Added -D option to copy to S3 with the initial AWS credentials instead of the assumed as with -B option @sectoramen#974
Merged
Conversation
j2clerck
reviewed
Dec 20, 2021
j2clerck
left a comment
There was a problem hiding this comment.
I believe there are more cases to cover here, depending on how Prowler is initially getting credentials:
- Instance Profile
- Named Profile
- Environment Variables
- AWS Config / Credentials file
It might be worth reviewing the existing options and test how it behave. Setting environment variable to '' does not seem to bother aws cli. But you need to be able to revert the profile too at least. Happy to do some testing.
Member
|
I always have tried to keep Prowler consistent with the way that the cli works in terms of configuration settings and precedence
Additionally, Prowler handles:
|
Contributor
Author
|
This is ready to go. It was tested and it appears to work fine. |
Member
|
Awesome, thanks @sectoramen! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Toni,
Does it make sense to save the original AWS credentials and then restore them before doing a copy to S3? I don't see a reason to keep the assumed credentials before the copy. The credentials of the individual/process that launched prowler are most likely to be the one used to perform other tasks, such as copy to S3. Optionally, we could add a new option, i.e.,
-Bn Custom output bucket used with original prowler role, requires -M and it can work also with -o flag.
(i.e.: -M csv -B my-bucket or -M csv -B my-bucket/folder/)