb-9c79-249b4dd47b89')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/data-sources/compute_instance">Documentation</a><br/>|
16731675
|Serial Ports Are Enabled For VM Instances<br/><sup><sub>97fa667a-d05b-4f16-9071-58b939f34751</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Networking and Firewall|<a href="../terraform-queries/gcp/97fa667a-d05b-4f16-9071-58b939f34751" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/97fa667a-d05b-4f16-9071-58b939f34751')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_instance">Documentation</a><br/>|
16741676
|SSH Access Is Not Restricted<br/><sup><sub>c4dcdcdf-10dd-4bf4-b4a0-8f6239e6aaa0</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Networking and Firewall|<a href="../terraform-queries/gcp/c4dcdcdf-10dd-4bf4-b4a0-8f6239e6aaa0" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/c4dcdcdf-10dd-4bf4-b4a0-8f6239e6aaa0')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_firewall">Documentation</a><br/>|
1677+
|Beta - Google DNS Policy Logging Disabled<br/><sup><sub>cc9e464e-5abc-4c8f-8077-a9aa7ebe6a05</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Observability|<a href="../terraform-queries/gcp/cc9e464e-5abc-4c8f-8077-a9aa7ebe6a05" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/cc9e464e-5abc-4c8f-8077-a9aa7ebe6a05')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/dns_policy#enable_logging-1">Documentation</a><br/>|
1678+
|Beta - SQL DB Instance With Minimum Log Duration<br/><sup><sub>00335e17-674c-442e-a64c-9436e60e6efb</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Observability|<a href="../terraform-queries/gcp/00335e17-674c-442e-a64c-9436e60e6efb" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/00335e17-674c-442e-a64c-9436e60e6efb')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/sql_database_instance.html#settings-1">Documentation</a><br/>|
1679+
|Beta - SQL DB Instance Without Connections Logging<br/><sup><sub>fc7187e5-b9a2-46c0-950d-3bfcaaacc5ca</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Observability|<a href="../terraform-queries/gcp/fc7187e5-b9a2-46c0-950d-3bfcaaacc5ca" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/fc7187e5-b9a2-46c0-950d-3bfcaaacc5ca')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/sql_database_instance.html#settings-1">Documentation</a><br/>|
1680+
|Beta - SQL DB Instance Without Disconnections Logging<br/><sup><sub>8895abb4-6491-4ae6-9c33-c2f360752b7a</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Observability|<a href="../terraform-queries/gcp/8895abb4-6491-4ae6-9c33-c2f360752b7a" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/8895abb4-6491-4ae6-9c33-c2f360752b7a')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/sql_database_instance.html#settings-1">Documentation</a><br/>|
16751681
|Cloud Storage Bucket Logging Not Enabled<br/><sup><sub>d6cabc3a-d57e-48c2-b341-bf3dd4f4a120</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Observability|<a href="../terraform-queries/gcp/d6cabc3a-d57e-48c2-b341-bf3dd4f4a120" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/d6cabc3a-d57e-48c2-b341-bf3dd4f4a120')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/storage_bucket#log_bucket">Documentation</a><br/>|
16761682
|Cloud Storage Bucket Versioning Disabled<br/><sup><sub>e7e961ac-d17e-4413-84bc-8a1fbe242944</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Observability|<a href="../terraform-queries/gcp/e7e961ac-d17e-4413-84bc-8a1fbe242944" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/e7e961ac-d17e-4413-84bc-8a1fbe242944')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/storage_bucket#enabled">Documentation</a><br/>|
16771683
|Google Compute Subnetwork Logging Disabled<br/><sup><sub>40430747-442d-450a-a34f-dc57149f4609</sub></sup>|Terraform|<span style="color:#ff7213">Medium</span>|Observability|<a href="../terraform-queries/gcp/40430747-442d-450a-a34f-dc57149f4609" onclick="newWindowOpenerSafe(event, '../terraform-queries/gcp/40430747-442d-450a-a34f-dc57149f4609')">Query details</a><br><a href="https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/compute_subnetwork">Documentation</a><br/>|

docs/queries/ansible-queries/aws/905f4741-f965-45c1-98db-f7a00a0e5c73.md

Lines changed: 216 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -30,7 +30,7 @@ SNS Topic Policy should not allow any principal to access<br>
3030

3131
### Code samples
3232
#### Code samples with security vulnerabilities
33-
```yaml title="Positive test num. 1 - yaml file" hl_lines="50 23"
33+
```yaml title="Positive test num. 1 - yaml file" hl_lines="52 23"
3434
---
3535
- name: Create alarm SNS topic community
3636
community.aws.sns_topic:
@@ -58,7 +58,73 @@ SNS Topic Policy should not allow any principal to access<br>
5858
Statement:
5959
- Action: Publish
6060
Effect: Allow
61-
Principal: "*"
61+
Principal:
62+
AWS: "*"
63+
64+
- name: Create alarm SNS topic
65+
sns_topic:
66+
name: "alarms"
67+
state: present
68+
display_name: "alarm SNS topic"
69+
delivery_policy:
70+
http:
71+
defaultHealthyRetryPolicy:
72+
minDelayTarget: 2
73+
maxDelayTarget: 4
74+
numRetries: 3
75+
numMaxDelayRetries: 5
76+
backoffFunction: "<linear|arithmetic|geometric|exponential>"
77+
disableSubscriptionOverrides: True
78+
defaultThrottlePolicy:
79+
maxReceivesPerSecond: 10
80+
subscriptions:
81+
- endpoint: "[email protected]"
82+
protocol: "email"
83+
- endpoint: "my_mobile_number"
84+
protocol: "sms"
85+
policy:
86+
Version: '2022-05-02'
87+
Statement:
88+
- Effect: Allow
89+
Action: Publish
90+
Principal:
91+
AWS: "*"
92+
93+
```
94+
```yaml title="Positive test num. 2 - yaml file" hl_lines="55 23"
95+
---
96+
- name: Create alarm SNS topic community
97+
community.aws.sns_topic:
98+
name: "alarms"
99+
state: present
100+
display_name: "alarm SNS topic"
101+
delivery_policy:
102+
http:
103+
defaultHealthyRetryPolicy:
104+
minDelayTarget: 2
105+
maxDelayTarget: 4
106+
numRetries: 3
107+
numMaxDelayRetries: 5
108+
backoffFunction: "<linear|arithmetic|geometric|exponential>"
109+
disableSubscriptionOverrides: True
110+
defaultThrottlePolicy:
111+
maxReceivesPerSecond: 10
112+
subscriptions:
113+
- endpoint: "[email protected]"
114+
protocol: "email"
115+
- endpoint: "my_mobile_number"
116+
protocol: "sms"
117+
policy:
118+
Version: '2022-05-02'
119+
Statement:
120+
- Effect: Allow
121+
Action: Publish
122+
Principal:
123+
AWS: "*"
124+
Condition:
125+
StringEquals:
126+
sns:Endpoint: "[email protected]"
127+
62128
- name: Create alarm SNS topic
63129
sns_topic:
64130
name: "alarms"
@@ -85,7 +151,11 @@ SNS Topic Policy should not allow any principal to access<br>
85151
Statement:
86152
- Effect: Allow
87153
Action: Publish
88-
Principal: '*'
154+
Principal:
155+
AWS: "*"
156+
Condition:
157+
StringEquals:
158+
sns:Endpoint: "[email protected]"
89159

90160
```
91161

@@ -113,7 +183,7 @@ SNS Topic Policy should not allow any principal to access<br>
113183
Statement:
114184
- Effect: Allow
115185
Action: Publish
116-
Principal: NotAll
186+
Principal: "arn:aws:iam::123456789012:root"
117187

118188
- name: Create alarm SNS topic
119189
sns_topic:
@@ -136,7 +206,148 @@ SNS Topic Policy should not allow any principal to access<br>
136206
Statement:
137207
- Effect: Allow
138208
Action: Publish
139-
Principal: NotAll
209+
Principal: "arn:aws:iam::123456789012:root"
210+
211+
```
212+
```yaml title="Negative test num. 2 - yaml file"
213+
- name: Create SNS topic with safe policy
214+
community.aws.sns_topic:
215+
name: secure-topic
216+
display_name: "Secure SNS Topic"
217+
state: present
218+
policy:
219+
Id: secure-topic-policy
220+
Version: "2012-10-17"
221+
Statement:
222+
- Sid: AllowPublishFromSpecificAccount
223+
Effect: Allow
224+
Resource: "arn:aws:sns:*:*:secure-topic"
225+
Principal: "*"
226+
Action: sns:Publish
227+
Condition:
228+
StringEquals:
229+
aws:SourceAccount: "123456789012"
230+
231+
- name: Create alarm SNS topic
232+
sns_topic:
233+
name: alarms
234+
state: present
235+
display_name: "alarm SNS topic"
236+
delivery_policy:
237+
http:
238+
defaultHealthyRetryPolicy:
239+
minDelayTarget: 2
240+
maxDelayTarget: 4
241+
numRetries: 3
242+
numMaxDelayRetries: 5
243+
backoffFunction: exponential
244+
disableSubscriptionOverrides: true
245+
defaultThrottlePolicy:
246+
maxReceivesPerSecond: 10
247+
policy:
248+
Version: '2022-05-02'
249+
Statement:
250+
- Effect: Allow
251+
Action: Publish
252+
Principal: "*"
253+
Condition:
254+
StringEquals:
255+
aws:SourceOwner: "123456789012"
256+
257+
```
258+
```yaml title="Negative test num. 3 - yaml file"
259+
- name: Create SNS topic with mixed conditions
260+
community.aws.sns_topic:
261+
name: mixed-topic
262+
display_name: "Mixed SNS Topic"
263+
state: present
264+
policy:
265+
Id: mixed-topic-policy
266+
Version: "2012-10-17"
267+
Statement:
268+
- Sid: AllowAnyPrincipalWithRestrictions
269+
Effect: Allow
270+
Resource: "arn:aws:sns:*:*:mixed-topic"
271+
Principal: "*"
272+
Action: sns:Publish
273+
Condition:
274+
StringEquals:
275+
aws:ResourceAccount: "123456789012"
276+
277+
- name: Create alarm SNS topic
278+
sns_topic:
279+
name: alarms
280+
state: present
281+
display_name: "alarm SNS topic"
282+
delivery_policy:
283+
http:
284+
defaultHealthyRetryPolicy:
285+
minDelayTarget: 2
286+
maxDelayTarget: 4
287+
numRetries: 3
288+
numMaxDelayRetries: 5
289+
backoffFunction: exponential
290+
disableSubscriptionOverrides: true
291+
defaultThrottlePolicy:
292+
maxReceivesPerSecond: 10
293+
policy:
294+
Version: '2022-05-02'
295+
Statement:
296+
- Effect: Allow
297+
Action: Publish
298+
Principal: "*"
299+
Condition:
300+
StringEquals:
301+
aws:PrincipalAccount: "123456789012"
302+
303+
```
304+
<details><summary>Negative test num. 4 - yaml file</summary>
305+
306+
```yaml
307+
- name: Create SNS topic with mixed conditions
308+
community.aws.sns_topic:
309+
name: mixed-topic
310+
display_name: "Mixed SNS Topic"
311+
state: present
312+
policy:
313+
Id: mixed-topic-policy
314+
Version: "2012-10-17"
315+
Statement:
316+
- Sid: AllowAnyPrincipalWithRestrictions
317+
Effect: Allow
318+
Resource: "arn:aws:sns:*:*:mixed-topic"
319+
Principal: "*"
320+
Action: sns:Publish
321+
Condition:
322+
StringEquals:
323+
aws:VpceAccount: "123456789012"
324+
325+
- name: Create alarm SNS topic
326+
sns_topic:
327+
name: alarms
328+
state: present
329+
display_name: "alarm SNS topic"
330+
delivery_policy:
331+
http:
332+
defaultHealthyRetryPolicy:
333+
minDelayTarget: 2
334+
maxDelayTarget: 4
335+
numRetries: 3
336+
numMaxDelayRetries: 5
337+
backoffFunction: exponential
338+
disableSubscriptionOverrides: true
339+
defaultThrottlePolicy:
340+
maxReceivesPerSecond: 10
341+
policy:
342+
Version: '2022-05-02'
343+
Statement:
344+
- Effect: Allow
345+
Action: Publish
346+
Principal: "*"
347+
Condition:
348+
StringEquals:
349+
aws:VpceAccount: "123456789012"
140350

141351
```
352+
</details>
142353

0 commit comments

Comments
 (0)