diff --git a/pkg/policies/opa/rego/aws/aws_api_gateway_stage/AWS.API Gateway.Logging.Medium.0571.json b/pkg/policies/opa/rego/aws/aws_api_gateway_stage/AWS.API Gateway.Logging.Medium.0571.json index 6a205aae9..bac29465a 100755 --- a/pkg/policies/opa/rego/aws/aws_api_gateway_stage/AWS.API Gateway.Logging.Medium.0571.json +++ b/pkg/policies/opa/rego/aws/aws_api_gateway_stage/AWS.API Gateway.Logging.Medium.0571.json @@ -5,7 +5,7 @@ "resource_type": "aws_api_gateway_stage", "template_args": null, "severity": "MEDIUM", - "description": "Enable Active Tracing", + "description": "Ensure AWS API Gateway has active xray tracing enabled", "reference_id": "AWS.API Gateway.Logging.Medium.0571", "category": "Logging and Monitoring", "version": 2 diff --git a/pkg/policies/opa/rego/aws/aws_api_gateway_stage/apiGatewayTracing.rego b/pkg/policies/opa/rego/aws/aws_api_gateway_stage/apiGatewayTracing.rego index 56e93e1f5..aa1bf00a6 100755 --- a/pkg/policies/opa/rego/aws/aws_api_gateway_stage/apiGatewayTracing.rego +++ b/pkg/policies/opa/rego/aws/aws_api_gateway_stage/apiGatewayTracing.rego @@ -1,9 +1,6 @@ package accurics -apiGatewayTracing[retVal] { +apiGatewayTracing[api.id] { api := input.aws_api_gateway_stage[_] - api.config.xray_tracing_enabled == false - - traverse = "xray_tracing_enabled" - retVal := { "Id": api.id, "ReplaceType": "edit", "CodeType": "attribute", "Traverse": traverse, "Attribute": "xray_tracing_enabled", "AttributeDataType": "bool", "Expected": true, "Actual": api.config.xray_tracing_enabled } + object.get(api.config, "xray_tracing_enabled", "undefined") == [false, "undefined"][_] } \ No newline at end of file diff --git a/pkg/policies/opa/rego/aws/aws_lb_listener/AC_AWS_046.json b/pkg/policies/opa/rego/aws/aws_lb_listener/AC_AWS_046.json index 305f101f9..029f9d5f8 100644 --- a/pkg/policies/opa/rego/aws/aws_lb_listener/AC_AWS_046.json +++ b/pkg/policies/opa/rego/aws/aws_lb_listener/AC_AWS_046.json @@ -7,7 +7,7 @@ "prefix": "" }, "severity": "MEDIUM", - "description": "Ensure there is a one listener configured on HTTPs", + "description": "Ensure there is a one listener configured on HTTPs or with a port 443", "reference_id": "AC_AWS_046", "category": "Infrastructure Security", "version": 2 diff --git a/pkg/policies/opa/rego/aws/aws_lb_listener/listenerNotHttps.rego b/pkg/policies/opa/rego/aws/aws_lb_listener/listenerNotHttps.rego index 619e53794..456f90203 100644 --- a/pkg/policies/opa/rego/aws/aws_lb_listener/listenerNotHttps.rego +++ b/pkg/policies/opa/rego/aws/aws_lb_listener/listenerNotHttps.rego @@ -10,4 +10,9 @@ package accurics listener = input.aws_lb_listener[_] upper(listener.config.protocol) == "HTTP" upper(listener.default_action.redirect.protocol) != "HTTPS" +} + +{{.prefix}}listenerNotHttps[listener.id] { + listener = input.aws_lb_listener[_] + listener.config.port == 80 } \ No newline at end of file