-
Notifications
You must be signed in to change notification settings - Fork 30
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: Add Automated Acceptance Test #452
Conversation
management_account_id, | ||
] | ||
|
||
assert expected_members == actual_members |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think this might fail once not all accounts in the suspended OU are not actually suspended
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The accounts should be de-registered by the cleanup script, or not?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I double-checked. It works because we use the manual invite/accept mechanism, not the organizational guard duty feature that automatically adds all accounts. We need to make sure that the clean-up script deletes the detectors properly since it still fails from time to time, so we avoid false positives.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, I think we use the same for the backup feature. Maybe the organizations feature was not available at the time of creation?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yes, generally aws is a bit slow in regards to integrating services on the organisational level. I'm pretty sure back then it was simply not available yet. the LZA for example uses the guard duty and security hub on org level
LGTM overall 👍🏻 |
No description provided.